Threat Intelligence

Chainguard Hits 1 Billion Build Manifests: What It Means for Software Supply Chain Security

The Hacker News · 8 Sept 2026
Key Takeaway When choosing software vendors or cloud tools, ask whether they patch and rebuild continuously rather than on a slow release schedule, since this affects how quickly known vulnerabilities are fixed.

Chainguard, a security vendor focused on software supply chain protection, has announced it now produces more than 1 billion container build manifests, doubling its output over the past six months. The company's catalog has also grown to over 3,000 unique container images and 675,000 image versions.

Each build manifest represents a verified rebuild of a software component, triggered by things like a new version release, a security patch to an underlying library, or a new hardware architecture. Rather than treating security as a one-time check when software is downloaded, Chainguard's approach continuously rebuilds and re-verifies images as upstream changes occur, aiming to keep software secure every day it's in use, not just the day it was pulled. This is powered by their custom Linux operating system and build infrastructure, which produces artifacts with verifiable proof of how and where they were built.

For small and medium businesses, this reflects a broader industry trend: the tools and applications you rely on are increasingly built and patched through automated pipelines rather than occasional manual updates. Understanding whether your software vendors follow continuous security practices, rather than infrequent patch cycles, is becoming an important factor in assessing third-party risk.

supply chain security container security software patching vendor risk DevSecOps
Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.