Skip to content

Security1 publisher2 min readPublished

Chainguard opens Athena's 40,000-finding backlog on September 28 with fifty silent fixes

Chainguard says fix generation was never its bottleneck and that responsible disclosure at scale is, so its first public batch is built from bugs upstreams quietly fixed years ago and never filed CVEs for.

The Watch · Security desk

Illustration accompanying Chainguard opens Athena's 40,000-finding backlog on September 28 with fifty silent fixes

What happened

  • Chainguard says its Athena system has taken in more than 40,000 vulnerability findings since June, across more than 500 projects, and has produced more than 2,000 patches from them.
  • Chainguard rates 42 percent of those findings critical or high, which works out to roughly 16,800 of them.
  • Public disclosure starts on September 28 with about fifty findings, and Chainguard says the batch is deliberately low-stakes to see what breaks before the thousands behind it arrive.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint This program is now paced by how many disclosures a team can shepherd, not by detection capacity, and that ceiling does not rise when the model improves.
  • exposure Any program driven by scanner output has no record of these bugs at all, because the absent CVE means there is nothing for a scanner or an auditor's feed to key on.
  • decision Defenders running versions their upstream will not support have to decide whether a third party's patch repo is an acceptable fix source, and who signs off on applying a diff nobody upstream will ship.
  • precedent If the September batch clears without upstream objection, the same route is available for thousands more, and for anyone else pointing a model at deployed code.

Fifty is 2.5 percent of the patches Chainguard says it has already written, and roughly one eighth of one percent of the intake behind them [2][3]. The post puts the constraint downstream of the model: "Generating fixes was never the bottleneck. Disclosing them responsibly, at a scale nobody has ever tried, is," Chainguard wrote [15]. Every count here comes from that post [4].

The first batch avoids every process that could stall it. All fifty are bugs an upstream fixed at head, sometimes years ago, with no CVE ever filed [7]. Upstreams generally will not merge a fix into an old release, and Chainguard says they are right not to, because the code was rewritten and there is no branch to merge into [10]. Same for the advisory layer: no CVE gets filed for something already fixed at head [11]. "It's the one class of finding where acting doesn't step on anyone else's process, because there isn't one," Chainguard wrote [12].

According to Chainguard, a large share of what the models find affects only old versions, because the models scan what is actually deployed and what is deployed is old [9]. Where a project has no route for accepting a fix to an old version, Chainguard is publishing plain .patch files in a public repo under the project's original license, and says it is not forking the code or claiming stewardship [13][14]. The fix arrives as a diff, so someone on the operator's side applies it and rebuilds, and the same file tells anyone else reading the repo which old versions are affected. "Your scanner has nothing to say about them, and the old versions are still running everywhere," Chainguard wrote [8].

Live pre-auth remote code execution is not in this batch. It goes through a program Chainguard calls Akrites on embargo, and the post defers the explanation of how that works [16][22]. Chainguard has also joined Anthropic's Project Glasswing and says it is now finding vulnerabilities itself [17]. Writing in agreement with Dario Amodei's essay We Must Pace the Frontier, it argued that "Where governments can act is on consumption: not what the models can do, but what happens to what they find" [18][19]. For the fifty due on September 28, Chainguard wrote that "The durable fix is still upgrading", and describes the patch repo as somewhere to put fixes for the people who cannot upgrade yet [20][13].

What to watch

  • Whether the September 28 batch actually lands at about fifty, and what Chainguard reports breaking in the process it says the batch exists to test.
  • Whether any upstream maintainer objects publicly to a third party distributing patches for releases they will not support.
  • Details on Akrites: who receives pre-auth RCE findings under embargo, how long the embargo runs, and who arbitrates it.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories