If you are interested in what we are building re AI-Governance at Chainloop take a look at this article. AI adoption visibility through AI Coding Sessions and Session Alignment Scoring, enforcement through policies, compliance through controls.
https://t.co/TkRzbL9uWY
AI coding agents are writing your code. But who's governing them?
We just shipped support for AI agent configuration and session evidence. Every instruction file, tool invocation, model used, every file changed, captured, signed, and policy-enforceable.
https://t.co/U8TiPRpg1L
Busy week for supply chain security. I know we're all busy building. But it's about time we stop for a moment and re-evaluate our security foundations. Supply chain security should be a first-class concern, not a post-mortem talking point.
https://t.co/eYeT49q6A0
Last week Trivy got compromised. A security scanner, one of the most trusted in the ecosystem, quietly turned into a credential stealer. Pipelines kept running like nothing happened. We wrote about it.
https://t.co/joFNzgBEqv
Chainloop is joining @chainguard_dev Commercial Builds — hardened, zero CVEs, full provenance, FIPS-ready.
Enterprises shouldn't have to choose between shipping software and trusting what's beneath it.
https://t.co/l2dx1rndXf
A new version of Chainloop just dropped
With a new UI/UX foundation for what's to come, agentic policies and workflows support, new guardrails and security features, all of that is packed in this release.
https://t.co/BXVc70xCA2
There is a lot of fear with regards to the Cyber Resiliency Act (CRA), but we believe that in the end, most of the security practices are rooted in well-known security and development best practices seen before, let's break it down
https://t.co/Ra8BSwJN3w
🚀 The new @chainloopHQ major version is now available in the Bitnami catalog!
A CNCF project to secure software supply chains with in-toto attestations, ready to deploy via containers and Helm charts.
🔐 Need FedRAMP compliance with FIPS, STIG? Check 👉 https://t.co/MuZyLFzaS7
At @chainloopHQ we've made solid progress on foundational components like Policies or visibility with Prometheus 🔥 and @grafana 🚀
Also, on solidifying our on-prem/SaaS offerings with our work on SOC-2, FIPS, and air gap environments support 🤓 https://t.co/y4hzCTipIg
I am so excited to return to San Francisco after almost 3 years since I moved out.
I'll be at @RSAConference and would love to discuss your challenges in Software Supply Chain security. We got some cool demos, too! Let's chat :) https://t.co/VIpmFZ68os
We will be at #RSAC in San Francisco (May 6 - 9), an opportunity for you to see a demo of the upcoming @chainloopHQ Platform. We would love to discuss software supply chain security and get your insights. Contact us if you are interested or know someone who would be!
Chainloop was born open source, and today, we are reaffirming our commitment by joining @openssf. This will propel our mission of helping developers ship trusted software faster.
https://t.co/dIEr5bkrdO
Thanks to everyone who came to our talk at 3PM on Friday at @KubeCon_
The recording is not up yet, but in the meantime, check out our project and send feedback and comments!
https://t.co/dIEr5bkrdO
Chainloop is an Open Source Metadata Vault for your Software Supply Chain metadata, SBOMs, VEX, SARIF files, QA reports, and more.
From today, you can programmatically collect and enforce pieces of evidence from your Dagger pipeline!
https://t.co/1yaUTp8Tki