Introducing Chainguard Libraries for Python: Malware-Resistant Dependencies Built Entirely from Source
more efficiently
KIRKLAND, Wash., May 14, 2025 /PRNewswire/ -- Chainguard, the secure foundation for software development and deployment, today announced Chainguard Libraries for Python, an index of malware-resistant Python dependencies built securely from source on SLSA L2 infrastructure. By securely building every library and all of its dependencies from source, Chainguard Libraries for Python provides application security teams with confidence that malware has not been inserted during the build and distribution of libraries in the Python ecosystem, closing a significant gap in the threat landscape. To start, Chainguard has built nearly 10,000 of the most popular projects and will continuously grow its inventory of Python libraries to become the safe source for all open source.
The growing threat of malware in the Python ecosystem
Today, more than half of the world's developers rely on Python, a programming language that has become the foundation of modern AI and machine learning applications. As the popularity of Python has surged, so has the frequency and severity of supply chain attacks against the ecosystem. Notable malware attacks against popular Python packages like Ultralytics and PyTorch TorchTriton have shaken the community and demonstrated the risk of relying on traditional mechanisms (e.g., public registries like PyPI) for language library consumption. These public registries do minimal vetting of hosted artifacts, and they do not provide assurance that the distributed library matches its source code, exposing enterprises to supply chain attacks. Additionally, Python libraries are susceptible to supply chain attacks because many projects include more than just pure Python code — project maintainers often rebundle shared system libraries into their Python libraries to ensure stable behavior. This practice of rebundling OS dependencies into Python libraries obscures the components from security scanners, meaning the vulnerabilities they introduce to production environments go unnoticed and pose a serious risk for enterprise security.
With Chainguard Libraries for Python, Chainguard delivers malware protection for one of the most critical and vulnerable parts of the supply chain — the language dependencies that developers rely on to build and deploy applications. Up to now, application security teams have had no comprehensive solution for mitigating malware without disrupting their developers' workflows and productivity. This left enterprises susceptible to the risks of malicious code that could waste resources, steal application secrets, break production systems, or even leak customer data. Chainguard Libraries for Python integrates with existing artifact managers to empower application security teams to close this massive security hole while meeting developers how they work.
'Chainguard is rebuilding every component for a given library — Python, Java, or otherwise — from source so organizations can mitigate malware, have clear visibility into what exactly is in their software, and eliminate the risk of hidden supply chain vulnerabilities,' said Kim Lewandowski, Co-founder and Chief Product Officer, Chainguard. 'We're providing a secure, trusted source of Python libraries that allows enterprises to remove friction and add security without asking developers to change how they build and deploy software.'
Mitigating malware attacks across Python dependencies
Following the recent launch of Chainguard Libraries for Java, Chainguard is building every dependency for every Python library from source, combating malware injection at the build and distribution links of the open source supply chain. This reduces risk from supply chain threat vectors like compromised build processes, release pipelines, and distribution points. Isolating and rebuilding the shared system dependencies required by Python libraries allows Chainguard to eliminate an additional hidden attack vector stemming from bundled software components.
Chainguard Libraries for Python furthers the company's mission to be the safe source for open source and gives customers greater confidence to ship products more efficiently and securely. Chainguard now helps organizations secure even more of the modern development stack, starting with the OS and runtime environment with minimal, zero-CVE containers and virtual machines, and up to the application layer with language libraries for Python and Java.
'At Paylocity, application security is core to the modern HR, payroll and spend management software we're building,' said Joe Christian, Senior Engineering Manager, Application Security, Paylocity. 'Chainguard already helps us reduce our attack surface while giving our teams confidence in what they're shipping. We see promise in Chainguard Libraries for Python to ensure developers can build securely from the very first line of code.'
'MAN Energy Solutions enables its customers to achieve sustainable value creation in the transition towards a carbon neutral future. As a global provider of large-scale industrial machinery and energy solutions, software supply chain security is a top priority,' Carsten Skov, Senior DevOps Engineer, MAN Energy Solutions. 'Chainguard Containers have already helped us ensure that our containerized analytics workloads are built and run securely by default. Now, we're excited about the potential of Chainguard Libraries for Python to further strengthen our software supply chain by mitigating the risks posed by unverified dependencies and malware in the Python ecosystem. Securing these workloads plays a key role in ensuring that the MAN-CEON Digital Ecosystem continues to meet the requirements of ISO/IEC 27001:2022 and ABS Cyber Safety Certification.'
Chainguard Libraries for Python is now available in early access. For more information, visit https://www.chainguard.dev/libraries
About Chainguard
Chainguard is the secure foundation for software development and deployment. By providing guarded open source software with Chainguard Containers, VMs, and Libraries, built from source and updated continuously, Chainguard helps organizations eliminate threats in their software supply chains. Its customers include Fortune 500 enterprises and global industry leaders, including Anduril, ANZ Bank, Canva, Hewlett Packard Enterprise, MAN Energy Solutions, Snap Inc., and Snowflake. Chainguard is venture-backed by leading investors, including Amplify, IVP, Kleiner Perkins, Lightspeed Venture Partners, Mantis VC, Redpoint Ventures, Sequoia Capital, and Spark Capital. For more information, visit: https://www.chainguard.dev/
View original content to download multimedia: https://www.prnewswire.com/news-releases/introducing-chainguard-libraries-for-python-malware-resistant-dependencies-built-entirely-from-source-302454677.html
SOURCE Chainguard
Hashtags

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


Bloomberg
15 minutes ago
- Bloomberg
Introducing Bloomberg's New Quant Platform for Sell-Side
Bloomberg has released a new product aimed specifically at the quant community. Quants and python proficient employees can now build their own applications within Bloomberg using our full financial data library. These bespoke applications can then be seamlessly shared with front office colleagues in Sales and Trading, fully integrating into their Bloomberg desktop view. BQuant Desktop is a Jupyter Notebook Python coding environment combined with Bloomberg's high-quality multi-asset-class financial data and advanced calculation services, providing programmatic access to a vast library of more than 17,000 data items. It is a turnkey solution available through a standard Bloomberg Terminal subscription, designed to enhance the entire quant workflow — from building applications and back testing datasets not currently available on internal platforms, to creating relative value and visualization tools, and seamlessly publishing projects as Bloomberg Launchpad applications. The sharing can be done instantly via the platform, a Bloomberg MSG or IB instant chat, without the end user seeing the code. Agenda: Introduction - why we have built this platform Demonstration - overview of BQuant Platform, real use case examples and sample projects / applications Next Steps - how to get enabled, how to share and build a community of users at your bank Speakers Anish Popat Quantitative Finance Specialist Sales Bloomberg Anish joined Bloomberg last year from Brevan Howard, where he was a global macro portfolio manager for 6 years. Prior to that, he was an FX portfolio manager at Tudor. He began his career as a European rates trader at UBS.
Yahoo
35 minutes ago
- Yahoo
InventHelp Inventor Develops New Safety Mechanism for Chairs with Caster Wheels (BRA-1242)
PITTSBURGH, Aug. 18, 2025 /PRNewswire/ -- "While working as a dental assistant using a stool containing caster wheels, my wife experienced a serious accident when the stool skated out from under her causing serious injury. I thought there could be a safer way to utilize a chair with caster wheels," said an inventor, from Cowandilla, SA, Australia, "so I invented the CASTOR CORRECT. My design reduces the number of accidents, injuries, and insurance claims associated with using caster wheel chairs and stools. Fitting this safety device to your castors could be the difference between a minor or severe injury." The patent-pending invention provides an effective safety mechanism designed to convert any office chair with caster wheels into a safer chair. In doing so, it diminishes the risk of the chair skating out from under the worker. As a result, it reduces the risk of accidents and injuries. It also increases safety while lowering absenteeism and insurance claims. The invention features a simple and discreet design that is easy to apply and safe to use so it is ideal for offices, home offices, all government sectors, hospitals and medical centers, educational facilities, defense industries, major corporations, manufacturing industries, administration, etc. Additionally, a prototype model and technical drawings are available upon request. The original design was submitted to the Brisbane sales office of InventHelp. It is currently available for licensing or sale to manufacturers or marketers. For more information, write Dept. 24-BRA-1242, InventHelp, 100 Beecham Drive, Suite 110, Pittsburgh, PA 15205-9801, or call (412) 288-1300 ext. 1368. Learn more about InventHelp's Invention Submission Services at View original content to download multimedia: SOURCE InventHelp 擷取數據時發生錯誤 登入存取你的投資組合 擷取數據時發生錯誤
Yahoo
43 minutes ago
- Yahoo
PATLive Flex Platform Delivers Personal Touch Powered by Smarter Technology
TALLAHASSEE, Fla., Aug. 18, 2025 /PRNewswire/ -- PATLive, a trusted leader in virtual receptionist services for more than 35 years, today announced the launch of the PATLive Flex Platform, state-of-the-art technology designed to give businesses more customization, control, and adaptability in how calls are handled. Long recognized for its highly trained virtual receptionists and exceptional customer service, PATLive now brings the technology powering that award-winning experience into the spotlight. The PATLive Flex Platform functions as the engine behind every call, message, and interaction. Every tool it powers, from call routing to intake workflows, can be configured to align with a customer's specific industry, processes, schedules, and communication preferences. "By combining our live receptionist services with the advanced capabilities of the PATLive Flex Platform, we're empowering businesses to tailor every interaction to their unique needs — delivering more flexibility, more control, and a better customer experience," says Jackie Gonzalez, CEO of PATLive. "It's the next step in our mission to deliver receptionist services that truly adapt to each client's unique needs." For small business owners, the result is a service that blends the warmth of human interaction with the precision and adaptability of modern technology. Clients retain the trusted human connection their callers expect, while gaining more flexibility and control. With the PATLive Flex Platform in place, the company is positioned to evolve rapidly alongside customer needs, expanding its capabilities while continuing to offer the reliable, friendly service that has defined PATLive since its founding in 1990. About PATLive Founded in 1990, PATLive is a trusted provider of 24/7 virtual receptionist services, offering businesses unparalleled expertise and customization in call handling. With a U.S.-based team of highly trained professional receptionists, PATLive ensures that businesses never miss a call while delivering tailored, strategic, and reliable customer interactions. Learn more at View original content to download multimedia: SOURCE PATLive Error in retrieving data Sign in to access your portfolio Error in retrieving data Error in retrieving data Error in retrieving data Error in retrieving data