Chainguard Customers Have 94% Python Ecosystem Coverage for Their Environments
Chainguard expands coverage and impact across Python, Java, and JavaScript libraries, securing the open source dependencies engineering teams rely on
The expanding risk of open source dependencies
Engineering teams are increasingly relying on AI coding tools to build software, with 4% of all GitHub commits now being authored by
"As untrusted code proliferates in this new world of AI coding, secure-by-default is the only effective security posture. Relying on unverified binaries and after-the-fact scanning simply doesn't work," said
Coverage that reflects real impact across open source ecosystems
Across Chainguard Libraries for Python, Java, and JavaScript, customers have access to the coverage they need to reduce their reliance on the malware-flooded registries that can disrupt their businesses. For every version built across each of the ecosystems, every underlying transitive dependency has been rebuilt too:
- Python: Now generally available, Chainguard Libraries for Python customers see 94% coverage across the dependencies they use in their environments. Chainguard has built more than half a million unique versions, including notoriously hard-to-rebuild AI libraries such as PyTorch, torchvision, and torchaudio.
- Java: Chainguard has rebuilt nearly one million unique versions of Java dependencies, including enterprise essentials such as Spring Boot, Jackson,
Apache Commons , and Log4j. - JavaScript: Just five months after launch, Chainguard already covers 88% of npm's top 500 highest-impact JavaScript libraries, and tens of thousands more in the long tail. A library earns "high-impact" status by crossing both of the following thresholds: more than one million downloads in the past week, or is depended upon by at least 500 other projects.
Over the past 12 months, enterprises from highly regulated industries to high-growth AI startups, such as Abridge AI, Alara, Canva, Cast AI, and Rocket Lab, have switched from downloading dependencies from public registries to using Chainguard Libraries. Now, they have verifiable proof through signed provenance and SBOMs that their open source artifacts match the source code bit-for-bit.
"Knowing what's in our dependencies before anything gets deployed is huge,"
Purpose-built for security, speed, and scale
Chainguard's ability to deliver broad, environment-based library coverage at scale is powered by the Chainguard Factory, a SLSA L2-compliant environment that builds libraries from verified source code. The Chainguard Factory allows Chainguard to quickly build new artifacts, apply consistent security best practices, and backport dozens of critical and high-severity CVEs in the Python ecosystem at scale. The company recently supercharged its software factory with the addition of DriftlessAF, a resilient, self-correcting agentic framework that uses AI reconciler bots to tackle complex tasks, such as adapting to new package releases and addressing security issues.
Discover how Chainguard Libraries eliminates the tradeoff between speed and security.
About Chainguard
Chainguard is the trusted source for open source. By delivering hardened, secure, and production-ready builds of all the open source software engineers rely on, Chainguard helps organizations build faster, stay compliant, and eliminate risk. Its customers include Fortune 500 enterprises and global industry leaders, including Anduril, Canva, Fortinet, Hewlett Packard Enterprise, Snap Inc., and Snowflake. Chainguard is venture-backed by leading investors, including Amplify, IVP,
View original content to download multimedia:https://www.prnewswire.com/news-releases/chainguard-customers-have-94-python-ecosystem-coverage-for-their-environments-302697811.html
SOURCE Chainguard
Serious News for Serious Traders! Try StreetInsider.com Premium Free!
You May Also Be Interested In
- AEAMC Bolted Pressure Switch Retrofit Wins Plant Engineering Product of the Year Award
- Lead Glass Pro Launches Turn-Key X-Ray Room Installation Service Across 26 States
- /C O R R E C T I O N -- THE GOOD DOG FOUNDATION/
Create E-mail Alert Related Categories
PRNewswire, Press ReleasesRelated Entities
Spark Capital, Sequoia CapitalSign up for StreetInsider Free!
Receive full access to all new and archived articles, unlimited portfolio tracking, e-mail alerts, custom newswires and RSS feeds - and more!



Tweet
Share