Chainguard Blog
Featured posts
Chainguard Libraries for Java is now GA and includes CVE remediation
Chainguard Libraries for Java is now GA, delivering CVE-remediated dependencies with SBOMs, provenance, and scanner-recognized fixes.
Ross Gordon, Staff Product Marketing Manager
Building a category: Chainguard named a Leader in the inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security
Gartner names Chainguard a Leader in Software Supply Chain Security, highlighting its secure-by-default approach and market vision.
Patrick Donahue, SVP, Product, and Sam Katzen, Director, Product Marketing
Latest updates
- product
Chainguard Libraries for Java is now GA and includes CVE remediation
Ross Gordon, Staff Product Marketing Manager
- open source
The Maintainer of Last Resort
Dan Lorenc, Co-founder and CEO
- news
Building a category: Chainguard named a Leader in the inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security
Patrick Donahue, SVP, Product, and Sam Katzen, Director, Product Marketing
- product
Introducing the Chainguard cinc-auditor image: STIG scanning for Chainguard Containers, ready to run
Steve Beattie, Sr. Principal Software Engineer, and Mandy Hubbard, Sr. Technical Product Marketing Manager
- news
Chainguard is named a Leader in the 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security
Sam Katzen, Director, Product Marketing
- security
@mastra npm scope takeover: 143 packages backdoored via compromised contributor account
Quincy Castro, CISO
- product
Chainguard Agent Skills is now open to everyone, with a private registry to manage your internal skills
Anushka Iyer, Product Marketing Manager, and Tyler Paxton, Principal Product Manager
- engineering
Faster than the advisory
Patrick Smyth, Principal Developer Relations Engineer, and Adrian Mouat, Staff Developer Relations Engineer
- product
The expanding threat landscape: Chainguard now scans source code for traditional malware and “greyware”
Ross Gordon, Staff Product Marketing Manager, and Evan Gibler, Staff Security Engineer
- security
Miasma Phantom Gyp npm attack: 57 packages, 286 malicious versions hijack CI/CD pipelines via binding.gyp
Quincy Castro, CISO
- security
Chainguard customers safe from Mini Shai-Hulud worm targeting @redhat-cloud-services npm packages with 100K+ weekly downloads
Quincy Castro, CISO
- engineering
The hardest fork
Dan Lorenc, Co-founder and CEO