Conceptual
What is software supply chain security
What is software supply chain security and why it matters: protect against attacks like SolarWinds with tools like Chainguard's SLSA-compliant containers and SBOMs
What makes a good SBOM?An explanation of what makes a good SBOM
Chainguard glossarySoftware supply chain security vocabulary
Verified organizationsAn overview of how to verify your organization and the implications
What is a build horizon?What a build horizon is and why enforcing maximum artifact age is a key practice for keeping software secure and up to date
What is OpenVEX?A conceptual overview of OpenVex
False positives and false negatives with container image scannersAn overview of the formation of false positive and false negative vulnerability results in container image scanners