Introducing the Guardener GitHub App
Introducing the Guardener GitHub App
Today, we’re introducing the Guardener GitHub app, now available in beta, to help teams migrate GitHub Actions to secure Chainguard Actions.
Standardizing on secure-by-default open source is a priority for many organizations, with the rate of supply chain attacks only accelerating.
In March 2026 alone, the Axios npm package was compromised, and the threat group TeamPCP hit Trivy, KICS, LiteLLM, and Telnyx within weeks of each other. With the average supply chain compromise costing $4.9 million, according to IBM's 2025 Cost of a Data Breach Report, the business case for switching to trusted open source is clear.
Change can be hard, no matter the size of an organization.
That's why we launched Guardener: to automate the adoption of trusted open source across the software development lifecycle faster and with less friction.
Initially, we made Guardener available in our chainctl CLI for container image migration to speed up the adoption of trusted, production-ready container images. Guardener rebuilds Dockerfiles layer by layer based on environmental context, testing as it goes, and outputting an accurate, stable, secure-by-default Dockerfile.
Our vision for Guardener is to have it reflect the way our customers see Chainguard, as the trusted source for all of their open source. With the release of the Guardener GitHub app, we’re expanding Guardener to support more use cases, the first of which is migration to Chainguard Actions. Now in Beta, Chainguard Actions is a catalog of over 800 continuously hardened drop-in replacements for GitHub Actions, the widely adopted re-usable code snippets that compose CI/CD pipelines. These actions have become common vehicles for attacks, like in the instances of Trivy and tj-actions, because of their popularity and their highly privileged nature.
Because of the increasing frequency of attacks, security and platform teams don’t have months to cajole their developers into updating their YAML workflow files. They need to be able to automate and centrally track the rollout of Chainguard Actions.
We built the Guardener app to make that a reality.
Automate Actions migration with the Guardener GitHub app
Let’s look at how the Guardner GitHub app works. It has two complementary modes.
The first is through upfront migration. Guardener will inventory the GitHub Actions in use across your repos and open a migration pull request for all of the actions where there is a Chainguard equivalent. Each pull request summarizes every change and anything it couldn't migrate in the PR body, giving you visibility into actions in use across your organization. For Actions not in our catalog today, you can easily request them to be added and have them available within one business day for gapless coverage. You can also configure this process to rerun on a cadence you control.
The second mode is for continuing standardization on Chainguard Actions. Pipelines are only as secure as the actions running within them, so Guardener can continually watch for new actions being added and suggest their Chainguard equivalents. It does this by watching for PR changes to a workflow under .github/workflows/
. When it detects newly added or changed uses:
references, it posts a non-blocking review comment with a one-click ```suggestion
block recommending the Chainguard-hardened equivalent.
In both modes, Guardener replaces mutable tags with pins to a specific SHA of a hardened action in a trailing comment, like uses: chainguard-actions/actions-checkout@ # v6
, enforcing GitHub's recommended best practice to protect against tag hijacking. To update these SHAs, you can use Renovate or Dependabot for complete action lifecycle automation.
The combination of upfront migration automation plus non-blocking enforcement on every new pull request is what enables Chainguard customers to seamlessly adopt hardened, secure-by-default actions. Xometry, a global digital marketplace for on-demand manufacturing with hundreds of repositories, has moved to Chainguard Actions without slowing its engineering teams down:
"As a security team, we're focused on preventing supply chain attacks before they happen,” said Jeremy Young, Software Engineer and Security Architect at Xometry. “With Chainguard Actions, we can proactively protect our pipelines without asking anyone to change how they work or take any action. Guardener sped up adoption by giving us visibility into the upstream GitHub Actions we were using and opening pull requests to swap in the hardened Chainguard versions. We look forward to continuing our standardization on Chainguard's secure-by-default artifacts and reducing adoption lift.”
See Guardener weed out insecure GitHub Actions
Watch the Guardener GitHub app in action as it fully automates migration from GitHub Actions to Chainguard Actions by:
Inventorying the upstream GitHub Actions in use
Finding the Chainguard Actions equivalents
Opening a migration PR
Finally, we'll also look at the HARDENING.md file for one of the newly migrated Chainguard Actions to see the vulnerabilities it mitigated.
Get started
As the software supply chain threat landscape continues to evolve, Guardener will expand what Chainguard can do to eliminate the maintenance and toil associated with standardizing on hardened artifacts across the entirety of the software supply chain. Over the coming months, we will be introducing support for Chainguard Libraries, Agent Skills, and more, across both chainctl and the Guardener GitHub app.
To get started with the Guardener GitHub app for automated Chainguard Actions adoption, check out the Guardener documentation, and try Chainguard Actions free for 30 days.
Share this article
Related articles
- product
Chainguard Libraries now available on AWS Security Hub Extended
Patrick Donahue, SVP, Product
- product
Fewer CVEs, more accurate findings: Wiz now scans Chainguard Libraries for Python and Java
Matt Stead, Product Marketing Manager
- product
Chainguard Repository adds new policies, Chainguard Libraries for JavaScript is GA
Ross Gordon, Staff Product Marketing Manager
- product
Everything we announced during AI Readiness Innovation Week
Patrick Donahue, SVP, Product
- product
Securing the AI coding ecosystem: Chainguard and the AI tools developers use
Matt Stead, Product Marketing Manager
- product
Chainguard plug-in now available on Cursor Marketplace
Matt Stead, Product Marketing Manager
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.