<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Chainguard Guardener on</title><link>https://deploy-preview-3615--ornate-narwhal-088216.netlify.app/chainguard/guardener/</link><description>Recent content in Chainguard Guardener on</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>Copyright (c) 2023 Chainguard</copyright><lastBuildDate>Wed, 08 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://deploy-preview-3615--ornate-narwhal-088216.netlify.app/chainguard/guardener/index.xml" rel="self" type="application/rss+xml"/><item><title>Chainguard Guardener GitHub App</title><link>https://deploy-preview-3615--ornate-narwhal-088216.netlify.app/chainguard/guardener/github/</link><pubDate>Mon, 13 Jul 2026 00:00:00 +0000</pubDate><guid>https://deploy-preview-3615--ornate-narwhal-088216.netlify.app/chainguard/guardener/github/</guid><description>&lt;p&gt;The Chainguard Guardener GitHub App is a single, hardened bot that runs against your repositories. Its capabilities are opt-in per repository through configuration files committed to a &lt;code&gt;.chainguard/&lt;/code&gt; directory, so installing the app has no effect on a repository until you enable a capability.&lt;/p&gt;
&lt;p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note&lt;/strong&gt;: Chainguard Guardener is in beta. Available to organizations that have installed and linked the Chainguard Guardener GitHub App.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/p&gt;
&lt;h2 id="getting-set-up" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;Getting set up&lt;/span&gt;
&lt;a href="#getting-set-up" class="anchor" aria-label="Link to Getting set up" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://deploy-preview-3615--ornate-narwhal-088216.netlify.app/chainguard/guardener/github/getting-started/"&gt;Getting started&lt;/a&gt;&lt;/strong&gt; — Install the GitHub App and link your Chainguard organization to your GitHub organization.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://deploy-preview-3615--ornate-narwhal-088216.netlify.app/chainguard/guardener/github/configuration/"&gt;Configuration&lt;/a&gt;&lt;/strong&gt; — Understand the &lt;code&gt;.chainguard/&lt;/code&gt; configuration model that all the GitHub App capabilities share.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="capabilities" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;Capabilities&lt;/span&gt;
&lt;a href="#capabilities" class="anchor" aria-label="Link to Capabilities" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://deploy-preview-3615--ornate-narwhal-088216.netlify.app/chainguard/guardener/github/actions-security/"&gt;Hardened Actions&lt;/a&gt;&lt;/strong&gt; — Recommends and migrates your GitHub Actions to Chainguard&amp;rsquo;s hardened, SHA-pinned equivalents, either through non-blocking pull request review comments or automated migration pull requests.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://deploy-preview-3615--ornate-narwhal-088216.netlify.app/chainguard/guardener/github/commit-verification/"&gt;Commit Verification&lt;/a&gt;&lt;/strong&gt; — Enforces cryptographically signed commits against a policy you control, supporting both keyless (Sigstore) signatures and static keys such as GPG.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Each capability is configured with its own file in the &lt;code&gt;.chainguard/&lt;/code&gt; directory.&lt;/p&gt;</description></item><item><title>Chainguard Guardener Dockerfile Migration</title><link>https://deploy-preview-3615--ornate-narwhal-088216.netlify.app/chainguard/guardener/dockerfile-migration/</link><pubDate>Mon, 13 Jul 2026 00:00:00 +0000</pubDate><guid>https://deploy-preview-3615--ornate-narwhal-088216.netlify.app/chainguard/guardener/dockerfile-migration/</guid><description>&lt;p&gt;The Dockerfile migration feature converts your Dockerfiles to use Chainguard Containers. It uses AI to iteratively translate instructions, build images, compare results, and fix issues until the migrated Dockerfile works as expected.&lt;/p&gt;
&lt;p&gt;Unlike the Guardener&amp;rsquo;s &lt;a href="https://deploy-preview-3615--ornate-narwhal-088216.netlify.app/chainguard/guardener/github/actions-security/"&gt;Hardened Actions&lt;/a&gt; and &lt;a href="https://deploy-preview-3615--ornate-narwhal-088216.netlify.app/chainguard/guardener/github/commit-verification/"&gt;Commit Verification&lt;/a&gt; features, Dockerfile migration does not run through the GitHub App or the &lt;code&gt;.chainguard/&lt;/code&gt; configuration directory. Instead, you drive it locally through &lt;code&gt;chainctl agent dockerfile&lt;/code&gt; commands. The AI runs server-side and scans your workspace to perform its analysis, while Docker builds and file access remain local to your machine.&lt;/p&gt;</description></item></channel></rss>