Blog

DevGuard Blog

Engineering deep-dives, research notes, and practical guidance on software supply chain security — straight from the team building DevGuard.

Patrick Rißmann
Tim Bastin
Vulnerability Management · 13 Aug 2026

DevGuard Vulnerability Database and the EUVD

When it comes to Vulnerability Management Tools, having a good vulnerability database is crucial. While it seems simple to just synchronize CVEs from a source like the NVD and call it a day, but building a good vulnerability database is far more nuanced than that. Here's what sources DevGuard synchronizes and why, how the VulnDB pipeline actually operates, and how we approached synchronizing the EUVD's sources.

Patrick Rißmann, Tim Bastin
17 min read
Philipp Schönbach
Supply Chain Security · 6 Aug 2026

What is Software Supply Chain Security?

Modern software is assembled from third-party libraries, build tools, and CI/CD pipelines rather than written from scratch. Here's what software supply chain security means, the threats it defends against, and how to get started.

Philipp Schönbach
14 min read