# base images

Published articles for base images.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## What Is a Container Registry and How to Use One

DevFeed: [What Is a Container Registry and How to Use One](<https://devfeed.tech/articles/what-is-a-container-registry-and-how-to-use-one-17491.md>)

Original publisher: [Read original article](<https://kodekloud.com/blog/what-is-a-container-registry-and-how-to-use-one/>)

Author: Pramodh Kumar M

Published: 2026-08-10T17:48:35Z

Content type: tutorial

Language: en

Sources: [Kubernetes - KodeKloud Blog | DevOps, Cloud, Kubernetes, AI Tutorials & More](<https://devfeed.tech/sources/kubernetes-kodekloud-blog-devops-cloud-kubernetes-ai-tutorials-more.md>)

Topics: [container images](<https://devfeed.tech/topics/container-images.md>), [content addressed store](<https://devfeed.tech/topics/content-addressed-store.md>), [Docker Hub](<https://devfeed.tech/topics/docker-hub.md>), [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>)

Tags: [base-images](<https://devfeed.tech/tags/base-images.md>), [cache](<https://devfeed.tech/tags/cache.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [container-registry](<https://devfeed.tech/tags/container-registry.md>), [containers](<https://devfeed.tech/tags/containers.md>), [content-addressed-store](<https://devfeed.tech/tags/content-addressed-store.md>), [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [devops](<https://devfeed.tech/tags/devops.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-hub](<https://devfeed.tech/tags/docker-hub.md>), [docker-login](<https://devfeed.tech/tags/docker-login.md>), [docker-pull-rate-limits](<https://devfeed.tech/tags/docker-pull-rate-limits.md>), [docker-registry](<https://devfeed.tech/tags/docker-registry.md>), [harbor](<https://devfeed.tech/tags/harbor.md>), [image-manifest](<https://devfeed.tech/tags/image-manifest.md>), [image-retention-policy](<https://devfeed.tech/tags/image-retention-policy.md>), [image-scanning](<https://devfeed.tech/tags/image-scanning.md>), [image-tags-vs-digests](<https://devfeed.tech/tags/image-tags-vs-digests.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [private-registry](<https://devfeed.tech/tags/private-registry.md>), [pull-through-cache](<https://devfeed.tech/tags/pull-through-cache.md>), [reproducible-builds](<https://devfeed.tech/tags/reproducible-builds.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

This guide explains how container registries store and distribute container images, emphasizing the distinction between mutable tags and immutable content digests. It also covers pushing, pulling, authentication, Docker Hub rate limits, caching, scanning, and retention.

### Source excerpt

A tag is a bookmark somebody else can move. A digest is the image itself. Once that distinction lands, reproducible builds, supply chain security, and every it worked yesterday mystery make sense.

## Introducing Chainguard OS Packages: Secure ingredients for custom container builds

DevFeed: [Introducing Chainguard OS Packages: Secure ingredients for custom container builds](<https://devfeed.tech/articles/introducing-chainguard-os-packages-secure-ingredients-for-custom-container-builds-13112.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-chainguard-os-packages>)

Published: 2026-03-17T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Docker Hardened Images](<https://devfeed.tech/topics/docker-hardened-images.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [bazel](<https://devfeed.tech/topics/bazel.md>), [chainguard sboms](<https://devfeed.tech/topics/chainguard-sboms.md>), [APK](<https://devfeed.tech/topics/apk.md>)

Tags: [apk](<https://devfeed.tech/tags/apk.md>), [apko](<https://devfeed.tech/tags/apko.md>), [automation](<https://devfeed.tech/tags/automation.md>), [base-images](<https://devfeed.tech/tags/base-images.md>), [bazel](<https://devfeed.tech/tags/bazel.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [chainguard-os-packages](<https://devfeed.tech/tags/chainguard-os-packages.md>), [chainguard-packages](<https://devfeed.tech/tags/chainguard-packages.md>), [chainguard-sboms](<https://devfeed.tech/tags/chainguard-sboms.md>), [container](<https://devfeed.tech/tags/container.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [dockerfiles](<https://devfeed.tech/tags/dockerfiles.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-software-packages](<https://devfeed.tech/tags/secure-software-packages.md>), [software-packages](<https://devfeed.tech/tags/software-packages.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-cve-packages](<https://devfeed.tech/tags/zero-cve-packages.md>)

### AI overview

Chainguard introduces Chainguard OS Packages, a service providing continuously maintained, enterprise-grade packages and base images for teams that build custom container images. Customers retain control over image composition and build tooling while Chainguard handles package sourcing, rebuilding, vulnerability remediation, and SBOM generation.

### Source excerpt

Chainguard OS Packages are enterprise-grade, zero-CVE packages and base images built and continuously maintained in the Chainguard Factory.

## Be my base image: Introducing Linky's Matchmaker

DevFeed: [Be my base image: Introducing Linky's Matchmaker](<https://devfeed.tech/articles/be-my-base-image-introducing-linky-s-matchmaker-12896.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/be-my-base-image-introducing-linkys-matchmaker>)

Published: 2026-02-12T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [App](<https://devfeed.tech/topics/app.md>), [Web](<https://devfeed.tech/topics/web.md>)

Tags: [base-images](<https://devfeed.tech/tags/base-images.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-valentine-s-day](<https://devfeed.tech/tags/chainguard-valentine-s-day.md>), [comparisons](<https://devfeed.tech/tags/comparisons.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [dockerfile-converter](<https://devfeed.tech/tags/dockerfile-converter.md>), [dockerfiles](<https://devfeed.tech/tags/dockerfiles.md>), [documentation](<https://devfeed.tech/tags/documentation.md>), [images](<https://devfeed.tech/tags/images.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Linky's Matchmaker is a web-based app that analyzes Dockerfiles, recommends compatible Chainguard Containers, and generates downloadable converted Dockerfiles. It also provides image availability checks, documentation and tag links, and vulnerability comparisons.

### Source excerpt

Linky's Matchmaker converts your Dockerfile to Chainguard Containers, recommending secure, minimal base images and generating an updated file in minutes

## Security baked into your software supply chain: The combined benefit of JFrog and Chainguard

DevFeed: [Security baked into your software supply chain: The combined benefit of JFrog and Chainguard](<https://devfeed.tech/articles/security-baked-into-your-software-supply-chain-the-combined-benefit-of-jfrog-and-chainguard-13248.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-combined-benefit-of-jfrog-and-chainguard>)

Published: 2026-01-23T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Jfrog](<https://devfeed.tech/topics/jfrog.md>), [Docker Hub](<https://devfeed.tech/topics/docker-hub.md>), [AI Models](<https://devfeed.tech/topics/ai-models.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-models](<https://devfeed.tech/tags/ai-models.md>), [base-images](<https://devfeed.tech/tags/base-images.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-jfrog](<https://devfeed.tech/tags/chainguard-jfrog.md>), [chainguard-jfrog-collaboration](<https://devfeed.tech/tags/chainguard-jfrog-collaboration.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container](<https://devfeed.tech/tags/container.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [devops](<https://devfeed.tech/tags/devops.md>), [docker-hub](<https://devfeed.tech/tags/docker-hub.md>), [jfrog](<https://devfeed.tech/tags/jfrog.md>), [jfrog-artifactory](<https://devfeed.tech/tags/jfrog-artifactory.md>), [jfrog-xray](<https://devfeed.tech/tags/jfrog-xray.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article describes a Chainguard and JFrog collaboration for securing the software supply chain through secure-by-default container base images, policy-based curation, and continuous compliance. It presents Chainguard as providing clean, continuously updated images and JFrog Curation as screening upstream components and enforcing organizational policies.

### Source excerpt

Chainguard and JFrog secure the software supply chain with secure-by-default container images, policy-based curation, and continuous compliance.

## It's time to rethink golden images. Chainguard can help.

DevFeed: [It's time to rethink golden images. Chainguard can help.](<https://devfeed.tech/articles/it-s-time-to-rethink-golden-images-chainguard-can-help-13130.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/its-time-to-rethink-golden-images-chainguard-can-help>)

Published: 2025-11-17T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [DevOps](<https://devfeed.tech/topics/devops.md>), [Tech Debt](<https://devfeed.tech/topics/tech-debt.md>)

Tags: [base-images](<https://devfeed.tech/tags/base-images.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-golden-images](<https://devfeed.tech/tags/chainguard-golden-images.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [development](<https://devfeed.tech/tags/development.md>), [devops](<https://devfeed.tech/tags/devops.md>), [golden-container-images](<https://devfeed.tech/tags/golden-container-images.md>), [golden-images](<https://devfeed.tech/tags/golden-images.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

Chainguard advocates developer-centric golden image programs built on secure, trusted, purpose-built container base images. The approach aims to balance governance and standardization with developer flexibility, improving delivery speed while reducing maintenance costs, vulnerabilities, and compliance concerns.

### Source excerpt

Chainguard helps teams build developer-centric golden image programs with zero-CVE, purpose-built containers--balancing speed, security, and standardization.

## 10 Docker Security Best Practices

DevFeed: [10 Docker Security Best Practices](<https://devfeed.tech/articles/10-docker-security-best-practices-7763.md>)

Original publisher: [Read original article](<https://snyk.io/blog/10-docker-image-security-best-practices/>)

Author: Liran Tal; Omer Levi Hevroni

Published: 2025-01-08T18:58:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Docker](<https://devfeed.tech/topics/docker.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [alpine](<https://devfeed.tech/tags/alpine.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [base-images](<https://devfeed.tech/tags/base-images.md>), [c](<https://devfeed.tech/tags/c.md>), [cheat-sheet](<https://devfeed.tech/tags/cheat-sheet.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [debian](<https://devfeed.tech/tags/debian.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [docker](<https://devfeed.tech/tags/docker.md>), [go](<https://devfeed.tech/tags/go.md>), [google](<https://devfeed.tech/tags/google.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [snyk-container](<https://devfeed.tech/tags/snyk-container.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article explains Docker security across image builds, container runtime, supply-chain risks, and orchestration. It presents best practices including using minimal or distroless base images, multi-stage builds, reducing attack surface, and running containers with the least privilege. It also references Docker Hub, Kubernetes, Helm, Alpine Linux, Go, C, Debian, Node, and Google distroless images.

### Source excerpt

Understand the basics of Docker security best practices with our Docker Cheat Sheet to improve container security.

## Efficient Dockerfile templating for complex build scenarios

DevFeed: [Efficient Dockerfile templating for complex build scenarios](<https://devfeed.tech/articles/efficient-dockerfile-templating-for-complex-build-scenarios-27715.md>)

Original publisher: [Read original article](<https://gagor.pro/2025/01/efficient-dockerfile-templating-for-complex-build-scenarios/>)

Author: Tom

Published: 2025-01-01T00:00:00Z

Content type: tutorial

Language: en

Sources: [Tomasz Gągor](<https://devfeed.tech/sources/tomasz-gagor.md>)

Topics: [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Docker Image](<https://devfeed.tech/topics/docker-image.md>), [configuration](<https://devfeed.tech/topics/configuration.md>)

Tags: [alpine](<https://devfeed.tech/tags/alpine.md>), [base-images](<https://devfeed.tech/tags/base-images.md>), [best-practices](<https://devfeed.tech/tags/best-practices.md>), [build](<https://devfeed.tech/tags/build.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [devops](<https://devfeed.tech/tags/devops.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-base-images](<https://devfeed.tech/tags/docker-base-images.md>), [dockerfiles](<https://devfeed.tech/tags/dockerfiles.md>), [go](<https://devfeed.tech/tags/go.md>), [infra](<https://devfeed.tech/tags/infra.md>), [java](<https://devfeed.tech/tags/java.md>), [linux](<https://devfeed.tech/tags/linux.md>), [scm](<https://devfeed.tech/tags/scm.md>), [sre](<https://devfeed.tech/tags/sre.md>), [ubuntu](<https://devfeed.tech/tags/ubuntu.md>)

### AI overview

This article explains why Dockerfile templating can help maintain complex Docker base-image variants. It discusses combinations of operating systems, Tomcat versions, Java versions, configurations, and package names, along with the differing responsibilities of development and infrastructure teams.

### Source excerpt

Why even consider templating Dockerfiles? Dockerfiles revolutionized the industry with their simplicity. Each instruction creates a new layer in the image, which is automatically cached. This process integrates well with SCM, where you "commit" the results of one stage and move forward with other changes. The process can be easily parameterized with ARG instructions, similar to ENV but provided during the build. This allows for creating highly flexible builds. For most users, this is more than sufficient. However, there's a notable exception: Docker base images.

## How to transition to secure container images with new migration guides

DevFeed: [How to transition to secure container images with new migration guides](<https://devfeed.tech/articles/how-to-transition-to-secure-container-images-with-new-migration-guides-13096.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-to-transition-to-secure-container-images-with-new-migration-guides>)

Published: 2024-05-22T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [migration](<https://devfeed.tech/topics/migration.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [APK](<https://devfeed.tech/topics/apk.md>), [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [Package manager](<https://devfeed.tech/topics/package-manager.md>), [Bash](<https://devfeed.tech/topics/bash.md>), [Zsh](<https://devfeed.tech/topics/zsh.md>), [Debian](<https://devfeed.tech/topics/debian.md>)

Tags: [and-best-practices](<https://devfeed.tech/tags/and-best-practices.md>), [apk](<https://devfeed.tech/tags/apk.md>), [base-images](<https://devfeed.tech/tags/base-images.md>), [bash](<https://devfeed.tech/tags/bash.md>), [best-practices](<https://devfeed.tech/tags/best-practices.md>), [build](<https://devfeed.tech/tags/build.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container](<https://devfeed.tech/tags/container.md>), [container-based-application](<https://devfeed.tech/tags/container-based-application.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [container-security-strategy](<https://devfeed.tech/tags/container-security-strategy.md>), [cves](<https://devfeed.tech/tags/cves.md>), [debian](<https://devfeed.tech/tags/debian.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [docker-hub-image](<https://devfeed.tech/tags/docker-hub-image.md>), [dockerfiles](<https://devfeed.tech/tags/dockerfiles.md>), [guides](<https://devfeed.tech/tags/guides.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [image-migration](<https://devfeed.tech/tags/image-migration.md>), [migration](<https://devfeed.tech/tags/migration.md>), [migration-guides](<https://devfeed.tech/tags/migration-guides.md>), [python-image](<https://devfeed.tech/tags/python-image.md>), [secure-container-image](<https://devfeed.tech/tags/secure-container-image.md>), [secure-container-images](<https://devfeed.tech/tags/secure-container-images.md>)

### AI overview

This guide explains how to migrate container images to Chainguard Images for smaller image sizes, fewer vulnerabilities, and continuous maintenance. It covers using -dev images for shells and package managers, installing bash or zsh when needed, searching for packages with apk, and adapting Dockerfiles and entrypoint scripts.

### Source excerpt

Struggling to adopt secure container images? Our new migration guides provide step-by-step instructions and best practices for a smooth transition.

## Into the deep: Exploring Chainguard Container Images

DevFeed: [Into the deep: Exploring Chainguard Container Images](<https://devfeed.tech/articles/into-the-deep-exploring-chainguard-container-images-13104.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/into-the-deep-exploring-chainguard-container-images>)

Published: 2023-11-29T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [soc2](<https://devfeed.tech/topics/soc2.md>)

Tags: [base-images](<https://devfeed.tech/tags/base-images.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [soc2](<https://devfeed.tech/tags/soc2.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

Chainguard Images provide value beyond low CVE counts by supporting software supply chain security. The article discusses rapid CVE remediation through Wolfi, enterprise remediation SLAs, compliance requirements, and the use of trusted minimal base images to reduce supply chain attack risk.

### Source excerpt

Learn how Chainguard Images go beyond reducing CVE count in your software supply chain, with hardened container images, SBOMs, and more.

## Conquering your Build Horizon

DevFeed: [Conquering your Build Horizon](<https://devfeed.tech/articles/conquering-your-build-horizon-13012.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/conquering-your-build-horizon>)

Published: 2023-10-10T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Automation](<https://devfeed.tech/topics/automation.md>), [rego](<https://devfeed.tech/topics/rego.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [GitHub Copilot](<https://devfeed.tech/topics/github-copilot.md>)

Tags: [architecture](<https://devfeed.tech/tags/architecture.md>), [automation](<https://devfeed.tech/tags/automation.md>), [base-images](<https://devfeed.tech/tags/base-images.md>), [build-horizon](<https://devfeed.tech/tags/build-horizon.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [config](<https://devfeed.tech/tags/config.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [defense-in-depth](<https://devfeed.tech/tags/defense-in-depth.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [github-action](<https://devfeed.tech/tags/github-action.md>), [rego](<https://devfeed.tech/tags/rego.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The article presents Build Horizon, a policy that limits how long build artifacts such as binaries and container images may remain in production before being rebuilt. It explains how freshness controls, dependency automation, and policy checks can reduce risks from outdated software and long-lived builds.

### Source excerpt

"Build Horizon" is a practice that imposes a maximum age on build artifacts. Learn more about how it works and see an example in action!

## How to use Dockerfiles with wolfi-base images

DevFeed: [How to use Dockerfiles with wolfi-base images](<https://devfeed.tech/articles/how-to-use-dockerfiles-with-wolfi-base-images-13097.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-to-use-dockerfiles-with-wolfi-base-images>)

Published: 2023-09-14T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [distroless](<https://devfeed.tech/topics/distroless.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Go](<https://devfeed.tech/topics/go.md>)

Tags: [apko](<https://devfeed.tech/tags/apko.md>), [base-images](<https://devfeed.tech/tags/base-images.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-hub](<https://devfeed.tech/tags/docker-hub.md>), [dockerfiles](<https://devfeed.tech/tags/dockerfiles.md>), [go](<https://devfeed.tech/tags/go.md>), [guide](<https://devfeed.tech/tags/guide.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [melange](<https://devfeed.tech/tags/melange.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

This tutorial explains how to use Dockerfiles with Chainguard wolfi-base and other Chainguard Images. It covers minimal static images, glibc-dynamic images, multi-stage builds, package management, and selecting image variants based on application dependencies and runtime needs.

### Source excerpt

Your guide to leveraging Dockerfiles with Wolfi-base images for hardened container images.

## What kind of (security) dog are you?

DevFeed: [What kind of (security) dog are you?](<https://devfeed.tech/articles/what-kind-of-security-dog-are-you-8245.md>)

Original publisher: [Read original article](<https://snyk.io/blog/what-kind-of-security-dog-are-you/>)

Author: Belyn Lai

Published: 2023-08-25T17:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [base-images](<https://devfeed.tech/tags/base-images.md>), [components](<https://devfeed.tech/tags/components.md>), [containers](<https://devfeed.tech/tags/containers.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [developer](<https://devfeed.tech/tags/developer.md>), [developers](<https://devfeed.tech/tags/developers.md>), [development](<https://devfeed.tech/tags/development.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [regulatory](<https://devfeed.tech/tags/regulatory.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [security-tools](<https://devfeed.tech/tags/security-tools.md>), [shift-left](<https://devfeed.tech/tags/shift-left.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-team](<https://devfeed.tech/tags/snyk-team.md>), [testing](<https://devfeed.tech/tags/testing.md>), [third-party](<https://devfeed.tech/tags/third-party.md>), [tool](<https://devfeed.tech/tags/tool.md>), [tools](<https://devfeed.tech/tags/tools.md>), [training](<https://devfeed.tech/tags/training.md>)

### AI overview

A playful Snyk quiz for International Dog Day uses security-dog personalities to explore how organizations handle SBOMs, open source components, AI, third-party base images, security tools, pipeline testing, shift-left practices, and security training.

### Source excerpt

In honor of International Dog Day, we've created a quiz: What kind of (security) dog are you? And while you're taking it, tell your dog that we say hi and give that good boy or girl a treat on our behalf!

## How Chainguard fixes vulnerabilities before they're detected

DevFeed: [How Chainguard fixes vulnerabilities before they're detected](<https://devfeed.tech/articles/how-chainguard-fixes-vulnerabilities-before-they-re-detected-13083.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-chainguard-fixes-vulnerabilities-before-theyre-detected>)

Published: 2023-07-14T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Go](<https://devfeed.tech/topics/go.md>), [Security](<https://devfeed.tech/topics/security.md>), [Software](<https://devfeed.tech/topics/software.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>), [HTTP](<https://devfeed.tech/topics/http.md>), [releases](<https://devfeed.tech/topics/releases.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [OAI-PMH](<https://devfeed.tech/topics/oai-pmh.md>)

Tags: [automated](<https://devfeed.tech/tags/automated.md>), [base-images](<https://devfeed.tech/tags/base-images.md>), [build](<https://devfeed.tech/tags/build.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cve](<https://devfeed.tech/tags/cve.md>), [go](<https://devfeed.tech/tags/go.md>), [http](<https://devfeed.tech/tags/http.md>), [image-cves](<https://devfeed.tech/tags/image-cves.md>), [library](<https://devfeed.tech/tags/library.md>), [net](<https://devfeed.tech/tags/net.md>), [repo](<https://devfeed.tech/tags/repo.md>), [scanner](<https://devfeed.tech/tags/scanner.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard describes how Wolfi rapidly remediated CVE-2023-29406 in Go by automating upstream release monitoring, package rebuilding, testing, review, and release. The article explains that the fix reached Wolfi-packaged Go applications before vulnerability scanners had the information needed to detect it, and that the updated Go image and dependent packages were rebuilt to include the fix.

### Source excerpt

Uncover Chainguard's strategic vulnerability remediation, enhancing your software's security posture.

## Container Loading in AWS Lambda

DevFeed: [Container Loading in AWS Lambda](<https://devfeed.tech/articles/container-loading-in-aws-lambda-12538.md>)

Original publisher: [Read original article](<http://brooker.co.za/blog/2023/05/23/snapshot-loading.html>)

Author: Marc Brooker

Published: 2023-05-23T00:00:00Z

Content type: article

Language: en

Sources: [Marc Brooker's Blog](<https://devfeed.tech/sources/marc-brooker-s-blog.md>), [Marc Brooker's Blog](<https://devfeed.tech/sources/marc-brooker-s-blog-2.md>)

Topics: [AWS Lambda](<https://devfeed.tech/topics/aws-lambda.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Caching](<https://devfeed.tech/topics/caching.md>), [Latency](<https://devfeed.tech/topics/latency.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [aws](<https://devfeed.tech/tags/aws.md>), [aws-lambda](<https://devfeed.tech/tags/aws-lambda.md>), [base-images](<https://devfeed.tech/tags/base-images.md>), [cache](<https://devfeed.tech/tags/cache.md>), [caching](<https://devfeed.tech/tags/caching.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [data](<https://devfeed.tech/tags/data.md>), [latency](<https://devfeed.tech/tags/latency.md>), [performance](<https://devfeed.tech/tags/performance.md>)

### AI overview

The article explains how AWS Lambda loads container images on demand without increasing cold-start latency. It highlights block-level deduplication, caching of common base images, and lazy loading of data only when container processes read it.

### Source excerpt

Container Loading in AWS Lambda Slap shot? Back in 2019, we started thinking about how allow Lambda customers to use container images to deploy their Lambda functions. In theory this is easy enough: a container image is an image of a filesystem, just like the zip files we already supported. The difficulty, as usual with big systems, was performance. Specifically latency. More specifically cold start latency. For eight years cold start latency has been one of our biggest investment areas in Lambda, and we wanted to support container images without increasing latency. But how do you take the biggest contributor to latency (downloading the image), increase the work it needs to do 40x (up to 10GiB from 256MiB), without increasing latency? The answer to that question is in our new paper On-demand Container Loading in AWS Lambda, which appeared at Usenix ATC'23. In this post, I'll pull out some highlights from the paper that I think folks might find particularly interesting. Deduplication The biggest win in container loading comes from deduplication: avoiding moving around the same piece of data multiple times. Almost all container images are created from a relatively small set of very popular base images, and by avoiding copying these base images around multiple times and caching them near where they are used, we can make things move much faster. Our data shows that something like 75% of container images contain less than 5% unique bytes. This isn't a new observation, and several other container loading systems already take advantage of it. Most of the existing systems1 do this at the layer or file level, but we chose to do it at the block level. We unpack a snapshot (deterministically, which turns out to be tricky) into a single flat filesystem, then break that filesystem up into 512KiB chunks. We can then hash the chunks to identify unique contents, and avoid having too many copies of the same data in the cache layers. Lazy Loading Most of the data in container images

## GitCommitted with your dream base image

DevFeed: [GitCommitted with your dream base image](<https://devfeed.tech/articles/gitcommitted-with-your-dream-base-image-13065.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/gitcommitted-with-your-dream-base-image>)

Published: 2023-04-01T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [App](<https://devfeed.tech/topics/app.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>)

Tags: [app](<https://devfeed.tech/tags/app.md>), [article](<https://devfeed.tech/tags/article.md>), [base-images](<https://devfeed.tech/tags/base-images.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [compare](<https://devfeed.tech/tags/compare.md>), [cve](<https://devfeed.tech/tags/cve.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [secure-images](<https://devfeed.tech/tags/secure-images.md>), [security](<https://devfeed.tech/tags/security.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [verify](<https://devfeed.tech/tags/verify.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard introduces GitCommitted, an app for finding and comparing base images according to project needs. It helps users evaluate image size, CVE count, SLSA level, signing and verification, location and version, and SBOM availability when selecting a secure base image.

### Source excerpt

Find your ideal base image with Chainguard's insights at GitCommitted, tailored to your project needs.

## Hopping into spring with Chainguard's RabbitMQ Image

DevFeed: [Hopping into spring with Chainguard's RabbitMQ Image](<https://devfeed.tech/articles/hopping-into-spring-with-chainguard-s-rabbitmq-image-13082.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/hopping-into-spring-with-chainguards-rabbitmq-image>)

Published: 2023-02-24T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Messaging](<https://devfeed.tech/topics/messaging.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [Erlang](<https://devfeed.tech/topics/erlang.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [base-images](<https://devfeed.tech/tags/base-images.md>), [bazel](<https://devfeed.tech/tags/bazel.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cosign](<https://devfeed.tech/tags/cosign.md>), [cves](<https://devfeed.tech/tags/cves.md>), [documentation](<https://devfeed.tech/tags/documentation.md>), [image](<https://devfeed.tech/tags/image.md>), [messaging](<https://devfeed.tech/tags/messaging.md>), [minimal-image](<https://devfeed.tech/tags/minimal-image.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [rabbitmq](<https://devfeed.tech/tags/rabbitmq.md>), [rabbitmq-image](<https://devfeed.tech/tags/rabbitmq-image.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-images](<https://devfeed.tech/tags/secure-images.md>), [security](<https://devfeed.tech/tags/security.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>)

### AI overview

Chainguard announces a Chainguard Image for RabbitMQ, an open-source message broker used in cloud-native applications. The image is built from source on Wolfi, with custom Erlang and OTP components, continuous patching, minimal CVEs, SBOMs, signatures, and SLSA Build Level 2 provenance.

### Source excerpt

Unlock advanced messaging capabilities with Chainguard's RabbitMQ image, designed for robustness and security.

## Chainguard Image now available for Kubectl

DevFeed: [Chainguard Image now available for Kubectl](<https://devfeed.tech/articles/chainguard-image-now-available-for-kubectl-12947.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-image-now-available-for-kubectl>)

Published: 2023-02-07T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [ci](<https://devfeed.tech/topics/ci.md>), [GitOps](<https://devfeed.tech/topics/gitops.md>)

Tags: [base-images](<https://devfeed.tech/tags/base-images.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [ci](<https://devfeed.tech/tags/ci.md>), [containers](<https://devfeed.tech/tags/containers.md>), [gitops](<https://devfeed.tech/tags/gitops.md>), [kubectl](<https://devfeed.tech/tags/kubectl.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

Chainguard announces a kubectl image in the Chainguard Images catalog. The image supports multiple architectures, including arm64, is 75% smaller than a commonly used alternative, includes SBOMs, and is signed with Sigstore. Chainguard reports zero known CVEs at publication time.

### Source excerpt

Kubectl added to Chainguard Images catalog. Chainguard kubectl build is 75% smaller than the usual image used & is the only supported image with arm64 support.

## Docker Base Images at Scale: A Devoxx 2022 Conference Talk

DevFeed: [Docker Base Images at Scale: A Devoxx 2022 Conference Talk](<https://devfeed.tech/articles/back-on-the-big-stage-27674.md>)

Original publisher: [Read original article](<https://gagor.pro/2022/06/back-on-the-big-stage/>)

Author: Tom

Published: 2022-06-13T00:00:00Z

Content type: article

Language: en

Sources: [Tomasz Gągor](<https://devfeed.tech/sources/tomasz-gagor.md>)

Topics: [Docker](<https://devfeed.tech/topics/docker.md>)

Tags: [base-images](<https://devfeed.tech/tags/base-images.md>), [conference](<https://devfeed.tech/tags/conference.md>), [conference-presentation](<https://devfeed.tech/tags/conference-presentation.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devops-conference](<https://devfeed.tech/tags/devops-conference.md>), [devoxx-2022](<https://devfeed.tech/tags/devoxx-2022.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-base-images](<https://devfeed.tech/tags/docker-base-images.md>), [docker-talk](<https://devfeed.tech/tags/docker-talk.md>), [github](<https://devfeed.tech/tags/github.md>), [linux](<https://devfeed.tech/tags/linux.md>), [managing-docker-images](<https://devfeed.tech/tags/managing-docker-images.md>)

### AI overview

The author announces a talk about managing Docker base images at scale at Devoxx 2022 in Kraków, taking place from June 22-24, 2022. The author also says that presentation slides were uploaded to GitHub and that a video is available.

### Source excerpt

Announcing my return to the big stage with a talk on managing Docker base images at scale, presented at the Devoxx 2022 conference in Kraków.

## Deploying to production in \<5m with our hosted container builder

DevFeed: [Deploying to production in \<5m with our hosted container builder](<https://devfeed.tech/articles/deploying-to-production-in-5m-with-our-hosted-container-builder-11729.md>)

Original publisher: [Read original article](<https://incident.io/blog/container-builder>)

Author: Lawrence Jones

Published: 2021-11-18T00:00:00Z

Content type: article

Language: en

Sources: [The incident.io Blog](<https://devfeed.tech/sources/the-incident-io-blog.md>)

Topics: [build times](<https://devfeed.tech/topics/build-times.md>), [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [Docker Image](<https://devfeed.tech/topics/docker-image.md>), [Caching](<https://devfeed.tech/topics/caching.md>), [Heroku](<https://devfeed.tech/topics/heroku.md>)

Tags: [base-images](<https://devfeed.tech/tags/base-images.md>), [build-times](<https://devfeed.tech/tags/build-times.md>), [building](<https://devfeed.tech/tags/building.md>), [caching](<https://devfeed.tech/tags/caching.md>), [developer](<https://devfeed.tech/tags/developer.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-image](<https://devfeed.tech/tags/docker-image.md>), [incident](<https://devfeed.tech/tags/incident.md>), [incident-channel](<https://devfeed.tech/tags/incident-channel.md>), [incident-management](<https://devfeed.tech/tags/incident-management.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [outage](<https://devfeed.tech/tags/outage.md>), [post-mortem](<https://devfeed.tech/tags/post-mortem.md>), [production](<https://devfeed.tech/tags/production.md>), [reduce](<https://devfeed.tech/tags/reduce.md>), [registry](<https://devfeed.tech/tags/registry.md>), [slack-incident](<https://devfeed.tech/tags/slack-incident.md>), [speed](<https://devfeed.tech/tags/speed.md>), [time](<https://devfeed.tech/tags/time.md>)

### AI overview

The article explains how incident.io reduced Docker build times from inconsistent peaks of about 10 minutes to roughly 3 minutes, helping deployments reach production faster. It describes their Heroku and CircleCI deployment setup and explains how Docker layer caching, checksums, and pinned base images can avoid repeating work.

### Source excerpt

Fast build times have a number of benefits, from reliability to developer happiness. We reduces our time to deploy to <5, and it's glorious.

## Official CentOS 8 Stream Docker Image Is Available on quay.io

DevFeed: [Official CentOS 8 Stream Docker Image Is Available on quay.io](<https://devfeed.tech/articles/official-centos-8-stream-docker-image-finally-available-27665.md>)

Original publisher: [Read original article](<https://gagor.pro/2021/07/official-centos-8-stream-docker-image-finally-available/>)

Author: Tom

Published: 2021-07-25T00:00:00Z

Content type: opinion

Language: en

Sources: [Tomasz Gągor](<https://devfeed.tech/sources/tomasz-gagor.md>)

Topics: [Docker Image](<https://devfeed.tech/topics/docker-image.md>), [centos](<https://devfeed.tech/topics/centos.md>), [Docker](<https://devfeed.tech/topics/docker.md>)

Tags: [base-images](<https://devfeed.tech/tags/base-images.md>), [centos](<https://devfeed.tech/tags/centos.md>), [centos-8-stream-docker-image](<https://devfeed.tech/tags/centos-8-stream-docker-image.md>), [centos-docker-image-updates](<https://devfeed.tech/tags/centos-docker-image-updates.md>), [centos-stream](<https://devfeed.tech/tags/centos-stream.md>), [centos-stream-9](<https://devfeed.tech/tags/centos-stream-9.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-hub](<https://devfeed.tech/tags/docker-hub.md>), [docker-hub-to-quay-io-transition](<https://devfeed.tech/tags/docker-hub-to-quay-io-transition.md>), [docker-image](<https://devfeed.tech/tags/docker-image.md>), [docker-image-management](<https://devfeed.tech/tags/docker-image-management.md>), [end-of-life](<https://devfeed.tech/tags/end-of-life.md>), [eol](<https://devfeed.tech/tags/eol.md>), [official-docker-images](<https://devfeed.tech/tags/official-docker-images.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>)

### AI overview

The article discusses the availability of an official CentOS 8 Stream Docker image on quay.io after its transition from Docker Hub. It also notes the lack of updates for older images and recommends considering CentOS Stream 9 as CentOS Stream 8 approaches archival.

### Source excerpt

Discover the availability of the official CentOS 8 Stream Docker image on quay.io, and learn about the transition from Docker Hub and its implications.

## How old are Official Docker images?

DevFeed: [How old are Official Docker images?](<https://devfeed.tech/articles/how-old-are-official-docker-images-27660.md>)

Original publisher: [Read original article](<https://gagor.pro/2021/01/how-old-are-official-docker-images/>)

Author: Tom

Published: 2021-01-28T00:00:00Z

Content type: article

Language: en

Sources: [Tomasz Gągor](<https://devfeed.tech/sources/tomasz-gagor.md>)

Topics: [docker images](<https://devfeed.tech/topics/docker-images.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [Security](<https://devfeed.tech/topics/security.md>), [DevOps](<https://devfeed.tech/topics/devops.md>)

Tags: [base-image-maintenance](<https://devfeed.tech/tags/base-image-maintenance.md>), [base-images](<https://devfeed.tech/tags/base-images.md>), [devops](<https://devfeed.tech/tags/devops.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-image-age](<https://devfeed.tech/tags/docker-image-age.md>), [docker-image-updates](<https://devfeed.tech/tags/docker-image-updates.md>), [docker-performance](<https://devfeed.tech/tags/docker-performance.md>), [docker-security](<https://devfeed.tech/tags/docker-security.md>), [images](<https://devfeed.tech/tags/images.md>), [official-docker-images](<https://devfeed.tech/tags/official-docker-images.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article examines how old various official Docker images are and how frequently they are updated. It highlights the security risks of using stale CentOS base images and discusses the tradeoff that package upgrades can make images larger.

### Source excerpt

Discover the age and update frequency of various official Docker images, and learn why it's important to keep your base images up to date for security and performance.

## Vapor: Docker Based Deployments

DevFeed: [Vapor: Docker Based Deployments](<https://devfeed.tech/articles/vapor-docker-based-deployments-3948.md>)

Original publisher: [Read original article](<https://laravel.com/blog/vapor-docker-based-deployments>)

Author: Mohamed Said

Published: 2020-12-16T10:27:00Z

Content type: article

Language: en

Sources: [Laravel Blog](<https://devfeed.tech/sources/laravel-blog.md>)

Topics: [Laravel](<https://devfeed.tech/topics/laravel.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [AWS Lambda](<https://devfeed.tech/topics/aws-lambda.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [Docker Image](<https://devfeed.tech/topics/docker-image.md>), [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [PHP](<https://devfeed.tech/topics/php.md>), [Composer](<https://devfeed.tech/topics/composer.md>), [Linux](<https://devfeed.tech/topics/linux.md>)

Tags: [alpine](<https://devfeed.tech/tags/alpine.md>), [applications](<https://devfeed.tech/tags/applications.md>), [aws-lambda](<https://devfeed.tech/tags/aws-lambda.md>), [base-images](<https://devfeed.tech/tags/base-images.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [docker](<https://devfeed.tech/tags/docker.md>), [ffmpeg](<https://devfeed.tech/tags/ffmpeg.md>), [library](<https://devfeed.tech/tags/library.md>), [php](<https://devfeed.tech/tags/php.md>)

### AI overview

Laravel Vapor introduces Docker-based deployments for AWS Lambda, allowing applications up to 10 GB and supporting additional PHP extensions and libraries. The article explains how to configure Vapor environments, customize Dockerfiles based on Alpine Linux images, and deploy the resulting Docker image.

### Source excerpt

One of the limitations of AWS Lambda is that the deployment size, including layers, must not exceed 250 MB. This is not ideal for large projects that have many composer dependencies. In addition, many...

## Docker Images : Part III - Going Farther To Reduce Image Size

DevFeed: [Docker Images : Part III - Going Farther To Reduce Image Size](<https://devfeed.tech/articles/docker-images-part-iii-going-farther-to-reduce-image-size-22159.md>)

Original publisher: [Read original article](<https://www.ardanlabs.com/blog/2020/04/docker-images-part3-going-farther-reduce-image-size.html>)

Published: 2020-04-03T00:00:00Z

Content type: tutorial

Language: en

Sources: [William Kennedy](<https://devfeed.tech/sources/william-kennedy.md>)

Topics: [Docker](<https://devfeed.tech/topics/docker.md>), [Docker Image](<https://devfeed.tech/topics/docker-image.md>), [Optimization](<https://devfeed.tech/topics/optimization.md>), [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [systems](<https://devfeed.tech/topics/systems.md>)

Tags: [ardan-labs](<https://devfeed.tech/tags/ardan-labs.md>), [base-images](<https://devfeed.tech/tags/base-images.md>), [bazel](<https://devfeed.tech/tags/bazel.md>), [blog](<https://devfeed.tech/tags/blog.md>), [build](<https://devfeed.tech/tags/build.md>), [building](<https://devfeed.tech/tags/building.md>), [cache](<https://devfeed.tech/tags/cache.md>), [containers](<https://devfeed.tech/tags/containers.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-image](<https://devfeed.tech/tags/docker-image.md>), [docker-images](<https://devfeed.tech/tags/docker-images.md>), [drivers](<https://devfeed.tech/tags/drivers.md>), [files](<https://devfeed.tech/tags/files.md>), [go](<https://devfeed.tech/tags/go.md>), [go-programming](<https://devfeed.tech/tags/go-programming.md>), [golang](<https://devfeed.tech/tags/golang.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [image](<https://devfeed.tech/tags/image.md>), [images](<https://devfeed.tech/tags/images.md>), [memory](<https://devfeed.tech/tags/memory.md>), [network](<https://devfeed.tech/tags/network.md>), [optimization](<https://devfeed.tech/tags/optimization.md>), [programming](<https://devfeed.tech/tags/programming.md>), [reduce](<https://devfeed.tech/tags/reduce.md>), [systems](<https://devfeed.tech/tags/systems.md>)

### AI overview

The third article in a series on reducing Docker image size explains further optimization techniques, including standardized base images, stripped binaries, asset optimization, and tools such as DockerSlim and Bazel. It also describes how shared image layers can reduce network, storage, disk I/O, and memory usage when running multiple containers.

### Source excerpt

Series Index Reducing Image Size Details Specific To Different Languages Going Farther To Reduce Image Size Introduction In the first two parts of this series, we covered the most common methods to optimize Docker image size. We saw how multi-stage builds, combined with Alpine-based images, and sometimes static builds, would generally give us the most dramatic savings. In this last part, we will see how to go even farther. We will talk about standardizing base images, stripping binaries, assets optimization, and other build systems or add-ons like DockerSlim or Bazel, as well as the NixOS distribution.

## Docker Images : Part I - Reducing Image Size

DevFeed: [Docker Images : Part I - Reducing Image Size](<https://devfeed.tech/articles/docker-images-part-i-reducing-image-size-22156.md>)

Original publisher: [Read original article](<https://www.ardanlabs.com/blog/2020/02/docker-images-part1-reducing-image-size.html>)

Published: 2020-02-04T00:00:00Z

Content type: tutorial

Language: en

Sources: [William Kennedy](<https://devfeed.tech/sources/william-kennedy.md>)

Topics: [docker images](<https://devfeed.tech/topics/docker-images.md>), [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [C](<https://devfeed.tech/topics/c.md>), [Go](<https://devfeed.tech/topics/go.md>), [Ubuntu](<https://devfeed.tech/topics/ubuntu.md>), [bazel](<https://devfeed.tech/topics/bazel.md>)

Tags: [ardan-labs](<https://devfeed.tech/tags/ardan-labs.md>), [base-images](<https://devfeed.tech/tags/base-images.md>), [bazel](<https://devfeed.tech/tags/bazel.md>), [blog](<https://devfeed.tech/tags/blog.md>), [c](<https://devfeed.tech/tags/c.md>), [containers](<https://devfeed.tech/tags/containers.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-images](<https://devfeed.tech/tags/docker-images.md>), [go](<https://devfeed.tech/tags/go.md>), [go-programming](<https://devfeed.tech/tags/go-programming.md>), [golang](<https://devfeed.tech/tags/golang.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [programming](<https://devfeed.tech/tags/programming.md>), [rust](<https://devfeed.tech/tags/rust.md>), [ubuntu](<https://devfeed.tech/tags/ubuntu.md>)

### AI overview

This tutorial explains techniques for reducing Docker image size, beginning with multi-stage builds and covering static versus dynamic linking and Alpine. It uses C and Go examples and introduces additional approaches such as common base images, stripping binaries, Bazel, Distroless, DockerSlim, and UPX, while noting that extreme reductions are not always appropriate.

### Source excerpt

Series Index Reducing Image Size Details Specific To Different Languages Going Farther To Reduce Image Size Introduction When getting started with containers, it's pretty easy to be shocked by the size of the images that we build. We're going to review a number of techniques to reduce image size, without sacrificing developers' and ops' convenience. In this first part, we will talk about multi-stage builds, because that's where anyone should start if they want to reduce the size of their images. We will also explain the differences between static and dynamic linking, as well as why we should care about that. This will be the occasion to introduce Alpine.