Products
ProDUCtS
Chainguard Images New

Images are our security-first container base images.

Chainguard Enforce Beta

Enforce is a supply chain security solution for containerized workloads.

Professional Services

We can provide live and written training on supply chain security, the SLSA Framework and Sigstore.

Featured
All About That Base Image

Read our latest research paper on base image security.

View whitepaper
Community
Resources
CHAINGUARD RESOURCES
Whitepapers New

Complex software supply chain security
topics explained.

Customer Case Study

Read our case study with Block

Chainguard LabsNew

Original research on open source software and software supply chain security

Blog

Learn about software supply chain security from our experts.

NOW AVAILABLE
Chainguard Academy

Learning starts here
Company
PrivacyTerms
Sign inContact usGet a demo
Sign inContact usTry it out
Products
ProDUCtS
Chainguard Images New

Images are our security-first container base images.

Chainguard Enforce Beta

Enforce is a supply chain security solution for containerized workloads.

Professional Services

We can provide live and written training on supply chain security, the SLSA Framework and Sigstore.

Featured
All About That Base Image

Read our latest research paper on base image security.

View whitepaper
Community
Resources
CHAINGUARD RESOURCES
Whitepapers New

Complex software supply chain security
topics explained.

Customer Case Study

Read our case study with Block

Chainguard LabsNew

Original research on open source software and software supply chain security

Blog

Learn about software supply chain security from our experts.

NOW AVAILABLE
Chainguard Academy

Learning starts here
Company
PrivacyTerms
Sign inContact usGet a demo
Sign inContact usTry it out

Securing Software Repositories with the OpenSSF

Zachary Newman
  •  
April 20, 2022
Tweet
The Case for Farm-to-Table Package Signing

Here at Chainguard, we believe that everyone benefits from better security in open-source software. That’s why we’re so excited that the OpenSSF has just created a new “Securing Software Repositories” working group, which aims to bring maintainers of software repositories and package managers together to share and develop best practices for secure software distribution. So far, the group has seen participants from many language communities, including PHP, Python, Ruby, Java, and Rust.

The group has discussed many possible security enhancements:

  • package signing with Sigstore
  • using The Update Framework (TUF) to manage package owners
  • tamper-evident package repositories with transparency logs
  • software bills of materials (SBOMs)
  • rolling out multifactor authentication.

The group’s charter tasks it with developing non-binding recommendations about best practices in package security and aligning. To that end, there are in-progress efforts to compile data about practices across various language ecosystems, formalize a threat model to help analyze various risks, and provide a clearinghouse for package repository data that could be used to fight  typosquatting attacks and for other research.

Chainguard is proud to be an OpenSSF member because of initiatives like this working group. We encourage you to learn more about the Securing Software Repositories working group at the OpenSSF blog! The meetings are publicly listed on the OSSF calendar, and the members hang out in the #securing_software_repos channel on the OpenSSF Slack.

The Case for Farm-to-Table Package Signing

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

More articles

Chainguard Image Now Available for NATS

Dan Lorenc
  •  
March 27, 2023

Chainguard contributes Rekor Search Project to Sigstore

Priya Wadhwa
  •  
March 24, 2023

5 Capabilities in Chainguard Enforce You Don’t Want to Miss (Your Security Team Will LOVE #4)

Adam Dawson
  •  
March 23, 2023

Don’t break the chain – secure your supply chain today!

Contact us

Chainguard

Please direct security disclosures or questions about our bug bounty program to security@chainguard.dev
Copyright 2022
BlogCareersLegalTerms

Sign up for our newsletter

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Chainguard uses cookies to improve your experience and analyze traffic. By using our website, you agree to our privacy policy and our cookie policy.

Accept