949 karma · joined October 5, 2015
Previously: VP, Product @Cloudflare; CPTO, Aurora Solar
DMs open on Twitter (@prdonahue)
Chainguard is the trusted source for open source. We build hardened, minimal, continuously-updated images, libraries, and packages that eliminate vulnerabilities before they ship — used by teams at Anduril, Canva, OpenAI, Snap, and Snowflake, among others.
We're hiring a PM to own the malware and greyware scanning engine inside Chainguard Repository — the system that analyzes source code, build behavior, and maintainer activity across the open source packages flowing through our platform to catch compromised or malicious artifacts before they reach a customer's environment. You'd own the roadmap for detection coverage, scanner accuracy (precision/recall trade-offs are the daily grind), and how findings get surfaced to security teams and translated into policy enforcement. Close partnership with our detection engineering and threat research teams, and with customers who are increasingly asking "how do you know this package is safe?"
Good fit if you've done PM work on a detection, fraud, spam, or security scanning system before, are comfortable being hands-on with data and false-positive/false-negative trade-offs, and want to work on a problem that's getting more urgent as AI agents pull in more open source dependencies automatically.
JD to be posted imminently but email me if interested and I'll route appropriately: patrick@chainguard.dev
Most of these attacks don't make it into the upstream source, so solutions[1] that build from source get you ~98% of the way there. If you can't get a from-source build vs. pulling directly from the registries, can reduce risk somewhat with a cooldown period.
For the long tail of stuff that makes it into GitHub, you need to do some combination of heuristics on the commits/maintainers and AI-driven analysis of the code change itself. Typically run that and then flag for human review.
[1] Here's the only one I know that builds everything from source: https://www.chainguard.dev/libraries
(Disclaimer: I work there.)
Seems like it’d be helpful to bury mass reporters in a de facto spam bucket (where “mass” is some absolute quantity of reports along with percent that are accepted).
We're building the safe, trusted source for open source. We created the secure Container Image market and we've recently expanded into VMs and Libraries for popular language ecosystems such as JavaScript, Python, and Java.
We're hiring quite a few PMs and engineers for our Containers and Libraries products, amongst other roles. Check out the listings here https://www.chainguard.dev/careers and if you're a highly-technical PM that wants to SHIP email me directly at patrick at chainguard dot dev.
In this particular case, the bogus libraries had been out there for months. But if in addition to a delay, you mirror just the most common subset of packages with some opinionated selection criteria and build directly from source, you eliminate most of these attacks. (The same is true across whatever language ecosystems, including JS as you mention npm, etc.)
Is this 100% infallible? No, but security is a risk reduction game.
Essentially: building the world from GitHub repos on SLSA L2 hardened infra and delivering directly to our customers to bypass the registry threat vector (which is where vast, vast majority of attacks occur—we'll be blogging about this soon with more data).
[1] https://www.chainguard.dev/unchained/announcing-chainguard-l...
I asked for an incident report and received this terse response:
> There has been no breach of Oracle Cloud. The published credentials are not for the Oracle Cloud. No Oracle Cloud customers experienced a breach or lost any data.
I remember calling Clint and Jeremy at DigiCert and asking: "hey we have this cool IP address—what are the odds you guys can issue a certificate for it?"
I'm not sure if they had to dust off some code or process to do it, but they got it done really quickly once the demonstration of control was handled.
It's been somewhat maddening switching from Confluence.
Highly recommend MGE if you’re in the Cape Cod area. Not sure how far off Cape they’ll go if not.
(Full disclosure: I’m in the solar industry, but on the software side. Recently left Cloudflare to join Aurora Solar as CPO.)
If you disagree, what’s a reliable way to identify the great agents?