正在加载视频...
视频加载失败
Open source is dying. We raised over $800M to save it. Chainguard is the world’s first infrastructure that stops cyberattacks before they can start:
839,388 次观看 • 2 个月前 •via X (Twitter)
69 条评论

the package has done nothing wrong. it's just sitting there being exactly what it always was

Could someone explain this in FIFA terms

other people scan for injuries. we don't sign injured players. now that covers agent skills too

It’s so scary to know how vulnerable we all currently are. Would open source really die without this?

nah, open source is fine. it's how we consume it that's a mess. same projects, same source, we just rebuild them properly

You should just start messing with people like this fr

@grok Is open source going to die with AI threats?

⚠️⚠️⚠️ With AI agents now autonomously pulling and executing dependencies, how does Chainguard's threat intelligence stay current? What is the update cycle on your hardened catalog when a new malicious package is discovered in the wild?

the trick is not trusting prebuilt binaries at all. that's where most malware hides. we rebuild everything from verified source continuously, so there's far less to detect in the first place

Your devs and agents pull unverified, vulnerability-ridden open source components from the internet. The typical scanner finds vulns, patches them, and moves on. But now Mythos-class models help AI-assisted attackers exploit vulns faster than humans can scan for them.

changes this. We work across your entire stack: - Secure container images with near-zero CVEs - Malware-free libraries - Hardened agent skills for AI-era development

chainctl allows you to access Chainguard’s repository of secure agent skills, and install them in ALL agentic coding tools on your machine with one command. Tell your agent: > Install chainctl > Log in to chainguard > Browse agent skills > Install them across your coding platforms

Today, @OpenAI, @anduriltech, @canva, and hundreds of other companies reduce their attack surface by 85%. We are becoming the foundation for modern software.

@anduriltech @canva And now we’re hosting a bug hunt with a $200,000 prize pool. If you find a vulnerability in our system, we’ll pay you up to $200k.

We sleep easy tonight knowing you have the watch

appreciate that. still keep your own watch though

Well done, I hope this buys us another lifetime of open source 🙏

thanks for saying that!

What an amazing launch guys. Super stoked as to how we can use this

thank you. what are you building? curious which piece is most useful to you

Currently we’re building a lot of project management tools inhouse and other gamification features, def need help with cybersecurity

@grok did this company really raise $800m?

Yayyy lfggg

ayyyy 🚀

can we put @clankercloud on it?

@clankercloud genuinely the best possible test. we built agent skills, someone should send agents at us

"Open source is dying." Nope

nope is correct

Very interesting. Will check this out.

try to find some bugs!

This nails why open source supply chain security needs a fundamental rethink in the AI age. Prevention by default makes sense.

Great vid and framing, Dan! Also, hi @lizwalton!

@lizwalton thanks! Liz carried that video honestly

@lizwalton Not surprised. Great work, Liz! 🙌🏽

I'm really glad someone is doing this, and I like that its you. It's thankless hard work, but its worth doing.

appreciate that more than you know. the team will like reading this one

Congratulations Dan! so happy to see this Journey and I remember talking with @mattomata when he left google to see whats happening in the ecosystem we pulled of the first ever Knative series with him and @AikasVille and others. Then I did the Investing 101 with you on X spaces. I and some of my buddies also tried to build buildsafe which was nix based. but so cool to see the growth of chainguard 👍🏻

@mattomata @AikasVille Appreciate that so much Saiyam!

Congrats on the launch! Checking this out now.

Appreciate it. Let me know how it goes!

super cool! is there a structural way of how you achieve near-zero CVEs getting into the libraries or containers you offer? is it manual or more like Mythos testing everything and trying to find vulnerabilities?

structural. we rebuild everything from source continuously, so most cves never get shipped, and the ones that land get patched fast

Open source is not dying lol. What kind of narrative is this?

hopefully not. we're spending a lot of money on it

Nope, my GitHub projects aren't going anywhere and I didn't receive any of that $800M.

you're not wrong. maintainers carry all of this and see none of the money. what are you maintaining?

$800 million and you couldn’t use a real actor for your video?

that's @lizwalton. she's real, she just has good lighting

"open source is dying" is a spicy way to pitch a security product lol. but the real shift is agents now pulling random dependencies at scale with zero human eyeballs on them

lesgoooo

that's the energy!!

@ice_z3us @ice_blockchain @JoshuaTobkin @SUPRA_Labs I hope this helps

Interesting

we think so too! what caught your eye?

what really got me is how you are treating AI coding agents the same way you hardened containers. Trusted skills rebuilt from source instead of random pulls. Most tools are still just scanning after the fact. But agents are moving so fast it feels like the next real layer we need. Curious how early adoption of the skills catalog is going across tools like Cursor and Claude Code.

This is great news as proactive rather than reactive cybersecurity is the best way to mitigate increasingly sophisticated cyberattacks in the AI tech era!

that's the bet. curious whether you're seeing that shift happening where you are, or if it's still mostly scan and patch?

You don’t need an entire OS to run a web server in most cases. Great product!

yep. the smallest thing that runs your app is also the safest thing that runs your app

really cool. would love to understand the business model.

we rebuild open source from source and enterprises pay us for the clean versions plus the sla

smooth. really good. I feel really bad that I didn't come up with the idea. Anyways, best wishes. Will keep an eye on you guys.

Tell me the bubble is about to burst without telling me 💀

Loving this video, congrats on the launch!!

appreciate it. what landed for you?

Solving a problem where attacks happen 7 days before a vulnerability is disclosed. Goated 🐐

appreciate it. that window is exactly what we're going after

super cool! and congrats!

thanks!
