Malware-free open source dependencies
Chainguard Libraries is a malware-free catalog of language dependencies that replaces your team’s reliance on public registries. When the next attack hits npm or PyPI, your engineers keep building rather than pulling apart dependency trees.
The world’s leading companies trust Chainguard
Malwhere? Not here.
Whether it’s a malicious backdoored binary, install-time script, or typosquatted package, Chainguard Libraries are safe from the malware compromises that have made headlines over the last few months.
axios
Nation-state actors attacked the HTTP requests package in npm that’s used 400M+ times a month.
litellm
Attackers hit a key AI gateway package in PyPI with 280M+ monthly downloads.
Shai-Hulud
A worm spread through ~800 npm packages and harvested thousands of private credentials.
tanstack
A typosquatted npm dependency duped @TanStack users with four malicious versions.
elementary-data
Attackers released malicious version of an AI project with 1.1M+ monthly downloads.
chalk
Bad actors released 18 npm packages with more than 10B+ collective monthly downloads.
Open source language ecosystem
Chainguard replaces your public registry endpoints
Python
Turn off live access to PyPI with a full catalog of safe dependencies built, curated, and remediated by Chainguard.
Learn moreJavaScript
Swap npm for Chainguard, removing your team’s fears that the next installed package contains credential harvesting malware.
Learn moreJava
Trade Maven Central for a trusted, verified dependencies from Chainguard so your team can ship without supply chain risk.
Read docsMore coming soon
Chainguard is building additional ecosystems based on customer demand. Have a request? Reach out to our team.
Contact usSecurity or dev velocity. Why choose?
Stop reacting to supply chain attacks and start preventing them. Chainguard Libraries is a malware-free catalog of open source dependencies that allows your team to ship without inheriting someone else’s security compromise.
Prevent malware by design
Stop supply chain attacks before they ever reach your environment with a safe catalog of open source packages that are built, curated, and remediated by Chainguard.
Eliminate “are we impacted?” fire drills
Avoid the incident response scramble when the next attack hits so your engineers stay on roadmap work instead of pulling apart dependency trees at 2 a.m.
Streamline compliance evidence
Prove to auditors that your software supply chain is secure with signed verification that your open source dependencies match their source code bit-for-bit.
Works with your existing tooling
Chainguard Libraries works with your existing artifact managers and workflows. Each package has the same functionality as the public upstream version, so there are no breaking changes. Your engineers won’t notice a difference.
Embedded policies protect what’s not built
With the Chainguard Repository, you get every package you need on day one. Configure cooldowns, block packages with known CVEs, or enforce licenses to meet your team’s standards. Your supply chain security improves overnight.
Learn more about Chainguard RepositorySigned, sealed, and dependable
Every version comes built with full provenance and signed SBOMs, giving you indisputable proof that your dependencies came from the SLSA L3-compliant Chainguard Factory and not a vulnerable maintainer account.
Patched critical and high CVEs in Python
We backport critical and high-severity CVE fixes from upstream versions and test every remediation to ensure the issue is successfully resolved, letting you stay secure while planning your next major version upgrade.
Read about how we do itWhy Chainguard?
Trusted libraries you can’t get elsewhere
Proactive malware prevention
Stay protected from malicious attacks often inserted during the build and distribution stages of package creation.
Verification by default
Every library is built in a secure, SLSA L3 build system with full provenance and signed SBOMs to prove supply chain integrity.
System scale
Access to hundreds of thousands of versions of libraries across Java, Python, and JavaScript, with more being added every week.
Expertise and experience
The leading open source minds driving the industry forward, delivering new innovations for developers.
Explore the rest of Chainguard’s product suite
Related resources
Introducing Chainguard Repository: A unified experience for secure-by-default open source artifacts
Read now
Registries and the npm Breach: Securing the Weakest Link in the Software Supply Chain
Read now
Malware-Resistant Python without the Guesswork
Read now
Announcing Chainguard Libraries: Guarded Java Language Dependencies Built from Source
Read now
Chainguard’s Vision for a Safer Software Supply Chain
Read now
Panic! At The Distro: A Study of Malware Prevention in Linux Distributions
Read now
Taming bad Python packages: Assessing Python malware detectors with a benchmark dataset
Read now
























