SmartBear announced AI enhancements for API testing, UI test automation, and test management across its product suite, the SmartBear Application Integrity Core™.
Chainguard announced Chainguard Repository, a single Chainguard-managed experience for pulling secure-by-default open source containers, dependencies, OS packages, virtual machine images, CI/CD workflows, and agent skills that have built-in, intelligent policies to enforce enterprise security standards.
"AI is dramatically increasing the speed of software development for defenders and attackers alike. AI coding tools and autonomous agents are generating more code, pulling in more dependencies, and interacting with open source at a scale humans have never seen before," said Dan Lorenc, CEO and Co-founder of Chainguard. "Chainguard Repository is the trust layer for this new era. By giving developers a single, policy-enforced experience for open source, organizations can control what software enters their environments. In a world where software is increasingly generated and deployed autonomously, trust must be built into the foundation."
With Chainguard Repository, organizations connect once to a single Chainguard-managed experience with built-in, intelligent policies for secure-by-default open source artifacts. Starting today, customers can consume JavaScript libraries from Chainguard Repository, gaining access to more than 73,000 Chainguard-built JavaScript packages, only falling back to npm when necessary. Chainguard Libraries are built in a SLSA L3-compliant environment and eliminate 99.7% of malware by design. A cooldown protects the upstream fallback from npm malware by giving community researchers time to discover attacks before they are available in an organization's environment. As the AI-native Chainguard Factory builds more packages from source, an organization's security posture improves automatically without having to change settings, endpoints, or a line of code.
Later this year, Chainguard Repository will expand to Python and Java libraries, container images, OS packages, virtual machine images, CI/CD workflows, and agent skills, bringing the same secure-by-default experience and even more policy controls to the entire modern software stack. Additional policy types will include:
- CVE blocking: Prevent artifacts with known critical vulnerabilities from being pulled, reducing exposure before code runs.
- License enforcement: Restrict artifacts to approved licenses to help organizations align with their legal requirements.
- End-of-life prevention: Reject artifacts that have reached end of life, eliminating the risk of unmaintained software.
- Long-term support enforcement: Require artifacts to have long-term support, ensuring all in-use software is actively maintained.
Chainguard Repository advances Chainguard's mission to make open source trustworthy by default by shifting security from reactive scanning and patching to secure-by-default at the point of consumption. Artifacts are built from verifiable, public source code, and intelligent policies add another layer of protection and compliance.
At its core, the repository delivers:
- Automated compliance: Configurable policies that enforce organizational security standards across containers and libraries without manual reviews.
- Security posture that improves automatically: Risk shrinks as Chainguard rebuilds more artifacts from source, all without requiring developers to change a line of code.
- Clear visibility: Dashboards show real-time coverage, policy enforcement, and vulnerability status across every artifact an organization consumes.
Chainguard Repository integrates with existing artifact managers or can be deployed as a standalone experience.
Chainguard Repository is available in beta.
Industry News
JFrog announced its partnership with iZeno Pte Ltd, a Singapore-headquartered enterprise technology solutions provider.
Red Hat announced an expanded collaboration with Google Cloud to help organizations accelerate application modernization and cloud migrations.
The Linux Foundation, the nonprofit organization enabling mass innovation through open source, announced the contribution of SQLMesh, an open source data transformation framework, to the Foundation by Fivetran.
Check Point® Software Technologies Ltd. released the AI Factory Security Architecture Blueprint — a comprehensive, vendor-tested reference architecture for securing private AI infrastructure from the hardware layer to the application layer.
CMD+CTRL Security won the following awards from Cyber Defense Magazine (CDM), the industry’s leading electronic information security magazine: Most Innovative Cybersecurity Training and Pioneering Secure Coding: Developer Upskilling.
Check Point® Software Technologies Ltd. announced the Check Point AI Defense Plane, a unified AI security control plane designed to help enterprises govern how AI is connected, deployed, and operated across the business.
Oracle announced the latest updates to Oracle AI Agent Studio for Fusion Applications, a complete development platform for building, connecting, and running AI automation and agentic applications.
The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for cloud native software, announced that Istio has launched a host of new features designed to meet the rising needs of modern, AI-driven infrastructure while reducing operational complexity.
Chainguard announced Chainguard Repository, a single Chainguard-managed experience for pulling secure-by-default open source containers, dependencies, OS packages, virtual machine images, CI/CD workflows, and agent skills that have built-in, intelligent policies to enforce enterprise security standards.
Backslash Security announced new cross-product support for agentic AI Skills within its platform, enabling organizations to discover, assess, and apply security guardrails to Skills used across AI-native software development environments.
The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for cloud native software, announced the graduation of Kyverno, a Kubernetes-native policy engine that enables organizations to define, manage and enforce policy-as-code across cloud native environments.
Zero Networks announced the Kubernetes Access Matrix, a real time visual map that exposes every allowed and denied rule inside Kubernetes clusters.
Apiiro announced AI Threat Modeling, a new capability within Apiiro Guardian Agent that automatically generates architecture-aware threat models to identify security and compliance risks before code exists.
GitLab released GitLab 18.10, making it easier and more affordable to use agentic AI capabilities across the entire software development lifecycle.




