惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Hugging Face - Blog
Hugging Face - Blog
腾讯CDC
阮一峰的网络日志
阮一峰的网络日志
博客园_首页
Last Week in AI
Last Week in AI
月光博客
月光博客
D
DataBreaches.Net
WordPress大学
WordPress大学
雷峰网
雷峰网
酷 壳 – CoolShell
酷 壳 – CoolShell
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园 - 叶小钗
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
U
Unit 42
Recent Announcements
Recent Announcements
宝玉的分享
宝玉的分享
MyScale Blog
MyScale Blog
C
Check Point Blog
F
Fortinet All Blogs
B
Blog
小众软件
小众软件
Vercel News
Vercel News
罗磊的独立博客
有赞技术团队
有赞技术团队

SiliconANGLE

Will agentic AI governance run amok? The lesson of Asimov’s Three Laws - SiliconANGLE AI + quantum, Amazon vs. Starlink and the wide-open US-China internet battle - SiliconANGLE Team Cymru launches Total Insights Feed to replace legacy threat intelligence lists - SiliconANGLE AI Mode in Chrome adds split-screen view to enhance the web search experience - SiliconANGLE Resolve AI raises $40M at $1.5B valuation to optimize production environments - SiliconANGLE How Zscaler and OpenAI turn zero-trust security into an AI accelerator - SiliconANGLE OpenAI ratchets up Codex's agentic capabilities to rival Claude Code - SiliconANGLE Anthropic launches Claude Opus 4.7 with coding, visual reasoning improvements - SiliconANGLE Slash raises $100M at a $1.4B valuation to expand AI-powered banking platform for online businesses - SiliconANGLE Canva unveils Canva AI 2.0, recasting its platform as an agentic system for work - SiliconANGLE Data center, consumer device chips boost TSMC’s revenue - SiliconANGLE Mission-critical security cannot be bolted on, says Oracle - SiliconANGLE Agentic infrastructure reshapes enterprise AI - SiliconANGLE Data quality, and data freedom, foundational for AI success - SiliconANGLE Data trust is a bedrock in successful, scalable AI outcomes - SiliconANGLE Google introduces new agentic AI-ready tools and resources for Android developers  - SiliconANGLE Agentic AI orchestration separates winners from laggards - SiliconANGLE Data-driven tools turning the tide against human trafficking - SiliconANGLE Achieving trusted AI development goes beyond 'vibes' - SiliconANGLE Impinj boosts edge computing power in updated R700 RAIN RFID reader - SiliconANGLE Certinia powers professional services with AI - SiliconANGLE Antioch prepares to accelerate simulated testing for autonomous robots after raising $8.5M - SiliconANGLE Developer tooling startup Expo nabs $45M investment - SiliconANGLE Solidroad lands $25M to bring AI to customer support interactions - SiliconANGLE DuploCloud lands compliance and AI governance certifications as enterprise buyers tighten scrutiny - SiliconANGLE Lua lands $5.8M to help businesses build and manage AI agent workforces - SiliconANGLE Best of frenemies: Oracle's and AWS' clouds unite with dedicated, private connectivity - SiliconANGLE NIST shifts National Vulnerability Database to risk-based triage as CVE submissions hit record levels - SiliconANGLE Cisco goes to the races with new Churchill Downs multiyear partnership - SiliconANGLE Susecon 2026 will tackle the future of open-source platforms - SiliconANGLE
Exclusive: Chainguard extends Repository scanning and pol...
by Duncan Riley · 2026-06-25 · via SiliconANGLE

Exclusive: Chainguard extends Repository scanning and policies to Java, Python and containers

Secure software supply chain solution provider Chainguard Inc. today expanded its Chainguard Repository product with malware scanning, policy enforcement and visibility features that now cover Java packages, Python packages and container images.

The update extends protections that previously applied only to JavaScript packages. Chainguard pitches the move as a way for security and platform teams to set guardrails once for an entire organization, so any artifact a developer or an artificial intelligence agent pulls already meets the company’s security and compliance bar.

The expansion targets a problem the company says has accelerated alongside AI coding tools. Faster development has been matched by a steady run of supply chain attacks, including npm package compromises and credential-stealing worms reported in recent months. Teams typically stack scanners, artifact managers and policy engines to manage the risk, but Chainguard argues those tools act too late in the pipeline or demand constant upkeep.

Chainguard’s proprietary scanner now analyzes upstream Python packages, Java packages and container images for malicious behavior in addition to JavaScript. The scanner sits at the repository level and removes the exposure window that occurs when checks run after an artifact has already been pulled.

The scanner also flags “greyware,” a term Chainguard uses for packages that function as advertised while actually doing something malicious, for example harvesting credentials or sending large language model prompts to a third-party server. Chainguard says it blocks more than 70 greyware projects every week that would never pass a chief information security officer security review but elude traditional malware scanners.

Repository’s built-in policy engine has been extended to the same artifact types, meaning consumption of containers, Python packages and Java packages can now be governed by policy. The change also brings an upstream fallback to Java and Python, allowing teams to pull scanned upstream packages that have passed a cool-down when Chainguard has not yet built a given package from source.

Chainguard also said its JavaScript libraries reached general availability, completing the rollout of its three library ecosystems alongside Java and Python.

New policy types accompany the expansion, available in open beta as of today. For containers, teams can block images that have reached end of life, restrict pulls to images with long-term support and set cool-downs that delay access to new versions. For libraries, Chainguard added custom blocking that prevents developers from pulling specific projects or versions, along with manual overrides across both product lines for cases where a team needs an artifact a policy would otherwise block.

The company also added a preview mode that shows how a policy would affect current open-source consumption before it is enforced, plus reporting on which artifacts were blocked, which policies triggered the block and when.

Founded in 2021, Chainguard raised $280 million in October at a reported valuation of $3.5 billion, bringing its total raised to roughly $892 million.

Image: Chainguard/ChatGPT

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.

About SiliconANGLE Media

SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.