# Reducing vulnerabilities in Backstage with Chainguard's Wolfi

DevFeed: [Reducing vulnerabilities in Backstage with Chainguard's Wolfi](<https://devfeed.tech/articles/reducing-vulnerabilities-in-backstage-with-chainguard-s-wolfi-13207.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/reducing-vulnerabilities-in-backstage-with-chainguards-wolfi>)

Published: 2024-05-16T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Backstage](<https://devfeed.tech/topics/backstage.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [internal developer portal](<https://devfeed.tech/topics/internal-developer-portal.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Developer experience](<https://devfeed.tech/topics/developer-experience.md>), [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>)

Tags: [backstage](<https://devfeed.tech/tags/backstage.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [developer-experience](<https://devfeed.tech/tags/developer-experience.md>), [developer-portal](<https://devfeed.tech/tags/developer-portal.md>), [docker](<https://devfeed.tech/tags/docker.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

## AI overview

This guest post describes how American Airlines evaluated Chainguard's Wolfi and wolfi-base image as an alternative base for its Backstage developer portal. The author reports that the original base image contained 74 vulnerabilities and that the default Docker build added 330 more, motivating a Dockerfile refactoring effort focused on reducing packages, image size, vulnerabilities, and software supply-chain risk while maintaining compatibility.

## Source excerpt

Learn how American Airlines enhanced Backstage security with Chainguard's Wolfi.