# apko

Published articles for apko.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Introducing Chainguard OS Packages: Secure ingredients for custom container builds

DevFeed: [Introducing Chainguard OS Packages: Secure ingredients for custom container builds](<https://devfeed.tech/articles/introducing-chainguard-os-packages-secure-ingredients-for-custom-container-builds-13112.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-chainguard-os-packages>)

Published: 2026-03-17T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Docker Hardened Images](<https://devfeed.tech/topics/docker-hardened-images.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [bazel](<https://devfeed.tech/topics/bazel.md>), [chainguard sboms](<https://devfeed.tech/topics/chainguard-sboms.md>), [APK](<https://devfeed.tech/topics/apk.md>)

Tags: [apk](<https://devfeed.tech/tags/apk.md>), [apko](<https://devfeed.tech/tags/apko.md>), [automation](<https://devfeed.tech/tags/automation.md>), [base-images](<https://devfeed.tech/tags/base-images.md>), [bazel](<https://devfeed.tech/tags/bazel.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [chainguard-os-packages](<https://devfeed.tech/tags/chainguard-os-packages.md>), [chainguard-packages](<https://devfeed.tech/tags/chainguard-packages.md>), [chainguard-sboms](<https://devfeed.tech/tags/chainguard-sboms.md>), [container](<https://devfeed.tech/tags/container.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [dockerfiles](<https://devfeed.tech/tags/dockerfiles.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-software-packages](<https://devfeed.tech/tags/secure-software-packages.md>), [software-packages](<https://devfeed.tech/tags/software-packages.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-cve-packages](<https://devfeed.tech/tags/zero-cve-packages.md>)

### AI overview

Chainguard introduces Chainguard OS Packages, a service providing continuously maintained, enterprise-grade packages and base images for teams that build custom container images. Customers retain control over image composition and build tooling while Chainguard handles package sourcing, rebuilding, vulnerability remediation, and SBOM generation.

### Source excerpt

Chainguard OS Packages are enterprise-grade, zero-CVE packages and base images built and continuously maintained in the Chainguard Factory.

## Reimagining the Linux distro with Wolfi

DevFeed: [Reimagining the Linux distro with Wolfi](<https://devfeed.tech/articles/reimagining-the-linux-distro-with-wolfi-13209.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/reimagining-the-linux-distro-with-wolfi>)

Published: 2024-02-21T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Linux](<https://devfeed.tech/topics/linux.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Package Management](<https://devfeed.tech/topics/package-management.md>), [APK](<https://devfeed.tech/topics/apk.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [apk](<https://devfeed.tech/tags/apk.md>), [apko](<https://devfeed.tech/tags/apko.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cve](<https://devfeed.tech/tags/cve.md>), [linux](<https://devfeed.tech/tags/linux.md>), [melange](<https://devfeed.tech/tags/melange.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [package-management](<https://devfeed.tech/tags/package-management.md>), [secure-container-images](<https://devfeed.tech/tags/secure-container-images.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

The article explains why Chainguard created Wolfi, a minimal Linux distribution designed for modern container use. It describes the roles of Melange for building APK packages and Apko for assembling reproducible container images, along with Wolfi's security advisory and vulnerability-management capabilities.

### Source excerpt

Discover Wolfi: Chainguard's answer to modern container security, creating minimal, secure Linux distributions for today's needs.

## Wolfi's approach to container security and CVE management

DevFeed: [Wolfi's approach to container security and CVE management](<https://devfeed.tech/articles/revolutionizing-container-security-and-cve-management-13213.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/revolutionizing-container-security-and-cve-management>)

Published: 2024-02-08T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [container-security](<https://devfeed.tech/topics/container-security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [apko](<https://devfeed.tech/tags/apko.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-management](<https://devfeed.tech/tags/cve-management.md>), [melange](<https://devfeed.tech/tags/melange.md>), [oci](<https://devfeed.tech/tags/oci.md>), [secure-images](<https://devfeed.tech/tags/secure-images.md>), [secure-software-supply-chain](<https://devfeed.tech/tags/secure-software-supply-chain.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

The article explains how Wolfi, a secure-by-default undistro, supports container security by helping create minimal, reproducible OCI-compliant images and reducing software supply chain risks. It also describes how Wolfi powers Chainguard Images.

### Source excerpt

Discover Wolfi, the 'secure-by-default' undistro for container security, enhancing open-source software with minimal CVE counts and robust protection.

## How Chainguard protects against "Leaky Vessel" container escape vulnerabilities

DevFeed: [How Chainguard protects against "Leaky Vessel" container escape vulnerabilities](<https://devfeed.tech/articles/how-chainguard-protects-against-leaky-vessel-container-escape-vulnerabilities-13084.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-chainguard-protects-against-leaky-vessel-container-escape-vulnerabilities>)

Published: 2024-02-01T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>)

Tags: [apko](<https://devfeed.tech/tags/apko.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [container-escape](<https://devfeed.tech/tags/container-escape.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-image](<https://devfeed.tech/tags/docker-image.md>), [leaky-vessel](<https://devfeed.tech/tags/leaky-vessel.md>), [patches](<https://devfeed.tech/tags/patches.md>), [runc](<https://devfeed.tech/tags/runc.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>)

### AI overview

This article explains the "Leaky Vessel" vulnerabilities affecting runc and BuildKit, including risks of container escape, host filesystem access, and elevated privileges. It describes how Chainguard Images use apko instead of runc or BuildKit and recommends upgrading to patched versions.

### Source excerpt

Chainguard's response to 'Leaky Vessel' vulnerabilities: safeguarding container images with innovative, secure-by-default build processes.

## Images as Code: The pursuit of declarative image builds

DevFeed: [Images as Code: The pursuit of declarative image builds](<https://devfeed.tech/articles/images-as-code-the-pursuit-of-declarative-image-builds-13101.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/images-as-code-the-pursuit-of-declarative-image-builds>)

Published: 2024-01-22T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Code](<https://devfeed.tech/topics/code.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [bazel](<https://devfeed.tech/topics/bazel.md>), [distroless](<https://devfeed.tech/topics/distroless.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>), [Infrastructure as code](<https://devfeed.tech/topics/infrastructure-as-code.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [apk](<https://devfeed.tech/tags/apk.md>), [apko](<https://devfeed.tech/tags/apko.md>), [bazel](<https://devfeed.tech/tags/bazel.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [code](<https://devfeed.tech/tags/code.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [containers](<https://devfeed.tech/tags/containers.md>), [declarative](<https://devfeed.tech/tags/declarative.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [docker](<https://devfeed.tech/tags/docker.md>), [infrastructure-as-code](<https://devfeed.tech/tags/infrastructure-as-code.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [reproducibility](<https://devfeed.tech/tags/reproducibility.md>), [terraform](<https://devfeed.tech/tags/terraform.md>)

### AI overview

The article traces the pursuit of declarative container image builds. It critiques imperative Dockerfile-based builds for making multi-tenant, multi-architecture, and reproducible builds difficult, then discusses Bazel and distroless images as steps toward expressing intended build state. Kubernetes and Terraform are presented as examples of declarative systems, inspiring the idea of "Images as Code."

### Source excerpt

Chainguard's CTO Matt Moore describes the process of creating a declarative container image build for Chainguard Images.

## Wolfi: a new paradigm in Linux for containers

DevFeed: [Wolfi: a new paradigm in Linux for containers](<https://devfeed.tech/articles/wolfi-a-new-paradigm-in-linux-for-containers-13336.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/wolfi-a-new-paradigm-in-linux-for-containers>)

Published: 2024-01-17T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Linux](<https://devfeed.tech/topics/linux.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Package Management](<https://devfeed.tech/topics/package-management.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [apk](<https://devfeed.tech/tags/apk.md>), [apko](<https://devfeed.tech/tags/apko.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [linux](<https://devfeed.tech/tags/linux.md>), [melange](<https://devfeed.tech/tags/melange.md>), [package-management](<https://devfeed.tech/tags/package-management.md>), [security](<https://devfeed.tech/tags/security.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Wolfi is a minimal Linux distribution designed for containerized applications. The article describes its focus on efficiency, security, rapid updates, reproducible APK-based package management, and container image creation through melange and apko.

### Source excerpt

Wolfi is a Linux distribution built specifically for containerized applications. See how it can speed up your development process.

## Building minimal, up-to-date cloud images with Wolfi

DevFeed: [Building minimal, up-to-date cloud images with Wolfi](<https://devfeed.tech/articles/building-minimal-up-to-date-cloud-images-with-wolfi-12908.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/building-minimal-up-to-date-cloud-images-with-wolfi>)

Published: 2023-12-15T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Cloud](<https://devfeed.tech/topics/cloud.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>), [DevOps](<https://devfeed.tech/topics/devops.md>)

Tags: [apk](<https://devfeed.tech/tags/apk.md>), [apko](<https://devfeed.tech/tags/apko.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [chainguard-academy](<https://devfeed.tech/tags/chainguard-academy.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [container](<https://devfeed.tech/tags/container.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [devops](<https://devfeed.tech/tags/devops.md>), [efficiency](<https://devfeed.tech/tags/efficiency.md>), [kubecon-na](<https://devfeed.tech/tags/kubecon-na.md>), [melange](<https://devfeed.tech/tags/melange.md>), [minimalism](<https://devfeed.tech/tags/minimalism.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [os](<https://devfeed.tech/tags/os.md>), [packages](<https://devfeed.tech/tags/packages.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

The article introduces Wolfi, an open source project for building minimal, up-to-date cloud and container images. It explains how Wolfi's security-first architecture, proactive updates, minimalism, and supporting tools such as melange, apko, and apk help reduce attack surfaces and CVE exposure while improving software supply chain security.

### Source excerpt

Discover Wolfi OS: Crafting minimal, always up-to-date cloud images for superior security and efficiency in the cloud.

## Announcing Bazel rules for extending Chainguard Images

DevFeed: [Announcing Bazel rules for extending Chainguard Images](<https://devfeed.tech/articles/announcing-bazel-rules-for-extending-chainguard-images-12875.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/announcing-bazel-rules-for-extending-chainguard-images>)

Published: 2023-10-24T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [distroless](<https://devfeed.tech/topics/distroless.md>), [Package manager](<https://devfeed.tech/topics/package-manager.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [apk](<https://devfeed.tech/tags/apk.md>), [apko](<https://devfeed.tech/tags/apko.md>), [bazel](<https://devfeed.tech/tags/bazel.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [secure-software-supply-chain](<https://devfeed.tech/tags/secure-software-supply-chain.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard and Aspect.Dev announce the general availability of rules_apko, an open source Bazel plugin for building secure, minimal Wolfi-based OCI container images. The article explains how rules_apko integrates APK packages and Wolfi-base images into existing Bazel workflows, supports reproducible builds, and provides dependency locking, integrity verification, and SBOM generation.

### Source excerpt

Explore Bazel rules for Chainguard Images, your pathway to secure, effortless image extension.

## Small octopus and a big idea: The story of how a one-year old Linux un-distro is improving the cloud's software supply chain

DevFeed: [Small octopus and a big idea: The story of how a one-year old Linux un-distro is improving the cloud's software supply chain](<https://devfeed.tech/articles/small-octopus-and-a-big-idea-the-story-of-how-a-one-year-old-linux-un-distro-is-improving-the-cloud-s-software-supply-chain-13234.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/small-octopus-and-a-big-idea-the-story-of-how-a-one-year-old-linux-un-distro-is-improving-the-clouds-software-supply-chain>)

Published: 2023-09-27T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Linux](<https://devfeed.tech/topics/linux.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>)

Tags: [apko](<https://devfeed.tech/tags/apko.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [containers](<https://devfeed.tech/tags/containers.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [linux](<https://devfeed.tech/tags/linux.md>), [melange](<https://devfeed.tech/tags/melange.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard reviews Wolfi's first year as a minimal Linux un-distro focused on rapid package updates, fast CVE remediation, and cloud-native software supply chain security. The article reports package, repository, contributor, update-interval, and vulnerability-scanning milestones, and describes Wolfi's rolling-release approach and wolfi-act integration with GitHub Actions.

### Source excerpt

Explore Wolfi's journey: A Linux un-distro revolutionizing cloud-native development with agile updates for robust software security.

## How to use Dockerfiles with wolfi-base images

DevFeed: [How to use Dockerfiles with wolfi-base images](<https://devfeed.tech/articles/how-to-use-dockerfiles-with-wolfi-base-images-13097.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-to-use-dockerfiles-with-wolfi-base-images>)

Published: 2023-09-14T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [distroless](<https://devfeed.tech/topics/distroless.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Go](<https://devfeed.tech/topics/go.md>)

Tags: [apko](<https://devfeed.tech/tags/apko.md>), [base-images](<https://devfeed.tech/tags/base-images.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-hub](<https://devfeed.tech/tags/docker-hub.md>), [dockerfiles](<https://devfeed.tech/tags/dockerfiles.md>), [go](<https://devfeed.tech/tags/go.md>), [guide](<https://devfeed.tech/tags/guide.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [melange](<https://devfeed.tech/tags/melange.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

This tutorial explains how to use Dockerfiles with Chainguard wolfi-base and other Chainguard Images. It covers minimal static images, glibc-dynamic images, multi-stage builds, package management, and selecting image variants based on application dependencies and runtime needs.

### Source excerpt

Your guide to leveraging Dockerfiles with Wolfi-base images for hardened container images.

## Reproducing Chainguard's reproducible image builds

DevFeed: [Reproducing Chainguard's reproducible image builds](<https://devfeed.tech/articles/reproducing-chainguard-s-reproducible-image-builds-13211.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/reproducing-chainguards-reproducible-image-builds>)

Published: 2023-07-05T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>)

Tags: [apko](<https://devfeed.tech/tags/apko.md>), [attestation](<https://devfeed.tech/tags/attestation.md>), [build](<https://devfeed.tech/tags/build.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [cosign](<https://devfeed.tech/tags/cosign.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [locks](<https://devfeed.tech/tags/locks.md>), [reproducibility](<https://devfeed.tech/tags/reproducibility.md>), [reproducible-builds](<https://devfeed.tech/tags/reproducible-builds.md>), [secure-image](<https://devfeed.tech/tags/secure-image.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

A tutorial explaining how to reproduce a Chainguard Images build using cosign and apko. It describes locking image configurations and notes caveats involving tooling changes and withdrawn packages.

### Source excerpt

Learn how to reproduce a Chainguard Images build using cosign and apko.

## Chainguard Image now available for Pulumi

DevFeed: [Chainguard Image now available for Pulumi](<https://devfeed.tech/articles/chainguard-image-now-available-for-pulumi-12951.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-image-now-available-for-pulumi>)

Published: 2023-06-29T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [pulumi](<https://devfeed.tech/topics/pulumi.md>), [Infrastructure as code](<https://devfeed.tech/topics/infrastructure-as-code.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [apko](<https://devfeed.tech/tags/apko.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [iac](<https://devfeed.tech/tags/iac.md>), [multi-arch](<https://devfeed.tech/tags/multi-arch.md>), [pulumi](<https://devfeed.tech/tags/pulumi.md>), [security](<https://devfeed.tech/tags/security.md>), [trivy](<https://devfeed.tech/tags/trivy.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>), [x86-64](<https://devfeed.tech/tags/x86-64.md>)

### AI overview

Chainguard announces a Pulumi container image packaged with the Pulumi toolchain in Wolfi OS and built using apko. The image supports multiple programming-language runtimes, is multi-architecture, and is reported to be smaller and to have fewer Trivy-reported CVEs than the official Pulumi image.

### Source excerpt

See a 57% reduction in your Pulumi image sizes with more security built in by default and a 97% reduction in CVEs with the new Chainguard Pulumi Image.

## apko: a year later

DevFeed: [apko: a year later](<https://devfeed.tech/articles/apko-a-year-later-12887.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/apko-a-year-later>)

Published: 2023-02-28T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Development](<https://devfeed.tech/topics/development.md>), [Package manager](<https://devfeed.tech/topics/package-manager.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Unix](<https://devfeed.tech/topics/unix.md>), [YAML](<https://devfeed.tech/topics/yaml.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>)

Tags: [alpine](<https://devfeed.tech/tags/alpine.md>), [apk](<https://devfeed.tech/tags/apk.md>), [apko](<https://devfeed.tech/tags/apko.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-enforce](<https://devfeed.tech/tags/chainguard-enforce.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [development](<https://devfeed.tech/tags/development.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [golang](<https://devfeed.tech/tags/golang.md>), [linux](<https://devfeed.tech/tags/linux.md>), [macos](<https://devfeed.tech/tags/macos.md>), [melange](<https://devfeed.tech/tags/melange.md>), [secure-software-supply-chain](<https://devfeed.tech/tags/secure-software-supply-chain.md>), [terraform-provider](<https://devfeed.tech/tags/terraform-provider.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>), [yaml](<https://devfeed.tech/tags/yaml.md>)

### AI overview

This article reviews apko one year after its public release. It describes apko's native Go implementation of the apk package manager, which runs on UNIX-like systems including macOS and BSDs, and explains how its declarative YAML interface helped support an ecosystem that includes Chainguard Images, Melange, Wolfi, and a Terraform provider. The article presents apko as a foundation for secure software supply chains through images-as-code and frequent image rebuilds.

### Source excerpt

Dive in to apko and learn more about the project; where it's been in the past year, and where it's going.

## Make SBOMs, not GuessBOMs: Why we need to shift left on SBOM generation

DevFeed: [Make SBOMs, not GuessBOMs: Why we need to shift left on SBOM generation](<https://devfeed.tech/articles/make-sboms-not-guessboms-why-we-need-to-shift-left-on-sbom-generation-13142.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/make-sboms-not-guessboms-why-we-need-to-shift-left-on-sbom-generation>)

Published: 2023-01-26T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [software dark matter](<https://devfeed.tech/topics/software-dark-matter.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Reverse Engineering](<https://devfeed.tech/topics/reverse-engineering.md>), [Containers](<https://devfeed.tech/topics/containers.md>)

Tags: [apko](<https://devfeed.tech/tags/apko.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [guessbom](<https://devfeed.tech/tags/guessbom.md>), [melange](<https://devfeed.tech/tags/melange.md>), [reverse-engineering](<https://devfeed.tech/tags/reverse-engineering.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [sca](<https://devfeed.tech/tags/sca.md>), [shift-left](<https://devfeed.tech/tags/shift-left.md>), [software-composition-analysis](<https://devfeed.tech/tags/software-composition-analysis.md>), [software-dark-matter](<https://devfeed.tech/tags/software-dark-matter.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The article argues that SBOMs generated after a build by software composition analysis tools can be incomplete because they may miss components that bypass recorded metadata, such as files copied through Dockerfiles. It presents build-time generation as a better way to produce complete SBOMs and describes untracked files as software dark matter, which can make post-build SBOMs closer to best guesses than reliable inventories.

### Source excerpt

GuessBOMs, SBOMs generated by reverse-engineering software artifacts, have severe limitations. The optimal point for generating complete SBOMs is at build time.