<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Automation on</title><link>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/tags/automation/</link><description>Recent content in Automation on</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><copyright>Copyright (c) 2023 Chainguard</copyright><lastBuildDate>Mon, 28 Sep 2026 16:33:22 +0000</lastBuildDate><atom:link href="https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/tags/automation/index.xml" rel="self" type="application/rss+xml"/><item><title>Managing tag-based Custom Assembly with Terraform</title><link>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/chainguard/containers/custom-assembly/tag-based-custom-assembly/terraform/</link><pubDate>Mon, 28 Sep 2026 16:33:22 +0000</pubDate><guid>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/chainguard/containers/custom-assembly/tag-based-custom-assembly/terraform/</guid><description>&lt;p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note&lt;/strong&gt;: Tag-based Custom Assembly is in beta. Contact your Chainguard account team to enable it for your organization.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/p&gt;
&lt;p&gt;This guide shows how to manage tag-based Custom Assembly with the &lt;a href="https://registry.terraform.io/providers/chainguard-dev/chainguard/latest"&gt;Chainguard Terraform provider&lt;/a&gt;. You define overlays with the &lt;code&gt;chainguard_image_overlay&lt;/code&gt; resource and bind them to repositories with the &lt;code&gt;chainguard_image_overlay_binding&lt;/code&gt; resource.&lt;/p&gt;
&lt;p&gt;For an explanation of overlays, bindings, and tag selectors, see &lt;a href="https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/chainguard/containers/custom-assembly/tag-based-custom-assembly/"&gt;Overview of tag-based Custom Assembly&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id="prerequisites" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;Prerequisites&lt;/span&gt;
&lt;a href="#prerequisites" class="anchor" aria-label="Link to Prerequisites" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;Before you start, you need the following:&lt;/p&gt;</description></item><item><title>Guardener Hardened Actions</title><link>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/chainguard/guardener/github/actions-security/</link><pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate><guid>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/chainguard/guardener/github/actions-security/</guid><description>&lt;p&gt;The Hardened Actions feature recommends and migrates your GitHub Actions to Chainguard&amp;rsquo;s hardened, SHA-pinned equivalents. Pinning actions to a specific commit SHA — rather than a mutable tag or branch — protects your workflows from supply chain attacks in which an upstream tag is moved to point at malicious code.&lt;/p&gt;
&lt;p&gt;Hardened Actions operates in two independent modes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Pull request recommendations&lt;/strong&gt; — non-blocking review comments that suggest hardened action alternatives, with one-click suggestion blocks.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Automated migration pull requests&lt;/strong&gt; — a periodically maintained pull request that updates workflows across your repository. You can also &lt;a href="https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/chainguard/guardener/github/actions-security/#run-an-on-demand-migration"&gt;trigger this migration on demand&lt;/a&gt; with &lt;code&gt;chainctl&lt;/code&gt; instead of waiting for the next scheduled run.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;You can enable either mode on its own or both together.&lt;/p&gt;</description></item></channel></rss>