<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Conceptual on</title><link>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/tags/conceptual/</link><description>Recent content in Conceptual on</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><copyright>Copyright (c) 2023 Chainguard</copyright><lastBuildDate>Mon, 28 Sep 2026 16:33:22 +0000</lastBuildDate><atom:link href="https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/tags/conceptual/index.xml" rel="self" type="application/rss+xml"/><item><title>Provision Chainguard users with SCIM</title><link>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/platform/administration/custom-idps/scim-provisioning/scim-overview/</link><pubDate>Fri, 14 Aug 2026 00:00:00 +0000</pubDate><guid>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/platform/administration/custom-idps/scim-provisioning/scim-overview/</guid><description>&lt;p&gt;System for Cross-domain Identity Management (SCIM) is an open standard for automating the exchange of user identity information between systems. Chainguard uses SCIM to create and deactivate user accounts based on your identity provider (IdP). Connect your IdP&amp;rsquo;s SCIM provisioning once; from then on, assigning a user to the application provisions them, and deactivating or unassigning them removes their Chainguard access. Accounts follow your IdP, so you manage access in one place.&lt;/p&gt;</description></item><item><title>Chainguard shared responsibility model</title><link>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/chainguard/containers/concepts/shared-responsibility-model/</link><pubDate>Thu, 17 Oct 2024 11:07:52 +0200</pubDate><guid>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/chainguard/containers/concepts/shared-responsibility-model/</guid><description>&lt;p&gt;Chainguard’s mission is to be the safe source for open source. As part of this mission, Chainguard builds all of our packages and images from upstream open source code and delivers the resulting artifacts to our customers. There are three distinct parties involved here: &lt;strong&gt;Upstream&lt;/strong&gt; projects, &lt;strong&gt;Chainguard&lt;/strong&gt;, and &lt;strong&gt;Customers&lt;/strong&gt;; each of these parties share some measure of responsibility across a few dimensions.&lt;/p&gt;
&lt;center&gt;&lt;img src="csrm-1.png" alt="Diagram representing the Chainguard-based open source software supply chain" style="width:1050px;"&gt;&lt;/center&gt;
&lt;br /&gt;
&lt;p&gt;This guide is an overview of Chainguard&amp;rsquo;s Shared Responsibility Model: a framework that outlines the security responsibilities of upstream open source software projects, Chainguard, and its customers. The dimensions of shared responsibility this guide covers are:&lt;/p&gt;</description></item><item><title>Strategies for minimizing your CVE risk</title><link>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/chainguard/containers/security-and-compliance/vulnerability-management/cve-risk/</link><pubDate>Thu, 16 Nov 2023 11:07:52 +0200</pubDate><guid>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/chainguard/containers/security-and-compliance/vulnerability-management/cve-risk/</guid><description>&lt;p&gt;&lt;a href="https://www.chainguard.dev/supply-chain-security-101/what-is-a-cve#what-is-a-cve"&gt;Common vulnerabilities and exposures&lt;/a&gt; (CVEs) are an increasing concern for developers and organizations, which is why Chainguard developed its minimal container images that reduce the attack surface. A new CVE in a widely-used application or a vulnerability scan with numerous positive results can significantly impact security posture, compliance requirements, and development timelines.&lt;/p&gt;
&lt;p&gt;Chances are, your software has already been impacted by a CVE. It&amp;rsquo;s likely there are active CVEs in software you are using. After all, there are software vulnerabilities currently in existence that haven&amp;rsquo;t even been discovered (known as zero-day vulnerabilities). With that said, this conceptual article aims to highlight a few practices and strategies you and your team can use to reduce the risk of CVEs on your software. It also includes a section on &lt;a href="https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/chainguard/containers/security-and-compliance/vulnerability-management/cve-risk/#recommended-tools"&gt;tools recommended by Chainguard&lt;/a&gt; that can help to reduce your attack surface area and minimize your risk of CVEs.&lt;/p&gt;</description></item><item><title>False positives and false negatives with container image scanners</title><link>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/chainguard/containers/security-and-compliance/working-with-scanners/false-results/</link><pubDate>Thu, 14 Sep 2023 16:59:04 +0000</pubDate><guid>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/chainguard/containers/security-and-compliance/working-with-scanners/false-results/</guid><description>&lt;p&gt;A &lt;em&gt;vulnerability scanner&lt;/em&gt; is a tool that analyzes your software components and reports any &lt;a href="https://www.chainguard.dev/supply-chain-security-101/what-is-a-cve"&gt;CVEs&lt;/a&gt; it finds. Using a vulnerability scanner to find CVEs that impact your system is a critical step in &lt;a href="https://www.chainguard.dev/supply-chain-security-101/cve-remediation-explained"&gt;software vulnerability remediation&lt;/a&gt;, but as you begin to triage scanner-reported vulnerabilities, you may find that your scanner&amp;rsquo;s results are not perfectly accurate.&lt;/p&gt;
&lt;p&gt;The goal of a vulnerability scanner is to identify the vulnerabilities that impact your container images, which can be considered &lt;em&gt;true positive vulnerabilities&lt;/em&gt;. Sometimes, a scanner surfaces CVEs which are not actually impacting your images, which are called &lt;em&gt;false positive vulnerabilities&lt;/em&gt;. Your scanner may even miss some vulnerabilities that are impacting you, termed &lt;em&gt;false negative vulnerabilities&lt;/em&gt;.&lt;/p&gt;</description></item><item><title>What is software supply chain security</title><link>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/software-security/what-is-software-supply-chain-security/</link><pubDate>Thu, 04 Aug 2022 15:21:01 +0200</pubDate><guid>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/software-security/what-is-software-supply-chain-security/</guid><description>&lt;p&gt;&lt;em&gt;An earlier version of this material was published in the &lt;a href="https://learning.edx.org/course/course-v1:LinuxFoundationX&amp;#43;LFS182x&amp;#43;2T2022/block-v1:LinuxFoundationX&amp;#43;LFS182x&amp;#43;2T2022&amp;#43;type@sequential&amp;#43;block@1623557b9fc849d5a1e38177502b1499/block-v1:LinuxFoundationX&amp;#43;LFS182x&amp;#43;2T2022&amp;#43;type@vertical&amp;#43;block@825d4b442d1346ba8e9d7c3b4f765e76"&gt;first chapter&lt;/a&gt; of the Linux Foundation &lt;a href="https://learning.edx.org/course/course-v1:LinuxFoundationX&amp;#43;LFS182x&amp;#43;2T2022/home"&gt;Sigstore course&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Software producers have a supply chain just like manufacturing businesses have a supply chain. And just like manufacturers require physical inputs and then perform a manufacturing process to build a finished product, so do software producers, whether the producer is a company or individual. In other words, a software producer uses components, developed by third parties and themselves, and technologies to write, build, and distribute software. A compromise introduced anywhere in this chain is an example of a software supply chain security issue. Tools and practices like those implemented in Chainguard&amp;rsquo;s containers help organizations protect against these risks through built-in SBOMs, provenance attestations, and SLSA compliance.&lt;/p&gt;</description></item><item><title>SCIM user provisioning</title><link>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/platform/administration/custom-idps/scim-provisioning/</link><pubDate>Fri, 14 Aug 2026 00:00:00 +0000</pubDate><guid>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/platform/administration/custom-idps/scim-provisioning/</guid><description/></item><item><title>Using Trivy to scan software artifacts</title><link>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/chainguard/containers/security-and-compliance/working-with-scanners/trivy-tutorial/</link><pubDate>Wed, 03 Jul 2024 20:00:00 +0200</pubDate><guid>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/chainguard/containers/security-and-compliance/working-with-scanners/trivy-tutorial/</guid><description>&lt;p&gt;&lt;a href="https://github.com/aquasecurity/trivy"&gt;Trivy&lt;/a&gt; is a vulnerability scanner for a wide variety of software artifacts and deployments. Trivy is written in the Go programming language and is maintained by &lt;a href="https://www.aquasec.com/"&gt;Aqua Security&lt;/a&gt;. Trivy targets container images, VMs, filesystems, remote GitHub repositories, and Kubernetes and Amazon Web Services deployments. The tool can be used to detect known vulnerabilities (CVEs), generate SBOMs, analyze licenses, and scan for misconfigurations and exposed secrets. Trivy can be installed from &lt;a href="https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/chainguard/containers/security-and-compliance/working-with-scanners/trivy-tutorial/#package-managers"&gt;package managers&lt;/a&gt; or as a &lt;a href="https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/chainguard/containers/security-and-compliance/working-with-scanners/trivy-tutorial/#binary-installation"&gt;binary&lt;/a&gt;, and can also be run as a &lt;a href="https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/chainguard/containers/security-and-compliance/working-with-scanners/trivy-tutorial/#container-image"&gt;container image&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Verified organizations</title><link>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/platform/administration/iam-organizations/verified-orgs/</link><pubDate>Tue, 15 Aug 2023 14:22:23 -0700</pubDate><guid>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/platform/administration/iam-organizations/verified-orgs/</guid><description>&lt;p&gt;The Chainguard platform organizes resources in a hierarchical structure called &lt;a href="https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/platform/administration/iam-organizations/overview-of-chainguard-iam-model/"&gt;IAM organizations&lt;/a&gt;. A customer typically uses one root-level &lt;em&gt;organization&lt;/em&gt; to manage its Chainguard resources.&lt;/p&gt;
&lt;h2 id="about-verified-organizations" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;About verified organizations&lt;/span&gt;
&lt;a href="#about-verified-organizations" class="anchor" aria-label="Link to About verified organizations" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;A verified organization is a root-level organization whose name Chainguard has confirmed and reserved for you. Only one organization on the Chainguard platform can hold a given verified name. Because of that, you can use the name anywhere you would otherwise use the organization&amp;rsquo;s unique ID.&lt;/p&gt;</description></item><item><title>Why apk</title><link>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/open-source/wolfi/apk-package-manager/</link><pubDate>Wed, 06 Jul 2022 08:49:31 +0000</pubDate><guid>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/open-source/wolfi/apk-package-manager/</guid><description>&lt;p&gt;&lt;a href="https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/open-source/build-tools/apko/getting-started-with-apko/"&gt;apko&lt;/a&gt; uses the &lt;a href="https://wiki.alpinelinux.org/wiki/Package_management"&gt;apk&lt;/a&gt; package manager to compose container images based on declarative pipelines.
The apk format was introduced by &lt;a href="https://www.alpinelinux.org/"&gt;Alpine Linux&lt;/a&gt; to address specific design requirements that could not be met by existing package managers such as &lt;code&gt;apt&lt;/code&gt; and &lt;code&gt;dnf&lt;/code&gt;. But what makes it different, and why does that matter in the context of apko?&lt;/p&gt;
&lt;h2 id="manipulating-the-desired-state" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;Manipulating the desired state&lt;/span&gt;
&lt;a href="#manipulating-the-desired-state" class="anchor" aria-label="Link to Manipulating the desired state" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;In traditional package managers like &lt;code&gt;dnf&lt;/code&gt; and &lt;code&gt;apt&lt;/code&gt;, requesting the installation or removal of packages causes those packages to be directly installed or removed, after a consistency check.&lt;/p&gt;</description></item><item><title>Overview of tag-based Custom Assembly</title><link>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/chainguard/containers/custom-assembly/tag-based-custom-assembly/</link><pubDate>Mon, 28 Sep 2026 16:33:22 +0000</pubDate><guid>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/chainguard/containers/custom-assembly/tag-based-custom-assembly/</guid><description>&lt;p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note&lt;/strong&gt;: Tag-based Custom Assembly is in beta. Contact your Chainguard account team to enable it for your organization.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/p&gt;
&lt;p&gt;Standard &lt;a href="https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/chainguard/containers/custom-assembly/overview/"&gt;Custom Assembly&lt;/a&gt; applies one customization to every tag in a repository. This fails for images that ship several language or runtime versions side by side, because a package built for one version can&amp;rsquo;t install on the others.&lt;/p&gt;
&lt;p&gt;For example, the &lt;code&gt;python&lt;/code&gt; image publishes tags for Python 3.11, 3.12, 3.13, and 3.14. The &lt;code&gt;py3.13-typer&lt;/code&gt; package depends on Python 3.13. If you add it with standard Custom Assembly, every tag tries to install it, and the 3.11, 3.12, and 3.14 builds fail.&lt;/p&gt;</description></item><item><title>What is the future of the Chainguard Factory?</title><link>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/platform/factory/future-of-factory/</link><pubDate>Sat, 02 Aug 2025 16:00:00 +0000</pubDate><guid>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/platform/factory/future-of-factory/</guid><description>&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;
&lt;iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/eF9EYK6AKPA?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" title="YouTube video"&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;h2 id="transcript" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;Transcript&lt;/span&gt;
&lt;a href="#transcript" class="anchor" aria-label="Link to Transcript" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;Interviewer&lt;/strong&gt;: So what do you see as the future for the Factory?&lt;/p&gt;</description></item></channel></rss>