🧾 Bob in Finance just used a skill to analyze revenue data. Is that data safe? Agent skills are one of the newest layers of the software supply chain, and attackers have taken notice. With Chainguard Agent Skills, we harden every skill your team gets through the Chainguard Factory. Here's how: https://lnkd.in/exRpN68b
Chainguard
Computer and Network Security
Kirkland, WA 68,948 followers
The trusted source for open source.
About us
Chainguard is the trusted source for open source. By delivering hardened, secure, and production-ready builds of all the open source software engineers and AI agents rely on, Chainguard helps organizations build faster, stay compliant, and eliminate risk. Its customers include Fortune 500 enterprises and global industry leaders, including Anduril, Canva, Fortinet, Hewlett Packard Enterprise, OpenAI, Snap Inc., and Snowflake. Chainguard is venture-backed by leading investors, including Amplify, IVP, Kleiner Perkins, Lightspeed Venture Partners, Mantis VC, Redpoint Ventures, Sequoia Capital, and Spark Capital. For more information, visit: https://www.chainguard.dev/
- Website
-
https://www.chainguard.dev/
External link for Chainguard
- Industry
- Computer and Network Security
- Company size
- 201-500 employees
- Headquarters
- Kirkland, WA
- Type
- Privately Held
- Founded
- 2021
- Specialties
- software supply chain security, cybersecurity, container images, and software development
Products
Chainguard Containers
Container Security Software
Secure-by-default container images Build software better with minimal, zero-CVE container images guarded under our industry-leading remediation SLA. Secure container images for modern applications *Reduce costly engineering toil Adopt inherently secure software so engineers can spend more time shipping products and less time patching CVEs. 4 hrs/month per developer saved on vulnerability management. *Secure your open source foundation Rely on trusted open source to improve your security posture and reduce the attack surface for bad actors. 97.6% reduction in CVEs compared to OSS equivalents *Simplify continuous compliance Solve critical compliance controls by default to reduce overhead costs and get products to market faster. 400+ FIPS Images with OS-level STIG hardening.
Locations
-
Primary
Get directions
Kirkland, WA 98033, US
Employees at Chainguard
Updates
-
Chainguard reposted this
I had one of the most energizing conversations of my year sitting down with John Sapp Jr, Field CISO of Chainguard, for the first episode of their new "Prevention Under Pressure" series. 📽️ Check out the full video here: https://lnkd.in/g5SWAvsk We covered a lot of ground in our discussion - some of it heavy, some genuinely fun - but three moments stuck with me: 1. The AI-enabled attack moment that changed everything for me. It wasn't one thing - it was two, back to back. First, phishing emails so clean they had zero typos, zero broken links, nothing for a filter to catch - a world away from the "Nigerian prince" era we all trained on. Then, watching a deepfake of a CEO walk on stage at a conference keynote in a completely different outfit, different hair - and not clocking it wasn't real, even though I'd met the actual person. That was the moment I realized this wasn't a future threat. It was already here. 2. Why prevention beats detection. I used to spend the first two or three hours of any incident just figuring out what happened - detection tools tell you something's wrong, not what or how bad. The real shift isn't that response gets faster with the right tooling in place. It's that the blast radius is smaller from the start, because the vulnerable path either wasn't there or never got the chance to be exploited. That changes the entire shape of the day. 3. What actually stops a threat before it starts. I walked through the TIDE model I built at Williams Rose AI Cyber Advisory - Tier, Intake, Determine controls, Enact decision - and why tiering risk has to come before you touch your SIEM, EDR, or IAM stack, not after. Most "AI governance" is detection wearing prevention's clothes. Real prevention means deciding what's allowed before anyone touches the tool. John is a phenomenal interviewer and an even better follow - if you're not already connected with John Sapp Jr, fix that. And if you want to see how Chainguard is putting prevention-first security into practice, check them out. Link in comments! Drop your own answer in the comments: what's the moment an AI-enabled attack changed how you think about security?
-
"If we'd started Chainguard a year earlier, building exactly the same product, we would have struggled to raise money. Nobody cared. Then, almost overnight, everyone did." Our co-founder and CTO Matt Moore reflects on the impact of SolarWinds, five years of building the trusted source for open source, and what comes next:
-
🥪 Would you eat a sandwich you found on a fence post? ...then why run code you never inspected? Chainguard CISO Quincy Castro sat down with VentureBeat to talk about how AI coding is accelerating supply chain risk and why teams should use open source components that are malware-resistant and free of vulnerabilities. https://lnkd.in/e6Yn-Bi8
-
We’re excited to share that Chainguard has received a Morgan Stanley Innovation Award 🎉 On the award, Michael Pizzi, Global Head of Technology and Operations at Morgan Stanley, said, “Open source technologies underpin modern software development and maintaining a strong security foundation is essential—Chainguard’s solutions are critical for us to accomplish both our cyber and business objectives." Learn more: https://lnkd.in/eAGxQgKS
-
-
__________________ | TWO WEEKS UNTIL| | #Assemble26LDN | |_________________| (◕ᴗ◕) || (((())))|| 🐙 Join us in London: https://lnkd.in/gNx9QTQb
-
taylor swift songs, if she worked in supply chain security 💿 You Belong With Minimal Images Blank Space in My SBOM Cruel Patch Summer Shake It Off (The Vulnerabilities) I Knew You Were Unpinned Look What You Made Me Rebuild All Too Well-Maintained (10 Minute Version) Supply Chain Mastermind Anti-Hero Dependency
-
Achieving FedRAMP for Polaris meant Black Duck either needed to manage the maintenance of its own supply chain dependencies or find someone to trust with it. That someone is us 🚀 Here's a look at just some of what they've accomplished since onboarding Chainguard: https://lnkd.in/e6V2yH5F
-