Supply Chain Security 101
Everything you need to know about software supply chain security in the age of open source.
- Tools & Buyer’s GuidesSoftware Supply Chain
Docker alternatives: Replacing the runtime and the base image
Compare container runtimes and secure base image options like Chainguard, Docker Hardened Images, Bitnami, RapidFort, and Distroless.
- AppSecSoftware Supply Chain
AI supply chain security: Risks & best practices
Learn best practices for AI supply chain security to ensure you integrate AI into your applications safely.
- Software Supply ChainDevSecOps
npm supply chain attacks: How to audit your dependency controls
Reduce the risk of npm supply chain attacks. Trace a package’s path into your build, verify its artifact, and control what can execute.
- Software Supply Chain
Open source security: The complete guide for 2026
Malicious packages, unmatched dependencies, and registry-native malware are accelerating. Learn how to build a preventative approach to open source security.
- Software Supply ChainDevSecOps
What is dependency confusion? How to reduce the risk of attack
Dependency confusion tricks a build into installing a malicious public package instead of a private one. Learn the controls that reduce the risk.
- Software Supply Chain
CI/CD pipeline security: Controls from source to deployment
Learn how to secure your CI/CD pipeline end to end, from source control and runners through dependencies, artifact signing, SBOMs, and deployment policy.
- Software Supply ChainTools & Buyer’s Guides
What is Chainguard? The trusted source for open source
Chainguard is the trusted source for open source — hardened containers, libraries, VMs, OS packages, CI/CD actions, and AI agent skills, built from source.
- DevSecOpsSoftware Supply Chain
CI/CD security: A practical guide to trusted pipelines
Secure CI/CD pipelines from dependency confusion, tag hijacking, and secret leaks. Learn key controls like pinned actions and build provenance.
- AppSecSoftware Supply Chain
What is malicious code? Examples, how it spreads, and how to stop it
Malicious code hides in trusted packages and pipelines. Learn how supply chain verification stops it before it reaches production.
- Software Supply ChainDevSecOps
What is container runtime security?
Understanding container runtime security best practices can help protect your critical applications against threats to your containerized applications.
- AppSecSoftware Supply Chain
Malicious dependency attacks in the software supply chain
Learn about malicious dependencies and how to secure your software systems against them.
- Software Supply ChainDevSecOps
Managing risk in the software supply chain
Secure your product by understanding risk factors in complex software supply chains, and best practices for mitigating common security vulnerabilities.