For the complete documentation index, see llms.txt.

Chainguard Libraries policies and security overview

Understand how Chainguard Libraries evaluates, verifies, and controls dependencies across supported ecosystems.
  1 min read

Learn how to verify Chainguard Library integrity, identify and remediate vulnerabilities, protect against malicious behavior, and apply configurable policies across Chainguard-built packages and protected upstream fallback packages.

  • Chainguard Library policies: Create and enforce rules that control which package versions your organization can pull, including cooldown settings, blocklists, allowlists, and deliberate exceptions.
  • Verification: Use chainctl libraries verify to confirm which dependencies were built by Chainguard and review their signed provenance and software bills of materials (SBOMs).
  • CVE remediation: Learn how Chainguard backports selected high- and critical-severity fixes to supported library versions and how to identify and use remediated releases.
  • Vulnerability scanners: Learn how common vulnerability scanners work with Chainguard Libraries and how to interpret findings for Chainguard-built and remediated dependencies.

Last updated: 2026-08-28 16:31