Chainguard Blog
RSS FeedLatest updates
securityHow financial services companies can modernize their software supply chain
securityProven, not promised: Chainguard Containers achieves SLSA Build Level 3
securityThe keyv and cacheable npm Supply Chain Attack: Inside the Mini Shai-Hulud Campaign
securityWhy AI-assisted attacks made software supply chain security its own category
securityWhy zero CVEs matters in mobile airgapped deployments
securityMitigating WordPress attacks with containers
securityResponding to the Five Eyes guidance on AI and cyber risk
securityAsyncAPI supply chain compromise: npm packages backdoored via GitHub Actions "pwn request" (July 2026)
securityWe're putting our security to the test, and we want your help
securitySummer of Clearinghouses
security@mastra npm scope takeover: 143 packages backdoored via compromised contributor account
securityMiasma Phantom Gyp npm attack: 57 packages, 286 malicious versions hijack CI/CD pipelines via binding.gyp