Chainguard Blog
RSS FeedFeatured stories

Building a category: Chainguard named a Leader in the inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security
Gartner names Chainguard a Leader in Software Supply Chain Security, highlighting its secure-by-default approach and market vision.

What it took to reach 1 billion build manifests
Chainguard doubled its container build output in six months. Learn how Factory 2.0 uses AI and reconciliation to rebuild secure software at scale.
Latest updates
productThe expanding threat landscape: Chainguard now scans source code for traditional malware and “greyware”
securityMiasma Phantom Gyp npm attack: 57 packages, 286 malicious versions hijack CI/CD pipelines via binding.gyp
securityChainguard customers safe from Mini Shai-Hulud worm targeting @redhat-cloud-services npm packages with 100K+ weekly downloads
engineeringThe hardest fork
security5 security myths that Mythos ended (as told by a CISO)
newsChainguard and Upwind: Secure what you build. Verify what you run.
securityPreparing for Mythos: Practical advice for engineering teams
newsBuilding for the AI era: Chainguard partners with Endor Labs
securityMini Shai-Hulud npm Attack: AntV Ecosystem Compromise (May 2026)
securityNode-ipc compromised: Credential stealer targets package with 500k+ weekly downloads
securityCanada's CPCSC and Bill C-8 are coming. Here's what you need to do.
securityLuck isn't a security control: What happened with mini Shai-Hulud and what you need to do