Chainguard Blog
Featured posts
Chainguard Libraries for Python: Now Generally Available with CVE Remediation and Malware Protection
Chainguard Libraries for Python, trusted open source language libraries designed for CVE remediation and malware protection, is now generally available.
Bria Giordano, Director, Product Marketing, and Anushka Iyer, Product Marketing Manager
The State of Trusted Open Source: December 2025
Chainguard’s State of Trusted Open Source for December 2025 dives into usage trends for Chainguard Containers, CVE data, and why remediation speed matters.
Ed Sawma, VP of Product Marketing, and Sasha Itkis, Product Analyst
Security insights delivered before they become problems
Latest updates
- product
When a picture is worth 306 CVEs: New image vulnerability comparisons in Chainguard Academy
Jamon Camisso, Developer Experience Engineer
- research
Taming bad Python packages: Assessing Python malware detectors with a benchmark dataset
John Speed Meyers and Zachary Newman, Principal Research Scientists
- product
Exploring new capabilities in the Chainguard Registry to enable secure and efficient container image management
Kim Lewandowski, Chief Product Officer
- product
Chainguard Image now available for Zig
Dan Lorenc, CEO
- product
Important updates for Chainguard Images public catalog users
Kim Lewandowski, Chief Product Officer
- engineering
Fully bootstrapping Go from source in Wolfi
Ariadne Conill, Principal Software Engineer
- security
What every CISO should know about the new SSDF security self-attestation form
Dan Lorenc, CEO; Christian Baer, Senior Associate and Sully Perella, Technical Director at Schellman
- news
Get in Chainguard, we’re going to fabulous Las Vegas!
Kaylin Trychon, VP of Marketing and External Affairs
- research
The zero CVE challenge: Can official Docker Hub images pass the test?
Trevor Dunlap, Research Intern
- open source
Can Protobom end the SBOM format wars?
Adolfo García Veytia, Staff OSS Engineer and John Speed Meyers, Principal Research Scientist
- open source
wolfi-act: Dynamic GitHub Actions from Wolfi packages
Josh Dolistky, Staff Software Engineer
- security
Fuzzy CVEs, tarfiles, and untrusted input
Dan Lorenc, CEO