Propio trusts Chainguard to prevent AI-driven supply chain attacks

The challenge

Like almost every company using open source today, Propio Language Services struggled to keep pace with an ever-growing wave of AI-driven supply chain attacks. According to Kevin Fuller, CISO at Propio, the team was constantly identifying and responding to new threats, which made proactive security nearly impossible and took time away from planned product work.

“
With AI advancing at the rate that it is, exposure is growing exponentially. And our capacity is not growing exponentially.
DONNIE DOOLEY, CTO, PROPIO

“CVEs were out of control,” said Donnie Dooley, CTO. “They were running rampant. They weren't being managed to the SLAs that we had stated.” At one point, roughly 20% of engineering capacity was dedicated solely to CVE management rather than building the product.

For the Propio team, the risk and subsequent security-oriented work started with containers, but didn’t end there. Kevin explained, “Containers and libraries have both kept me up at night trying to identify what we need to deal with.”

Kyle Vanderbilt, Director of Platform Engineering, described the sharpening urgency around libraries: “The Axios supply chain attack is what prompted our interest in Chainguard Libraries. It was surprising to us that a library that's used by millions of developers around the world was attacked and had such a broad impact.”

The team considered managing remediation in-house, but the effort was overwhelming. They needed to look to the market to bring on a vendor that would reduce CVE volume without new operational burdens.

The solution

The Propio team was looking for a few key capabilities: a drastic reduction in CVEs out of the box, protection against malware and supply chain attacks, and a way to reduce the manual security burden for internal teams.

While the team started with Chainguard Containers for the immediate reduction in CVEs, CVE remediation alone wasn’t enough. Propio then turned its attention to the open source dependencies powering its applications, adopting Chainguard Libraries for JavaScript, with plans to extend coverage to additional languages over time. For Donnie, having the two products working in tandem was essential for addressing the exposure across the platform.

“
We need to close all the loopholes in our code base across our platform. And that involves Chainguard Containers and Chainguard Libraries working together to manage that full risk.
DONNIE DOOLEY, CTO, PROPIO

The rollout moved quickly, with Propio’s platform engineering team getting two services running in their dev environment within days, and the first services in production within a few weeks. Because Chainguard integrated directly into Propio’s existing GitLab registry and CI/CD pipelines, the switch required minimal disruption to development teams, who simply needed to update their base images. As Donnie shared, "Propio's implementation with Chainguard Containers has been the best integration that we've done as a technology company."

The results

Container security that fuels development velocity

Since implementing Chainguard Containers, Propio has seen its CVEs drop from thousands to near zero almost overnight, a reduction that has translated directly into product feature enhancements rather than time spent on CVE remediation.

“
Our product development has increased by roughly a third. Our teams are delivering more product output today because they're spending less time on CVE remediation and more time on product development.
DONNIE DOOLEY, CTO, PROPIO

Extended prevention to the dependencies layer

Chainguard Libraries gives Propio’s team the ability to code in JavaScript without bringing on the malware risk that’s plagued npm. "With Chainguard Libraries, I'm looking forward to being able to sleep at night and not have to worry about the ongoing malware supply chain attacks," Kyle said.

Kevin sees Chainguard as driving the shift from reactive detection to proactive prevention across containers and libraries. "We have immediate visibility to that now, but more important than that, it's a preventative capability. So it's not just detection, it's prevention. And that has given us a world of peace."

“
My experience with Chainguard has been absolutely incredible. The team, product, and overall leadership are changing the paradigm for how we secure our environment. An ounce of prevention is worth a pound of response.
KEVIN FULLER, CISO, PROPIO
share this article

Propio trusts Chainguard to prevent AI-driven supply chain attacks

Execute commandCG System prompt

$ chainguard learn --more

Contact us