Close Menu

    Subscribe to Updates

    Get the latest creative news from infofortech

    What's Hot

    Exclusive: Chainguard extends Repository scanning and policies to Java, Python and containers

    June 25, 2026

    Google Will Open The Play Store To Outside Billing On June 30

    June 25, 2026

    Optimizing For Delivery And Visibility: A Content Marketing Perspective

    June 25, 2026
    Facebook X (Twitter) Instagram
    InfoForTech
    • Home
    • Latest in Tech
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    Facebook X (Twitter) Instagram
    InfoForTech
    Home»Innovation»Exclusive: Chainguard extends Repository scanning and policies to Java, Python and containers
    Innovation

    Exclusive: Chainguard extends Repository scanning and policies to Java, Python and containers

    InfoForTechBy InfoForTechJune 25, 2026No Comments4 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Exclusive: Chainguard extends Repository scanning and policies to Java, Python and containers
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email



    Secure software supply chain solution provider Chainguard Inc. today expanded its Chainguard Repository product with malware scanning, policy enforcement and visibility features that now cover Java packages, Python packages and container images.

    The update extends protections that previously applied only to JavaScript packages. Chainguard pitches the move as a way for security and platform teams to set guardrails once for an entire organization, so any artifact a developer or an artificial intelligence agent pulls already meets the company’s security and compliance bar.

    The expansion targets a problem the company says has accelerated alongside AI coding tools. Faster development has been matched by a steady run of supply chain attacks, including npm package compromises and credential-stealing worms reported in recent months. Teams typically stack scanners, artifact managers and policy engines to manage the risk, but Chainguard argues those tools act too late in the pipeline or demand constant upkeep.

    Chainguard’s proprietary scanner now analyzes upstream Python packages, Java packages and container images for malicious behavior in addition to JavaScript. The scanner sits at the repository level and removes the exposure window that occurs when checks run after an artifact has already been pulled.

    The scanner also flags “greyware,” a term Chainguard uses for packages that function as advertised while actually doing something malicious, for example harvesting credentials or sending large language model prompts to a third-party server. Chainguard says it blocks more than 70 greyware projects every week that would never pass a chief information security officer security review but elude traditional malware scanners.

    Repository’s built-in policy engine has been extended to the same artifact types, meaning consumption of containers, Python packages and Java packages can now be governed by policy. The change also brings an upstream fallback to Java and Python, allowing teams to pull scanned upstream packages that have passed a cool-down when Chainguard has not yet built a given package from source.

    Chainguard also said its JavaScript libraries reached general availability, completing the rollout of its three library ecosystems alongside Java and Python.

    New policy types accompany the expansion, available in open beta as of today. For containers, teams can block images that have reached end of life, restrict pulls to images with long-term support and set cool-downs that delay access to new versions. For libraries, Chainguard added custom blocking that prevents developers from pulling specific projects or versions, along with manual overrides across both product lines for cases where a team needs an artifact a policy would otherwise block.

    The company also added a preview mode that shows how a policy would affect current open-source consumption before it is enforced, plus reporting on which artifacts were blocked, which policies triggered the block and when.

    Founded in 2021, Chainguard raised $280 million in October at a reported valuation of $3.5 billion, bringing its total raised to roughly $892 million.

    Image: Chainguard/ChatGPT

    Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

    • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
    • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.

    About SiliconANGLE Media

    SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

    Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    InfoForTech
    • Website

    Related Posts

    Optimizing For Delivery And Visibility: A Content Marketing Perspective

    June 25, 2026

    Apple has reportedly worked through the foldable iPhone’s hinge problems, with production set to start next month

    June 25, 2026

    Best Prime Day Deals on LED Masks and Hair Growth Tools That Actually Work

    June 25, 2026

    HelloTwin launches ‘Digital Authority’ to bring governed AI agents to the enterprise

    June 24, 2026

    Why Enterprise SaaS Deals Actually Stall: The Internal Friction Of The Buying Committee

    June 24, 2026

    LastPass suffers another data breach, but this time your password vault is safe

    June 24, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202638 Views

    Microsoft is bringing an AI helper to Xbox consoles

    March 14, 202616 Views

    This is the tech that makes Volvo’s latest EV a major step forward

    January 24, 202616 Views

    Why Security Validation Is Becoming Agentic

    March 16, 202615 Views
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Advertisement
    About Us
    About Us

    Our mission is to deliver clear, reliable, and up-to-date information about the technologies shaping the modern world. We focus on breaking down complex topics into easy-to-understand insights for professionals, enthusiasts, and everyday readers alike.

    We're accepting new partnerships right now.

    Facebook X (Twitter) YouTube
    Most Popular

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202638 Views

    Microsoft is bringing an AI helper to Xbox consoles

    March 14, 202616 Views

    This is the tech that makes Volvo’s latest EV a major step forward

    January 24, 202616 Views
    Categories
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    • Latest in Tech
    © 2026 All Rights Reserved InfoForTech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.