Uploaded August 2026 | Updated September 2026, 18 hours ago
AI frontier models are accelerating the discovery of vulnerabilities in Java applications at a pace that teams can't keep up with. If your team is stuck on older Java versions that are hard to upgrade, you need support to remediate those vulnerabilities so you can get time back in your day to build.
In this Learning Lab, Manfred Moser will share the details behind Chainguard Libraries for Java, providing an overview on how to start using remediated versions directly with Apache Maven, Gradle, or your current repository manager configuration. With every Chainguard-built version, he will show you how to pull SBOMs and provenance to demonstrate the integrity of your third-party artifacts.
Specifically, he’ll cover and demonstrate the following new features:
- CVE remediation for Spring Framework and other libraries
- Protected fallback to Maven Central
- Cooldown policy
Discover more: https://edu.chainguard.dev/software-security/learning-labs/ll202607/
TIMESTAMPS
0:00 Introduction
2:42 Software supply chain and open source components
6:20 History of software supply chain security issues and attacks
8:30 Chainguard Libraries and Chainguard Factory overview
11:30 Details about Chainguard Libraries
17:36 CVE remediation
24:30 What is remediated?
25:47 Browsing remediated libraries
30:14 Fallback and policies
35:24 Start of demos
35:50 chainctl demo
40:47 Simple artifact download scripts demo
43:08 Example application and Maven settings.xml file
46:02 Building and running the example application
50:10 Advanced pom.xml modification
55:43 Final Q&A
About Chainguard
Founded by the industry's leading experts on open source software, security and cloud native development, we are on a mission to be the safe source for open source.
Where to find us:
Website: https://www.chainguard.dev/
Twitter: twitter.com/chainguard_dev
LinkedIn: linkedin.com/company/chainguard-dev
TikTok: tiktok.com/@chainguard_dev
AI frontier models are accelerating the discovery of vulnerabilities in Java applications at a pace that teams can't keep up with. If your team is stuck on older Java versions that are hard to upgrade, you need support to remediate those vulnerabilities so you can get time back in your day to build.
In this Learning Lab, Manfred Moser will share the details behind Chainguard Libraries for Java, providing an overview on how to start using remediated versions directly with Apache Maven, Gradle, or your current repository manager configuration. With every Chainguard-built version, he will show you how to pull SBOMs and provenance to demonstrate the integrity of your third-party artifacts.
Specifically, he’ll cover and demonstrate the following new features:
- CVE remediation for Spring Framework and other libraries
- Protected fallback to Maven Central
- Cooldown policy
Discover more: https://edu.chainguard.dev/software-security/learning-labs/ll202607/
TIMESTAMPS
0:00 Introduction
2:42 Software supply chain and open source components
6:20 History of software supply chain security issues and attacks
8:30 Chainguard Libraries and Chainguard Factory overview
11:30 Details about Chainguard Libraries
17:36 CVE remediation
24:30 What is remediated?
25:47 Browsing remediated libraries
30:14 Fallback and policies
35:24 Start of demos
35:50 chainctl demo
40:47 Simple artifact download scripts demo
43:08 Example application and Maven settings.xml file
46:02 Building and running the example application
50:10 Advanced pom.xml modification
55:43 Final Q&A
About Chainguard
Founded by the industry's leading experts on open source software, security and cloud native development, we are on a mission to be the safe source for open source.
Where to find us:
Website: https://www.chainguard.dev/
Twitter: twitter.com/chainguard_dev
LinkedIn: linkedin.com/company/chainguard-dev
TikTok: tiktok.com/@chainguard_dev










