<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Chainguard Libraries policies and security on</title><link>https://edu.chainguard.dev/chainguard/libraries/policies-and-security/</link><description>Recent content in Chainguard Libraries policies and security on</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><copyright>Copyright (c) 2023 Chainguard</copyright><lastBuildDate>Thu, 03 Jul 2025 12:00:00 +0000</lastBuildDate><atom:link href="https://edu.chainguard.dev/chainguard/libraries/policies-and-security/index.xml" rel="self" type="application/rss+xml"/><item><title>Chainguard Libraries verification</title><link>https://edu.chainguard.dev/chainguard/libraries/policies-and-security/verification/</link><pubDate>Thu, 03 Jul 2025 12:00:00 +0000</pubDate><guid>https://edu.chainguard.dev/chainguard/libraries/policies-and-security/verification/</guid><description>&lt;p&gt;Chainguard&amp;rsquo;s &lt;code&gt;chainctl&lt;/code&gt; tool with the command &lt;a href="https://edu.chainguard.dev/chainguard/chainctl/chainctl-docs/chainctl_libraries_verify/"&gt;&lt;code&gt;libraries verify&lt;/code&gt;&lt;/a&gt; verifies
which of your language ecosystem dependencies were built by Chainguard,
providing critical visibility into your software supply chain security. By
verifying binary artifacts across your projects and repositories, you can confirm which dependencies came from Chainguard&amp;rsquo;s hardened build environment, identify opportunities to
improve security posture, and maintain compliance with supply chain security
policies.&lt;/p&gt;
&lt;p&gt;For packages that aren&amp;rsquo;t built by Chainguard, you can enable &lt;a href="https://edu.chainguard.dev/chainguard/libraries/introduction/overview/#upstream-fallback-and-controls"&gt;upstream fallback&lt;/a&gt; to apply additional configurable security controls.&lt;/p&gt;</description></item><item><title>CVE remediation for Chainguard Libraries</title><link>https://edu.chainguard.dev/chainguard/libraries/policies-and-security/cve-remediation/</link><pubDate>Thu, 11 Sep 2025 00:00:00 +0000</pubDate><guid>https://edu.chainguard.dev/chainguard/libraries/policies-and-security/cve-remediation/</guid><description>&lt;p&gt;CVE remediation for Chainguard Libraries provides protection against
critical and high CVEs. Applications often rely on older versions of libraries,
but upstream maintainers may not apply and release patches for those versions.
Chainguard addresses this gap by backporting vulnerability fixes
from newer releases to older releases, particularly in cases where maintainers
are no longer able to support and provide fixes.&lt;/p&gt;
&lt;p&gt;CVE remediation helps reduce risk for organizations that cannot always upgrade
quickly, especially when moving to a newer version would introduce disruptive
changes. Remediated artifacts are published as incremental patch versions, allowing teams to take a targeted fix for a CVE without taking on a broader upgrade at the same time.&lt;/p&gt;</description></item><item><title>Vulnerability scanners and Chainguard Libraries</title><link>https://edu.chainguard.dev/chainguard/libraries/policies-and-security/scanners/</link><pubDate>Sat, 04 Oct 2025 12:00:00 +0000</pubDate><guid>https://edu.chainguard.dev/chainguard/libraries/policies-and-security/scanners/</guid><description>&lt;p&gt;Vulnerability scanners enable you to understand the potential security risks
from libraries used within your applications.&lt;/p&gt;
&lt;p&gt;Chainguard Libraries provides a trusted source for libraries typically
downloaded from public repositories. Chainguard Libraries are rebuilt from the
upstream open source project code repository content only. This prevents malware
without published source code and reduces almost all risk for software supply
chain attacks. In addition, some library versions are available with CVE fixes
applied. These fixes are backported from newer versions of the open source
project by Chainguard to create new libraries of older versions containing these
newer changes. Find more details in &lt;a href="https://edu.chainguard.dev/chainguard/libraries/policies-and-security/cve-remediation/"&gt;CVE
Remediation&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Manage build pinning for Chainguard Libraries</title><link>https://edu.chainguard.dev/chainguard/libraries/policies-and-security/build-pinning/</link><pubDate>Wed, 19 Aug 2026 08:04:00 +0000</pubDate><guid>https://edu.chainguard.dev/chainguard/libraries/policies-and-security/build-pinning/</guid><description>&lt;p&gt;Chainguard Libraries can serve a package version as either a Chainguard-built artifact or an &lt;a href="https://edu.chainguard.dev/chainguard/libraries/introduction/overview/#upstream-fallback-and-controls"&gt;upstream artifact that is scanned and proxied through Chainguard&lt;/a&gt;. Chainguard-built artifacts may have different checksums for the same version of the upstream artifact. If your lockfile records an upstream checksum and Chainguard later builds that package, your package manager can fail with integrity errors upon dependency resolution.&lt;/p&gt;
&lt;p&gt;Build pinning keeps library artifacts stable when Chainguard publishes a new build of a package version you previously pulled from the scanned upstream fallback. Chainguard-built artifacts are always the default and take priority when available. Pinning only affects the exact package version already pinned. When enabled, Chainguard remembers which upstream versions your organization pulled and continues serving those specific versions even if a new Chainguard build is available, until you remove the pin. Moving to a different version of the package is unaffected; since that version was never pinned, it resolves fresh and Chainguard’s build is served by default.&lt;/p&gt;</description></item></channel></rss>