threat_intelligence447 wordsRead on Arc Codex

Announcing the Sovereign Artifacts beta

Announcing the Sovereign Artifacts beta - View all articles Zayn Lohit Senior Product Manager Chainguard - View all articles David Henry Director of Solutions Marketing Chainguard Zayn Lohit Senior Product Manager + 1 other Today, we are announcing Sovereign Artifacts to help global organizations secure their software supply chains locally. With upcoming 2027 mandates like the EU Cloud and AI Development Act (CADA) requiring critical software to run in-region, sovereignty has shifted from a best practice to an explicit infrastructure requirement. Our customers in banking and defense who also needed a secure and verified supply chain to comply with the Cyber Resilience Act (CRA) and the Digital Operational Resilience Act (DORA), while building for data sovereignty across their global teams. To do this right, teams need localized artifacts from build to delivery, which has historically been notoriously difficult. Chainguard is changing that with the first local option for Chainguard’s secure open source artifacts. This beta marks the first milestone on our sovereignty roadmap, allowing customers to store container and library artifact bytes within an EU jurisdiction and pull them locally. Align with upcoming sovereignty frameworks Sovereign Artifacts supports DORA and CRA due diligence by reducing the risk of service, because local access can’t be disrupted while solving EU data residency and CADA Level 1 by storing and serving artifact bytes in the EU. Phase 1 covers artifact byte storage, which addresses where the data physically resides. Authentication and build pipelines are still hosted in the U.S., and the following phases are intended to close that gap. We are actively investing in a complete sovereignty solution and looking for design partners to help inform and accelerate our roadmap. Sovereign Artifacts also delivers a performance boost for European customers. Historically, transatlantic network latency has made EU pulls 1.7 to 2.2 times slower than U.S. pulls. Moving these artifact bytes closer to local infrastructure eliminates that network lag and reduces pull times by 30%. How to join the beta Enabling sovereign artifact byte storage may require a firewall config change to allow R2 bucket addresses to successfully pull artifacts. Once configured, Chainguard automatically backfills your artifacts to EU storage. Enrolled users then pull artifacts through their existing client workflows. Reach out today or contact your account team to join. Share this article Related articles - product Announcing Chainguard container images for Go 1.27 - product Introducing the Guardener GitHub App - product Chainguard Libraries now available on AWS Security Hub Extended - product Everything we announced during AI Readiness Innovation Week - product Fewer CVEs, more accurate findings: Wiz now scans Chainguard Libraries for Python and Java - product Chainguard Repository adds new policies, Chainguard Libraries for JavaScript is GA

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.