
Black Duck trusts Chainguard to minimize supply chain risk exposure for Polaris
The challenge
Black Duck’s mission is to enable development and security teams to build trust in software in an increasingly regulated and AI-powered world. As the pace of both software development and software supply chain exploitation accelerates, the need to rapidly innovate while ensuring the security of their own solutions is high. "We grapple with open source security risks just as our customers do,” said Ron Lewis, Head of Cybersecurity Governance at Black Duck. “It's the most prolific attack vector being leveraged against companies today. You see it in the news all the time.”
For Black Duck's flagship SaaS platform, Polaris, verifiable management of that risk was key to accessing the federal market. However, the team realized that achieving FedRAMP accreditation for Polaris would require significant ongoing effort to manage the maintenance of its own supply chain dependencies, which would pull focus from its established product roadmap.
The solution
To address this challenge, Black Duck searched for a partner it could trust to do the heavy lifting. "We wanted to outsource that with a trusted partner, one that has a good reputation in the industry. After vetting several potential candidates, we determined that Chainguard was the best solution for us," Collin Hogue-Spears, Senior Director, Product Management, said.
Seema Ganoje, Director of Cloud Operations, explained, "Chainguard's provenance tooling, the cryptographic proof of where images come from, how they were built, signed SBOMs, and attestations enable us to streamline our risk management workflows — for FedRAMP, that's the difference."
The results
Less time on plumbing, more time building
With Chainguard in place, Black Duck's engineering team was able to spend less time patching gaps and more time innovating. "Our ability to ship and scale our software has improved dramatically using Chainguard container images as a foundation. What we're able to do now is ship faster, with greater confidence that our solutions are vulnerability-free, and provide that evidence to our customers," Collin said. "The end result for us is that we can get our products to market faster using Chainguard.”
Ron's security team felt the difference, too. "One of the things that implementing Chainguard has really helped us with from a security team perspective is it cuts down the level of effort for vulnerability remediation. My team is always at max capacity, but with Chainguard, the challenge of staying on top of the constant stream of vulnerabilities and patches feels less overwhelming," he said.
With that foundational security work off their plate, the Black Duck team could focus its energy on delivering more value to its customers “With Chainguard, we can now focus on enhancing Polaris, which includes expanded integrations with DevOps automation tools and enhanced reachability analysis, as well as launching our agentic AppSec solution, Signal. All of these are the capabilities that our customers care about," Seema said.
A cultural shift toward secure-by-default open source
Chainguard changed how Black Duck's engineers think about how they manage open source risks. "With Chainguard in the picture, we can rely on open source that is secure by default," Seema said. Engineers no longer have to weigh security risk in every choice they make; they can focus on what's best for the product.
"This confidence has raised the bar,” Seema said. “By the time code reaches production, teams have a record of its provenance through every step.” And that provenance and secure-by-default posture are key stepping stones on the Black Duck team’s journey towards FedRAMP accreditation.
Compliance and customer trust
For some of its most regulated customers, Black Duck’s security posture has become a selling point.
"We have a lot of customers in regulated industries such as financial services critical infrastructure, medical devices, and automotive,” explained Collin. “And for those customers, security is key because they are under scrutiny by both regulators as well as their customers. Leveraging Chainguard as a foundation for security by default and supply chain provenance really helps us build trust with those customers.”
From customer to coalition
Black Duck's relationship with Chainguard has continued to grow. "We started with Chainguard as customers, and we quickly moved into partnership. And now, we're excited to further expand that partnership with the Athena Coalition," Collin said.
Athena is Chainguard's industry coalition to protect open source software from AI attacks, pooling vulnerability findings from its members and turning them into fixes and mitigations before attackers can act on them. Seema explained Black Duck's role, "We contribute SCA and vulnerability intelligence. When Mythos finds a zero-day, the coalition coordinates, pulls the findings, verifies them, builds the mitigations, pushes them upstream, and the whole ecosystem gets stronger.”
What began as a customer relationship built on FedRAMP requirements has grown into a partnership, and now a coalition, with Black Duck and Chainguard helping shape how the open source ecosystem defends itself.