Opens profile photo
Follow
Click to Follow chainguard_dev
Chainguard ⛓️
@chainguard_dev
Making the software supply chain secure by default. #softwaresecurity #cybersecurity
chainguard.devJoined July 2021

Chainguard ⛓️’s Tweets

Pinned Tweet
We asked what #VEX is & this pretty much sums it up: “Virtually Everyone is confused at this point & just want know what tool they have run in CI to produce some json file so they can just ship software again Xylophone.” We KNOW you have questions! 🤪
1
14
Show this thread
(Apko works hand in hand with a tool called melange) which produces an SBOM for images with all the packages listed inside, Apko is also used to build Images with complete SBOMs at build time. Here's Make SBOMs, not GuessBOMs 🧐👇
8
60 to 70% of browser and kernel vulnerabilities—and security bugs found in C/C++ code bases—are due to memory unsafety. Wolfi by (call it “undistro) gives developers the secure by default base they need to build software.
12
Join us next Tuesday (Jan 31) to talk about VEX and how it will help to make life easier when triaging vulnerabilities and #SBOM so much more useful.
Quote Tweet
We asked what #VEX is & this pretty much sums it up: “Virtually Everyone is confused at this point & just want know what tool they have run in CI to produce some json file so they can just ship software again Xylophone.” We KNOW you have questions! 🤪 twitter.com/i/spaces/1RDGl
Show this thread
10
Loved seeing 's research in ' Codebook today
Image
Quote Tweet
it's a busy, busy day — a great time for Codebook! today's edition: 💼 cyber hiring demand remains high, despite tech layoffs 📚 CISA releases K-12 report, recommendations 🤳 Apple launches new workshops about iPhone privacy settings axios.com/newsletters/ax
1
10
Another day, another new image! Here's our announcement for #Python in Wolfi and images! Faster runtime! Fewer CVEs! Smaller size! glibc for compatility and fast package install! SBOMs! Signatures! Magic!
20