CHAINGUARD LIBRARIES

Malware-free open source dependencies

Chainguard Libraries is a malware-free catalog of language dependencies that replaces your team’s reliance on public registries. When the next attack hits npm or PyPI, your engineers keep building rather than pulling apart dependency trees.

image
4.8 Stars on G2

The world’s leading companies trust Chainguard

  • customer logo
  • customer logo
  • customer logo
  • customer logo
  • customer logo
  • customer logo
  • customer logo
  • customer logo
  • Snap logo.
  • customer logo
  • customer logo
  • customer logo
  • customer logo
  • Logo of Chainguard customer SolarWinds
  • customer logo
  • customer logo
  • customer logo
  • VP Bank logo.
  • customer logo
  • customer logo
  • Logo of Chainguard customer Ironclad
  • Logo of Chainguard customer Wistia.
  • customer logo
  • customer logo
  • logo of Chainguard customer logicmonitor
  • Logo of Chainguard customer Fortinet
  • customer logo
  • customer logo
  • customer logo
  • customer logo

Malwhere? Not here.

Whether it’s a malicious backdoored binary, install-time script, or typosquatted package, Chainguard Libraries are safe from the malware compromises that have made headlines over the last few months.

axios

Nation-state actors attacked the HTTP requests package in npm that’s used 400M+ times a month.

litellm

Attackers hit a key AI gateway package in PyPI with 280M+ monthly downloads.

Shai-Hulud

A worm spread through ~800 npm packages and harvested thousands of private credentials.

tanstack

A typosquatted npm dependency duped @TanStack users with four malicious versions.

elementary-data

Attackers released malicious version of an AI project with 1.1M+ monthly downloads.

chalk

Bad actors released 18 npm packages with more than 10B+ collective monthly downloads.

Open source language ecosystem

Chainguard replaces your public registry endpoints

Python

Turn off live access to PyPI with a full catalog of safe dependencies built, curated, and remediated by Chainguard.

Learn more

JavaScript

Swap npm for Chainguard, removing your team’s fears that the next installed package contains credential harvesting malware.

Learn more

Java

Trade Maven Central for a trusted, verified dependencies from Chainguard so your team can ship without supply chain risk.

Read docs

More coming soon

Chainguard is building additional ecosystems based on customer demand. Have a request? Reach out to our team.

Contact us

Security or dev velocity. Why choose?

Stop reacting to supply chain attacks and start preventing them. Chainguard Libraries is a malware-free catalog of open source dependencies that allows your team to ship without inheriting someone else’s security compromise.

Use libraries from verified source in a SLSA L2-compliant factory to neutralize malware, ensuring the binary always matches the source bit-for-bit.

Prevent malware by design

Stop supply chain attacks before they ever reach your environment with a safe catalog of open source packages that are built, curated, and remediated by Chainguard.

Our isolated build process spares your team from costly malware incident response, protecting your development velocity while everyone else panics.

Eliminate “are we impacted?” fire drills

Avoid the incident response scramble when the next attack hits so your engineers stay on roadmap work instead of pulling apart dependency trees at 2 a.m.

Prove you’re secure without the toil. Every library comes with automated provenance and signed SBOMs, giving auditors real verification of component integrity.

Streamline compliance 
evidence

Prove to auditors that your software supply chain is secure with signed verification that your open source dependencies match their source code bit-for-bit.

Works with your existing tooling

Works with your existing tooling

Chainguard Libraries works with your existing artifact managers and workflows. Each package has the same functionality as the public upstream version, so there are no breaking changes. Your engineers won’t notice a difference.

Embedded policies protect what’s not built

Embedded policies protect what’s not built

With the Chainguard Repository, you get every package you need on day one. Configure cooldowns, block packages with known CVEs, or enforce licenses to meet your team’s standards. Your supply chain security improves overnight.

Learn more about Chainguard Repository
Signed, sealed, and dependable

Signed, sealed, and dependable

Every version comes built with full provenance and signed SBOMs, giving you indisputable proof that your dependencies came from the SLSA L3-compliant Chainguard Factory and not a vulnerable maintainer account.

Patched critical and high CVEs in Python

Patched critical and high CVEs in Python

We backport critical and high-severity CVE fixes from upstream versions and test every remediation to ensure the issue is successfully resolved, letting you stay secure while planning your next major version upgrade.

Read about how we do it

Why Chainguard?

Trusted libraries you can’t get elsewhere

Proactive malware prevention

Stay protected from malicious attacks often inserted during the build and distribution stages of package creation.

Verification by default

Every library is built in a secure, SLSA L3 build system with full provenance and signed SBOMs to prove supply chain integrity.

System scale

Access to hundreds of thousands of versions of libraries across Java, Python, and JavaScript, with more being added every week.

Expertise and experience

The leading open source minds driving the industry forward, delivering new innovations for developers.

CG System promptExecute command

$ chainguard learn --more

contact us

Frequently Asked Questions