<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Build Pinning on</title><link>https://edu.chainguard.dev/tags/build-pinning/</link><description>Recent content in Build Pinning on</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><copyright>Copyright (c) 2023 Chainguard</copyright><lastBuildDate>Wed, 19 Aug 2026 08:04:00 +0000</lastBuildDate><atom:link href="https://edu.chainguard.dev/tags/build-pinning/index.xml" rel="self" type="application/rss+xml"/><item><title>Manage build pinning for Chainguard Libraries</title><link>https://edu.chainguard.dev/chainguard/libraries/build-pinning/</link><pubDate>Wed, 19 Aug 2026 08:04:00 +0000</pubDate><guid>https://edu.chainguard.dev/chainguard/libraries/build-pinning/</guid><description>&lt;p&gt;Chainguard Libraries can serve a package version as either a Chainguard-built artifact or an &lt;a href="https://edu.chainguard.dev/chainguard/libraries/overview/#upstream-fallback-and-controls"&gt;upstream artifact that is scanned and proxied through Chainguard&lt;/a&gt;. Chainguard-built artifacts may have different checksums for the same version of the upstream artifact. If your lockfile records an upstream checksum and Chainguard later builds that package, your package manager can fail with integrity errors upon dependency resolution.&lt;/p&gt;
&lt;p&gt;Build pinning keeps library artifacts stable when Chainguard publishes a new build of a package version you previously pulled from the scanned upstream fallback. Chainguard-built artifacts are always the default and take priority when available. Pinning only affects the exact package version already pinned. When enabled, Chainguard remembers which upstream versions your organization pulled and continues serving those specific versions even if a new Chainguard build is available, until you remove the pin. Moving to a different version of the package is unaffected; since that version was never pinned, it resolves fresh and Chainguard’s build is served by default.&lt;/p&gt;</description></item></channel></rss>