software supply chain
Chainguard
|
Mar 18, 2026
The software supply chain startup is also now working with ISVs like Elastic and GitLab to harden their software as well as OSS.
"SBOMs describe what ends up in a piece of software, not how it got there. That distinction matters because..."
The malicious code creates a 'cascading compromise effect' into dependent ecosystems across npm's registry.
The malware "weaponized AI CLI tools (including Claude, Gemini, and q) to aid in reconnaissance and data exfiltration"
Google's new open source platform will shield popular dependencies with automations and data visibility tools.