The trusted source for open source (& memes).

Three weeks ago, we announced Athena, the industry coalition to protect open source software from AI attacks. Here’s where Athena stands today: • 40,000+ vulnerabilities processed, doubled since launch • 42% are critical- or high-severity • 86% are network reachable, meaning attackers can trigger them remotely • ~7% sit in packages more than five years old Frontier models are finding these vulnerabilities faster than any single team can respond. No one company can solve this alone. Today, we’re welcoming new members to the coalition: @Akamai, @BlackDuck_SW, @CycodeHQ, @jfrog, @MorganStanley, @qualys, @upwindsecurity, and @Zafran_io. More organizations mean more findings pooled and de-duplicated, which means fewer unique flaws left for an attacker to find first. It means more protection for the critical infrastructure we all rely on. Learn more: chainguard.dev/unchained/exp…
2
8
21
1,992
The package looks safe... the docs read fine... so it's safe, right? Wrong. @erikaheidi shares how to avoid malicious packages: piped.video/watch?v=5Tu_XOoQ…
4
3
338
if your agents could talk...
5
331
First (and only💥) to do it ✅ Chainguard now delivers an approved hybrid post-quantum key exchange inside a FIPS 140-3 module, because you shouldn't have to choose between compliance and quantum readiness. Rollout to our FIPS container images starts October 1 on an opt-in basis, so teams can migrate on their own schedules. Zayn Lohit shares more: chainguard.dev/unchained/ann…
2
7
251
Diane Morgan, writer, actor, and director best known as Philomena Cunk, is bringing the hard-hitting questions to #Assemble26LDN on October 14. Register here: chainguard.dev/assemble-lond…
4
14
2,382
Spotted in @TheEconomist: A whoooole lotta ⬜️nothing⬜️
1
6
247
📣 Chainguard is officially a CVE Numbering Authority 📣 Frontier AI models are finding latent bugs in widely used open source software that scanners and years of expert review couldn't detect. The Common Vulnerabilities and Exposures (CVE®) Program has authorized Chainguard to assign CVEs for vulnerabilities processed through Athena, our coalition to protect open source from AI attacks. That means organizations and open source maintainers can more easily assess their exposure, reduce false positives, and take action on the fixes coming out of Athena. Learn more: prnewswire.com/news-releases…
4
18
648
Chainguard ⛓️ retweeted
A compromised package is more than a code problem. If it can reach long-lived credentials, it can keep moving. On Zero-Shot Learning, Matt Moore (@mattomata) of @chainguard_dev and I discuss AI agents in the software supply chain. “Credentials let you launch the next wave.” Lock in: piped.video/watch?v=ZlK4gRYt…
3
8
292
how life feels when you have nothing to patch and everything to build ✨
4
11
389
Chainguard ⛓️ retweeted
Credential leaks continue to happen, even though the controls for human identity have been available for years. Matt Moore, co-founder and CTO of @chainguard_dev, joins @NancyzWang and Dev Tagare to discuss how security changes when credentials belong to people, machines, and AI agents moving through the SDLC. The controls differ, but the standard is the same; credentials should be protected and scoped, and every use should be attributable. ✅ People need MFA, secure credential storage, and SSO where it fits ✅ AI agents need short-lived, least-privilege access ✅ Keep raw secrets out of agent context where possible, and broker access at runtime ✅ Trace actions to the agent and its authorizing human or service The gap sits between what teams know works and what's actually deployed. 🎧Listen to the full conversation here: bit.ly/4hjYOEa
2
4
196
Story time just got twice as good 📚 In celebration of Hispanic Heritage Month, Los Guardians (one of our Chainguard Communities) rounded up the Spanish and bilingual children's books they love most. Swipe for the full list 💜
1
1
248
▶️ Now playing: what engineers actually want to hear (not emergency triage calls, PagerDuty pings, and Slack alert storms). 🧘
2
5
333
AI didn't invent supply chain attacks... it just made them easier and cheaper to execute 👀 Erika Heidi shares four AI-assisted attack patterns to watch out for: piped.video/watch?v=5Tu_XOoQ…
3
7
449
Agent skills are spreading across orgs faster than anyone can secure them 🔒 They live in Slack threads, shared drives, and dev instances with no versioning, access controls, or audit trails. Join @psmyth01 on September 22 to learn how Chainguard Agent Skills provides your organization with a safe and trusted source for agent skills 🤝 RSVP: chainguard.dev/events/learni…
1
1
9
305
Time is money💰 ... and most teams spend their time triaging instead of shipping. But not these customers! 👇
1
1
5
285
"When Mythos finds zero-days, the coalition coordinates, pulls the findings, verifies them, builds the mitigations, pushes them upstream, and the whole ecosystem gets stronger." Protecting open source software from AI attacks takes all of us. The @BlackDuck_SW team talks about why they're proud members of Athena: chainguard.dev/unchained/ath…
3
12
440
Your software supply chain *should* be boring. But your engineers are chasing CVEs, tracing malware, and racing to contain zero-days instead of tackling the roadmap. Chainguard keeps malicious packages out, eliminates CVEs from production, and remediates zero-days before they go public. In other words, we make nothing happen… so you can make 💥everything💥 happen.
4
8
665
🎬 Lights, camera, Assemble 🎬 As Philomena Cunk, she stuns experts by asking about the significance of the printing press, whether the Romans knew they were Romans, and how the pyramids were built. Actor, writer, and director Diane Morgan is also going to stun the #Assemble26LDN crowd when she closes out the event on October 14. Save your spot alongside the leaders building the future of secure software: chainguard.dev/assemble-lond…
2
2
7
294