Introducing Chainguard Libraries for JavaScript: Malware-Resistant Dependencies Built Entirely from Source
New JavaScript language libraries with end-to-end integrity help organizations build software more safely and efficiently
Demonstrated risk in the JavaScript ecosystem
The risk in the JavaScript ecosystem isn't theoretical: earlier this month, a number of packages used by millions of developers were compromised via malicious code. These malware attacks against popular JavaScript registries like npm, which developers download billions of times per week, demonstrated the risk of relying on traditional mechanisms for language library consumption. These public registries do not guarantee all host artifacts are vetted and do not provide assurance that the distributed library matches its source code, exposing enterprises to supply chain attacks. Compounding the issue, AI has fueled a surge in JavaScript development, multiplying both the volume and complexity of dependencies — and with it, the opportunities for attackers.
According to Gartner®, "A source estimates costs from software supply chain attacks will rise from
Mitigating malware attacks across JavaScript dependencies
With Chainguard Libraries for JavaScript, Chainguard offers protection for one of the most critical and vulnerable parts of the supply chain: the language dependencies that developers rely on to build and deploy applications. Until now, there was no way for security teams to mitigate malware at scale without disrupting engineering workflows and productivity. This gap left organizations susceptible to the risks of malicious code that could waste resources, steal application secrets, break production systems, or even leak customer data. Chainguard Libraries for JavaScript integrates with existing artifact managers, such as JFrog Artifactory and Sonatype Nexus, to empower application security teams to close this massive security hole while meeting developers how they work.
As with Chainguard Libraries for Java and Python, Chainguard is building every dependency for every JavaScript library from source, combating malware injection at the build and distribution links of the open source supply chain. Isolating and rebuilding the shared system dependencies required by JavaScript libraries allows Chainguard to eliminate an additional hidden attack vector stemming from bundled software components.
"Chainguard is the first to rebuild JavaScript libraries from source at scale. We are expanding on the work already completed with Chainguard Libraries for Java and Python to JavaScript, the most popular programming language in the world," said
Chainguard Libraries for JavaScript furthers the company's mission to make open source software trustworthy by default and gives customers greater confidence to ship products more efficiently and securely. Chainguard now helps organizations secure even more of the modern development stack, starting with the OS and runtime environment with minimal, zero-CVE containers and virtual machines, and up to the application layer with language libraries for Python, Java, and now JavaScript.
"The recent compromises in popular npm packages highlight just how easy it still is for attackers to slip malicious code into the software supply chain. Chainguard's approach to open source software security flips that paradigm — by rebuilding every JavaScript library from source, they will give development teams a way to eliminate common supply chain attacks and actually have a trusted source for packaged libraries. The open source community has done a herculean effort to bring software to the masses, but policing it falls to commercial entities," said
"JavaScript has long been the backbone of modern application development, but the ecosystem's dependency sprawl and security gaps come with risks," explains
Chainguard Libraries for JavaScript is now available in closed beta. For more information or to join the waitlist, visit https://www.chainguard.dev/libraries
Gartner, Leader's Guide to Software Supply Chain Security,
Gartner, Market Guide for Software Supply Chain Security,
Gartner is a registered trademark of Gartner, Inc. and/or its affiliates and is used herein with permission. All rights reserved.
About Chainguard
Chainguard is the trusted foundation for software development and deployment. By delivering hardened, secure, and production-ready builds of all the open source software engineers rely on, Chainguard helps organizations build faster, stay compliant, and eliminate risk. Its customers include Fortune 500 enterprises and global industry leaders, including Anduril, Canva, Fortinet, Hewlett Packard Enterprise, Snap Inc., and Snowflake. Chainguard is venture-backed by leading investors, including Amplify, IVP,
View original content to download multimedia:https://www.prnewswire.com/news-releases/introducing-chainguard-libraries-for-javascript-malware-resistant-dependencies-built-entirely-from-source-302566682.html
SOURCE Chainguard
Serious News for Serious Traders! Try StreetInsider.com Premium Free!
You May Also Be Interested In
- FlexScreen® / RiteScreen® Welcomes David Whisenhunt as Director of Sales
- WNC & Associates, Inc. Closes $66.3 Million California Affordable Housing Fund, Marking 55 Years of Investment in Home State
- Hanover Foods Launches GLP-1-friendly Skinny Veg® Line
Create E-mail Alert Related Categories
PRNewswire, Press ReleasesRelated Entities
Spark Capital, Sequoia CapitalSign up for StreetInsider Free!
Receive full access to all new and archived articles, unlimited portfolio tracking, e-mail alerts, custom newswires and RSS feeds - and more!



Tweet
Share