For the complete documentation index, see llms.txt.

Conceptual

What is software supply chain security
What is software supply chain security and why it matters: protect against attacks like SolarWinds with tools like Chainguard's SLSA-compliant containers and SBOMs
What makes a good SBOM?
An explanation of what makes a good SBOM
Chainguard glossary
Software supply chain security vocabulary
Verified organizations
An overview of how to verify your organization and the implications
What is a build horizon?
What a build horizon is and why enforcing maximum artifact age is a key practice for keeping software secure and up to date
What is OpenVEX?
A conceptual overview of OpenVex
False positives and false negatives with container image scanners
An overview of the formation of false positive and false negative vulnerability results in container image scanners