<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Introduction to Chainguard Libraries on</title><link>https://edu.chainguard.dev/chainguard/libraries/introduction/</link><description>Recent content in Introduction to Chainguard Libraries on</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><copyright>Copyright (c) 2023 Chainguard</copyright><lastBuildDate>Tue, 25 Mar 2025 08:04:00 +0000</lastBuildDate><atom:link href="https://edu.chainguard.dev/chainguard/libraries/introduction/index.xml" rel="self" type="application/rss+xml"/><item><title>Chainguard Libraries overview</title><link>https://edu.chainguard.dev/chainguard/libraries/introduction/overview/</link><pubDate>Tue, 25 Mar 2025 08:04:00 +0000</pubDate><guid>https://edu.chainguard.dev/chainguard/libraries/introduction/overview/</guid><description>&lt;p&gt;&lt;a href="https://www.chainguard.dev/libraries"&gt;Chainguard Libraries&lt;/a&gt; is a secure catalog
of language dependencies that replaces your team’s reliance on
&lt;a href="https://www.npmjs.com/"&gt;npm&lt;/a&gt;, &lt;a href="https://pypi.org/"&gt;PyPI&lt;/a&gt;, and &lt;a href="https://central.sonatype.com/"&gt;Maven
Central&lt;/a&gt;. Every package pulled by your team or AI
agents passes through multiple layers of defense, including malicious behavior
scanning, building from source, and cooldowns that help prevent malware from
entering your environment.&lt;/p&gt;
&lt;p&gt;As frontier coding models advance, attackers are creating more sophisticated
social engineering campaigns and malware injections to exfiltrate enterprise
secrets. Chainguard Libraries prevents malware instead of making developers
pause work, triage incidents, and respond after compromise.&lt;/p&gt;</description></item><item><title>Quickstart for Chainguard Libraries</title><link>https://edu.chainguard.dev/chainguard/libraries/introduction/quickstart/</link><pubDate>Tue, 25 Mar 2025 00:08:04 +0000</pubDate><guid>https://edu.chainguard.dev/chainguard/libraries/introduction/quickstart/</guid><description>&lt;p&gt;Most supply chain attacks succeed the same way: malicious code is injected into
a package after the source is written — either as a backdoored binary with no
verifiable source, or as a malicious install-time script that runs the moment a
dependency is pulled. Recent attacks on LiteLLM, Telnyx, and Axios all followed
this pattern.&lt;/p&gt;
&lt;p&gt;Chainguard Libraries for Java, JavaScript, and Python are rebuilt from verified
source in an isolated build environment, making them malware-resistant by
design. When a package is available as a Chainguard-built library, that rebuilt
package is served first. When you use the &lt;a href="https://edu.chainguard.dev/chainguard/libraries/introduction/overview/#upstream-fallback-and-controls"&gt;upstream
fallback&lt;/a&gt;,
the same ecosystem endpoint can also serve eligible upstream packages that
Chainguard has not yet built, subject to configurable policy controls such as
cooldown and malware scanning. This gives your engineers drop-in replacements
for the packages they already use, with no breaking changes.&lt;/p&gt;</description></item><item><title>Chainguard Libraries access</title><link>https://edu.chainguard.dev/chainguard/libraries/introduction/access/</link><pubDate>Tue, 25 Mar 2025 00:08:04 +0000</pubDate><guid>https://edu.chainguard.dev/chainguard/libraries/introduction/access/</guid><description>&lt;p&gt;Chainguard Libraries provide controlled access to security-enhanced Java and
Python dependencies through the unified Chainguard platform authentication
system. This guide explains how to access (download) Chainguard library artifacts for your organization.&lt;/p&gt;
&lt;h2 id="getting-started" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;Getting started&lt;/span&gt;
&lt;a href="#getting-started" class="anchor" aria-label="Link to Getting started" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;h3 id="prerequisites" class="heading-3" data-heading-level="3"&gt;
&lt;span class="heading-text"&gt;Prerequisites&lt;/span&gt;
&lt;a href="#prerequisites" class="anchor" aria-label="Link to Prerequisites" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;Ensure you have access to Chainguard Libraries.
&lt;ul&gt;
&lt;li&gt;If you are not a Chainguard user yet, a new Chainguard account must be
created and you must &lt;a href="https://edu.chainguard.dev/chainguard/libraries/introduction/access/#manage-library-entitlements"&gt;add an entitlement to Chainguard Libraries&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Confirm the name of your organization so you can use it with the &lt;code&gt;--parent&lt;/code&gt;
parameter to specify your organization when running commands with &lt;code&gt;chainctl&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="direct-access-vs-artifact-manager" class="heading-3" data-heading-level="3"&gt;
&lt;span class="heading-text"&gt;Direct access vs. artifact manager&lt;/span&gt;
&lt;a href="#direct-access-vs-artifact-manager" class="anchor" aria-label="Link to Direct access vs. artifact manager" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h3&gt;&lt;p&gt;There are two approaches to access: Using an artifact manager or
direct access.&lt;/p&gt;</description></item><item><title>Chainguard Libraries network requirements</title><link>https://edu.chainguard.dev/chainguard/libraries/introduction/network-requirements/</link><pubDate>Wed, 04 Jun 2025 09:30:00 +0000</pubDate><guid>https://edu.chainguard.dev/chainguard/libraries/introduction/network-requirements/</guid><description>&lt;p&gt;&lt;a href="https://edu.chainguard.dev/chainguard/libraries/introduction/overview/"&gt;Chainguard Libraries&lt;/a&gt; require specific network access to ensure secure delivery of hardened dependencies to your development environment. This guide details the domains and ports needed for authentication, package downloads, and verification tools.&lt;/p&gt;
&lt;h2 id="access-for-chainctl-and-other-tools" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;Access for chainctl and other tools&lt;/span&gt;
&lt;a href="#access-for-chainctl-and-other-tools" class="anchor" aria-label="Link to Access for chainctl and other tools" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;For initial configuration with chainctl and for in-process verification of
downloaded libraries, you must allow HTTPS access to the following domains:&lt;/p&gt;</description></item><item><title>Browsing Chainguard Libraries</title><link>https://edu.chainguard.dev/chainguard/libraries/introduction/browse/</link><pubDate>Thu, 03 Jul 2025 14:00:00 +0000</pubDate><guid>https://edu.chainguard.dev/chainguard/libraries/introduction/browse/</guid><description>&lt;p&gt;Chainguard Libraries is a malware-free catalog of Java, JavaScript, and Python
artifacts that have passed through multiple layers of security controls,
including malware and greyware scanning, building from source, cooldowns, and
additional policies.&lt;/p&gt;
&lt;p&gt;In the Chainguard Console, you can browse available
libraries and versions, inspect package details, and evaluate dependencies
before pulling them into your environment.&lt;/p&gt;
&lt;h2 id="access-libraries-in-the-chainguard-console" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;Access libraries in the Chainguard Console&lt;/span&gt;
&lt;a href="#access-libraries-in-the-chainguard-console" class="anchor" aria-label="Link to Access libraries in the Chainguard Console" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;Log in to the Chainguard Console at
&lt;a href="https://console.chainguard.dev/"&gt;https://console.chainguard.dev/&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>How does Chainguard Libraries plug into a developer's workflow?</title><link>https://edu.chainguard.dev/chainguard/libraries/introduction/how-libraries-plug-into-workflow/</link><pubDate>Sat, 02 Aug 2025 16:00:00 +0000</pubDate><guid>https://edu.chainguard.dev/chainguard/libraries/introduction/how-libraries-plug-into-workflow/</guid><description>&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;
&lt;iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/SBisxaL855k?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" title="YouTube video"&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;h2 id="transcript" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;Transcript&lt;/span&gt;
&lt;a href="#transcript" class="anchor" aria-label="Link to Transcript" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;Interviewer&lt;/strong&gt;: So Dustin, how does Libraries actually plug into a developer workflow?&lt;/p&gt;</description></item></channel></rss>