# chainguard images

Published articles for chainguard images.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Introducing the Chainguard cinc-auditor image: STIG scanning for Chainguard Containers, ready to run

DevFeed: [Introducing the Chainguard cinc-auditor image: STIG scanning for Chainguard Containers, ready to run](<https://devfeed.tech/articles/introducing-the-chainguard-cinc-auditor-image-stig-scanning-for-chainguard-containers-ready-to-run-13123.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-the-chainguard-cinc-auditor-image-stig-scanning-for-chainguard-containers-ready-to-run>)

Published: 2026-06-18T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [anchore](<https://devfeed.tech/topics/anchore.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [anchore](<https://devfeed.tech/tags/anchore.md>), [anchore-enterprise](<https://devfeed.tech/tags/anchore-enterprise.md>), [apache](<https://devfeed.tech/tags/apache.md>), [built-from-source](<https://devfeed.tech/tags/built-from-source.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cinc-auditor](<https://devfeed.tech/tags/cinc-auditor.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [pipeline](<https://devfeed.tech/tags/pipeline.md>), [scanner](<https://devfeed.tech/tags/scanner.md>), [stig](<https://devfeed.tech/tags/stig.md>), [stigs](<https://devfeed.tech/tags/stigs.md>)

### AI overview

Chainguard introduces a ready-to-run cinc-auditor container image for STIG scanning of Chainguard Containers. The image includes a maintained GPOS SRG InSpec profile, removes separate profile and dependency setup, and supports production compliance pipelines, including FedRAMP workflows.

### Source excerpt

Chainguard launches a ready-to-run STIG scanner with a built-in GPOS SRG InSpec profile, simplifying compliance scans for containers and FedRAMP workflows.

## Going beyond CVEs: Chainguard's one day KEV SLA

DevFeed: [Going beyond CVEs: Chainguard's one day KEV SLA](<https://devfeed.tech/articles/going-beyond-cves-chainguard-s-one-day-kev-sla-13068.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/going-beyond-cves-chainguards-one-day-kev-sla>)

Published: 2026-04-28T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Security](<https://devfeed.tech/topics/security.md>), [cisa](<https://devfeed.tech/topics/cisa.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-cves](<https://devfeed.tech/tags/chainguard-cves.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-kevs](<https://devfeed.tech/tags/chainguard-kevs.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cves](<https://devfeed.tech/tags/cves.md>), [exploited-vulnerabilities](<https://devfeed.tech/tags/exploited-vulnerabilities.md>), [kevs](<https://devfeed.tech/tags/kevs.md>), [known-exploitable-vulnerabilities](<https://devfeed.tech/tags/known-exploitable-vulnerabilities.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Chainguard announces a one-calendar-day SLA for remediating CVEs added to the CISA Known Exploited Vulnerabilities Catalog when they affect Chainguard container images. The article explains the SLA's relationship to exploited-vulnerability prioritization and Chainguard's continuous remediation processes.

### Source excerpt

Chainguard introduces a 1-day KEV SLA, ensuring exploited vulnerabilities are fixed fast--aligned with how security teams prioritize real-world threats.

## Managing third-party images at scale

DevFeed: [Managing third-party images at scale](<https://devfeed.tech/articles/managing-third-party-images-at-scale-13147.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/managing-third-party-images-at-scale>)

Published: 2026-04-16T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [container images](<https://devfeed.tech/topics/container-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [code productivity](<https://devfeed.tech/topics/code-productivity.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [appian](<https://devfeed.tech/tags/appian.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [developer-velocity](<https://devfeed.tech/tags/developer-velocity.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [scale](<https://devfeed.tech/tags/scale.md>), [security](<https://devfeed.tech/tags/security.md>), [third-party-container-images](<https://devfeed.tech/tags/third-party-container-images.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article explains how Appian approached managing third-party container images at scale with Chainguard. It describes the operational burden caused by image dependencies, vulnerabilities, maintenance, and compliance requirements, including the ongoing work needed for regulated environments such as FedRAMP. It also estimates that building a complete internal hardened-image program would require a dedicated team of 15 to 20 engineers.

### Source excerpt

Learn how companies can scale third-party container image management with Chainguard to reduce risk, cut toil, and accelerate compliance and developer velocity.

## Introducing the Activity Center: One place for every change that matters

DevFeed: [Introducing the Activity Center: One place for every change that matters](<https://devfeed.tech/articles/introducing-the-activity-center-one-place-for-every-change-that-matters-13122.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-the-activity-center>)

Published: 2026-03-25T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>)

Tags: [chainguard-activity-center](<https://devfeed.tech/tags/chainguard-activity-center.md>), [chainguard-catalog](<https://devfeed.tech/tags/chainguard-catalog.md>), [chainguard-console](<https://devfeed.tech/tags/chainguard-console.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-cve-alerts](<https://devfeed.tech/tags/chainguard-cve-alerts.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [notifications](<https://devfeed.tech/tags/notifications.md>), [product-updates](<https://devfeed.tech/tags/product-updates.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Chainguard introduces the Activity Center, a centralized and configurable notification feed in the Chainguard Console. It helps teams track breaking changes, incidents, image lifecycle events, CVE advisories, product updates, and entitlement changes, with additional filtering and notification-history features planned.

### Source excerpt

Chainguard's Activity Center centralizes alerts for CVEs, breaking changes, and updates -- delivering real-time notifications where your teams already work.

## FIPS-ing the Un-FIPS-able: Apache Kafka

DevFeed: [FIPS-ing the Un-FIPS-able: Apache Kafka](<https://devfeed.tech/articles/fips-ing-the-un-fips-able-apache-kafka-13044.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/fips-ing-the-un-fips-able-apache-kafka>)

Published: 2026-03-05T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Apache-Kafka](<https://devfeed.tech/topics/apache-kafka.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [Security](<https://devfeed.tech/topics/security.md>), [Event-Streaming](<https://devfeed.tech/topics/event-streaming.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [apache](<https://devfeed.tech/tags/apache.md>), [apache-kafka](<https://devfeed.tech/tags/apache-kafka.md>), [apache-kafka-fips](<https://devfeed.tech/tags/apache-kafka-fips.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-kafka-container](<https://devfeed.tech/tags/chainguard-kafka-container.md>), [chainguard-kafka-image](<https://devfeed.tech/tags/chainguard-kafka-image.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [event-streaming](<https://devfeed.tech/tags/event-streaming.md>), [fips](<https://devfeed.tech/tags/fips.md>), [fips-140-3](<https://devfeed.tech/tags/fips-140-3.md>), [fips-containers](<https://devfeed.tech/tags/fips-containers.md>), [kafka](<https://devfeed.tech/tags/kafka.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [tls](<https://devfeed.tech/tags/tls.md>)

### AI overview

Chainguard announces FIPS-validated images for Apache Kafka, describing targeted source changes, validated cryptographic providers, TLS and keystore requirements, testing, and image maintenance for regulated environments.

### Source excerpt

Chainguard delivers the FIPS-validated Apache Kafka images, enabling secure event streaming for FedRAMP and regulated environments.

## How Chainguard Automated Detection and Patching of a High-Severity CVE

DevFeed: [How Chainguard Automated Detection and Patching of a High-Severity CVE](<https://devfeed.tech/articles/this-shit-is-hard-the-life-and-death-of-a-cve-in-the-chainguard-factory-13291.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/this-shit-is-hard-the-life-and-death-of-a-cve-in-the-chainguard-factory>)

Published: 2026-02-13T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [anchore](<https://devfeed.tech/topics/anchore.md>), [grype](<https://devfeed.tech/topics/grype.md>), [ci](<https://devfeed.tech/topics/ci.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [anchore](<https://devfeed.tech/tags/anchore.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-cve-remediation](<https://devfeed.tech/tags/chainguard-cve-remediation.md>), [chainguard-factory](<https://devfeed.tech/tags/chainguard-factory.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [ci](<https://devfeed.tech/tags/ci.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [github](<https://devfeed.tech/tags/github.md>), [grype](<https://devfeed.tech/tags/grype.md>), [pull-request](<https://devfeed.tech/tags/pull-request.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

The article describes how Chainguard's Factory detected a high-severity vulnerability affecting k9s, updated Grype, opened and merged a pull request, and published a fixed package within 46 hours of the advisory. It also reports that Chainguard remediated 2,960 unique CVEs in November 2025 while meeting its stated remediation SLA.

### Source excerpt

The Chainguard Factory and DriftlessAF automate CVE detection and patching, delivering fixes in hours and maintaining industry-leading remediation SLAs.

## Introducing Fulfillment Dashboard: New artifact requests are now self-serve

DevFeed: [Introducing Fulfillment Dashboard: New artifact requests are now self-serve](<https://devfeed.tech/articles/introducing-fulfillment-dashboard-new-artifact-requests-are-now-self-serve-13116.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-fulfillment-dashboard-new-artifact-requests-are-now-self-serve>)

Published: 2026-02-12T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [dashboards](<https://devfeed.tech/topics/dashboards.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-factory](<https://devfeed.tech/tags/chainguard-factory.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [console](<https://devfeed.tech/tags/console.md>), [customers](<https://devfeed.tech/tags/customers.md>), [fulfillment-dashboard](<https://devfeed.tech/tags/fulfillment-dashboard.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [scale](<https://devfeed.tech/tags/scale.md>), [search](<https://devfeed.tech/tags/search.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [self-service](<https://devfeed.tech/tags/self-service.md>), [self-service-container-images](<https://devfeed.tech/tags/self-service-container-images.md>), [visibility](<https://devfeed.tech/tags/visibility.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

Chainguard introduces Fulfillment Dashboard, a self-service console for submitting, tracking, searching, and voting on secure container image requests. It provides lifecycle visibility, target delivery dates, deduplication, and community upvoting to help prioritize fulfillment.

### Source excerpt

Fulfillment Dashboard gives Chainguard customers real-time visibility, tracking, and community voting for new secure container image requests.

## Be my base image: Introducing Linky's Matchmaker

DevFeed: [Be my base image: Introducing Linky's Matchmaker](<https://devfeed.tech/articles/be-my-base-image-introducing-linky-s-matchmaker-12896.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/be-my-base-image-introducing-linkys-matchmaker>)

Published: 2026-02-12T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [App](<https://devfeed.tech/topics/app.md>), [Web](<https://devfeed.tech/topics/web.md>)

Tags: [base-images](<https://devfeed.tech/tags/base-images.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-valentine-s-day](<https://devfeed.tech/tags/chainguard-valentine-s-day.md>), [comparisons](<https://devfeed.tech/tags/comparisons.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [dockerfile-converter](<https://devfeed.tech/tags/dockerfile-converter.md>), [dockerfiles](<https://devfeed.tech/tags/dockerfiles.md>), [documentation](<https://devfeed.tech/tags/documentation.md>), [images](<https://devfeed.tech/tags/images.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Linky's Matchmaker is a web-based app that analyzes Dockerfiles, recommends compatible Chainguard Containers, and generates downloadable converted Dockerfiles. It also provides image availability checks, documentation and tag links, and vulnerability comparisons.

### Source excerpt

Linky's Matchmaker converts your Dockerfile to Chainguard Containers, recommending secure, minimal base images and generating an updated file in minutes

## DriftlessAF: Introducing Chainguard Factory 2.0

DevFeed: [DriftlessAF: Introducing Chainguard Factory 2.0](<https://devfeed.tech/articles/driftlessaf-introducing-chainguard-factory-2-0-13025.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/driftlessaf-introducing-chainguard-factory-2-0>)

Published: 2026-01-29T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [Bot](<https://devfeed.tech/topics/bot.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [event driven](<https://devfeed.tech/topics/event-driven.md>), [legacy](<https://devfeed.tech/topics/legacy.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [automation](<https://devfeed.tech/tags/automation.md>), [bots](<https://devfeed.tech/tags/bots.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-factory](<https://devfeed.tech/tags/chainguard-factory.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [cve](<https://devfeed.tech/tags/cve.md>), [driftlessaf](<https://devfeed.tech/tags/driftlessaf.md>), [event-driven](<https://devfeed.tech/tags/event-driven.md>), [legacy](<https://devfeed.tech/tags/legacy.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [reconciliation](<https://devfeed.tech/tags/reconciliation.md>), [safe-source-for-open-source](<https://devfeed.tech/tags/safe-source-for-open-source.md>), [self-healing](<https://devfeed.tech/tags/self-healing.md>)

### AI overview

Chainguard announces Chainguard Factory 2.0, powered by the DriftlessAF agentic framework. The system uses AI-driven, self-healing reconciliation to build and maintain more than 2,000 zero-CVE images, and DriftlessAF is being open-sourced.

### Source excerpt

Chainguard Factory 2.0, powered by DriftlessAF, brings AI-driven, self-healing reconciliation to build and maintain 2,000+ zero-CVE images -- now open sourced.

## Running Renovate as a GitHub Action (and NO PAT!)

DevFeed: [Running Renovate as a GitHub Action (and NO PAT!)](<https://devfeed.tech/articles/running-renovate-as-a-github-action-and-no-pat-13214.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/running-renovate-as-a-github-action>)

Published: 2026-01-19T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [renovate](<https://devfeed.tech/topics/renovate.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [octo sts](<https://devfeed.tech/topics/octo-sts.md>), [github personal access token](<https://devfeed.tech/topics/github-personal-access-token.md>), [Security](<https://devfeed.tech/topics/security.md>), [maintenance](<https://devfeed.tech/topics/maintenance.md>)

Tags: [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [dependabot](<https://devfeed.tech/tags/dependabot.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [github](<https://devfeed.tech/tags/github.md>), [github-action](<https://devfeed.tech/tags/github-action.md>), [github-pat-alternative](<https://devfeed.tech/tags/github-pat-alternative.md>), [guide](<https://devfeed.tech/tags/guide.md>), [maintenance](<https://devfeed.tech/tags/maintenance.md>), [octo-sts](<https://devfeed.tech/tags/octo-sts.md>), [personal-access-token](<https://devfeed.tech/tags/personal-access-token.md>), [renovate](<https://devfeed.tech/tags/renovate.md>), [run](<https://devfeed.tech/tags/run.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>)

### AI overview

This tutorial explains how to run Renovate as a scheduled GitHub Action to update repository dependencies without using a long-lived GitHub Personal Access Token. It presents Octo STS as the replacement for the PAT and outlines the workflow setup.

### Source excerpt

Discover how you can run Renovate as a GitHub Action without needing a GitHub Personal Access Token by using Octo STS.

## Fork yeah: We're adding ten new open source projects to EmeritOSS

DevFeed: [Fork yeah: We're adding ten new open source projects to EmeritOSS](<https://devfeed.tech/articles/fork-yeah-we-re-adding-ten-new-open-source-projects-to-emeritoss-13049.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/fork-yeah-were-adding-ten-new-open-source-projects-to-emeritoss>)

Published: 2026-01-15T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Open Source](<https://devfeed.tech/topics/open-source.md>), [Prometheus](<https://devfeed.tech/topics/prometheus.md>), [Apache Cassandra](<https://devfeed.tech/topics/cassandra.md>), [Amazon S3](<https://devfeed.tech/topics/amazon-s3.md>), [observability](<https://devfeed.tech/topics/observability.md>), [Grafana](<https://devfeed.tech/topics/grafana.md>), [data-processing](<https://devfeed.tech/topics/data-processing.md>)

Tags: [amazon-s3](<https://devfeed.tech/tags/amazon-s3.md>), [cassandra](<https://devfeed.tech/tags/cassandra.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-emeritoss](<https://devfeed.tech/tags/chainguard-emeritoss.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-open-source](<https://devfeed.tech/tags/chainguard-open-source.md>), [dashboards](<https://devfeed.tech/tags/dashboards.md>), [maintenance](<https://devfeed.tech/tags/maintenance.md>), [minio](<https://devfeed.tech/tags/minio.md>), [observability](<https://devfeed.tech/tags/observability.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-chainguard-images](<https://devfeed.tech/tags/open-source-chainguard-images.md>), [pgcat](<https://devfeed.tech/tags/pgcat.md>), [prometheus](<https://devfeed.tech/tags/prometheus.md>), [security](<https://devfeed.tech/tags/security.md>), [source](<https://devfeed.tech/tags/source.md>)

### AI overview

Chainguard announces ten additional open source projects joining EmeritOSS, a program intended to provide long-term maintenance and stability for mature projects. The supplied text highlights MinIO, Prometheus-related exporters, and integrations involving Apache Cassandra and RabbitMQ, covering object storage, monitoring, metrics, and observability.

### Source excerpt

We added 10 open source projects to EmeritOSS--including MinIO, Prometheus exporters, and PgCat--to provide long-term, stability-focused maintenance and security.

## Why Trusted Software Supply Chains Matter More Than Zero-CVE Container Claims

DevFeed: [Why Trusted Software Supply Chains Matter More Than Zero-CVE Container Claims](<https://devfeed.tech/articles/well-that-escalated-quickly-zero-cves-lots-of-vendors-13314.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/well-that-escalated-quickly-zero-cves-lots-of-vendors>)

Published: 2026-01-15T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Docker Hub](<https://devfeed.tech/topics/docker-hub.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [ceo](<https://devfeed.tech/tags/ceo.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-hub](<https://devfeed.tech/tags/docker-hub.md>), [docker-images](<https://devfeed.tech/tags/docker-images.md>), [echo-security](<https://devfeed.tech/tags/echo-security.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [minimus](<https://devfeed.tech/tags/minimus.md>), [rapidfort](<https://devfeed.tech/tags/rapidfort.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [wiz-images](<https://devfeed.tech/tags/wiz-images.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

Chainguard CEO Dan Lorenc argues that container security depends on trusting the origins and build processes of software, rather than relying primarily on post-hoc image hardening or zero-CVE claims.

### Source excerpt

Chainguard CEO Dan Lorenc explains why real security comes from trusted, from-source software supply chains, not post-hoc hardening or zero-CVE promises.

## Custom Certificates are now available in Custom Assembly

DevFeed: [Custom Certificates are now available in Custom Assembly](<https://devfeed.tech/articles/custom-certificates-are-now-available-in-custom-assembly-13016.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/custom-certificates-are-now-available-in-custom-assembly>)

Published: 2025-12-19T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Security](<https://devfeed.tech/topics/security.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [YAML](<https://devfeed.tech/topics/yaml.md>), [Containers](<https://devfeed.tech/topics/containers.md>)

Tags: [certificates](<https://devfeed.tech/tags/certificates.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-custom-assembly](<https://devfeed.tech/tags/chainguard-custom-assembly.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [custom-assembly](<https://devfeed.tech/tags/custom-assembly.md>), [custom-container-images](<https://devfeed.tech/tags/custom-container-images.md>), [enterprise-certificate-authority-certificates](<https://devfeed.tech/tags/enterprise-certificate-authority-certificates.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [security](<https://devfeed.tech/tags/security.md>), [yaml](<https://devfeed.tech/tags/yaml.md>)

### AI overview

Chainguard announces custom certificate support for Custom Assembly, allowing enterprise certificate authority certificates to be added directly to Chainguard Containers through image configuration. The certificates are validated, stored with the image configuration, appended to standard trust stores at build time, and included in image provenance.

### Source excerpt

Custom Certificate support for Custom Assembly allows you to add your enterprise certificate authority certificates directly to Chainguard Containers

## The State of Trusted Open Source: December 2025

DevFeed: [The State of Trusted Open Source: December 2025](<https://devfeed.tech/articles/the-state-of-trusted-open-source-december-2025-13270.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-state-of-trusted-open-source-december-2025>)

Published: 2025-12-18T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Open Source](<https://devfeed.tech/topics/open-source.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [ai](<https://devfeed.tech/tags/ai.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-cves](<https://devfeed.tech/tags/chainguard-cves.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-report](<https://devfeed.tech/tags/chainguard-report.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cve-data](<https://devfeed.tech/tags/cve-data.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [report](<https://devfeed.tech/tags/report.md>), [security](<https://devfeed.tech/tags/security.md>), [state-of-trusted-open-source](<https://devfeed.tech/tags/state-of-trusted-open-source.md>), [trends](<https://devfeed.tech/tags/trends.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard's December 2025 State of Trusted Open Source report examines open source usage, CVE data, vulnerability remediation, and compliance trends across its customer base and container image catalog. It highlights Python's role in AI workloads, the prevalence of longtail images in production, the concentration of remediated vulnerabilities outside the top 20 projects, FIPS image usage, and remediation of Critical CVEs in under 20 hours on average.

### Source excerpt

Chainguard's State of Trusted Open Source for December 2025 dives into usage trends for Chainguard Containers, CVE data, and why remediation speed matters.

## It's time to rethink golden images. Chainguard can help.

DevFeed: [It's time to rethink golden images. Chainguard can help.](<https://devfeed.tech/articles/it-s-time-to-rethink-golden-images-chainguard-can-help-13130.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/its-time-to-rethink-golden-images-chainguard-can-help>)

Published: 2025-11-17T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [DevOps](<https://devfeed.tech/topics/devops.md>), [Tech Debt](<https://devfeed.tech/topics/tech-debt.md>)

Tags: [base-images](<https://devfeed.tech/tags/base-images.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-golden-images](<https://devfeed.tech/tags/chainguard-golden-images.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [development](<https://devfeed.tech/tags/development.md>), [devops](<https://devfeed.tech/tags/devops.md>), [golden-container-images](<https://devfeed.tech/tags/golden-container-images.md>), [golden-images](<https://devfeed.tech/tags/golden-images.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

Chainguard advocates developer-centric golden image programs built on secure, trusted, purpose-built container base images. The approach aims to balance governance and standardization with developer flexibility, improving delivery speed while reducing maintenance costs, vulnerabilities, and compliance concerns.

### Source excerpt

Chainguard helps teams build developer-centric golden image programs with zero-CVE, purpose-built containers--balancing speed, security, and standardization.

## Introducing New Updates to the Chainguard Images Directory

DevFeed: [Introducing New Updates to the Chainguard Images Directory](<https://devfeed.tech/articles/introducing-new-updates-to-the-chainguard-images-directory-13118.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-new-updates-to-the-chainguard-images-directory>)

Published: 2025-11-12T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [bitnami-helm-charts](<https://devfeed.tech/tags/bitnami-helm-charts.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-catalog](<https://devfeed.tech/tags/chainguard-catalog.md>), [chainguard-console](<https://devfeed.tech/tags/chainguard-console.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-helm-charts](<https://devfeed.tech/tags/chainguard-helm-charts.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-images-directory](<https://devfeed.tech/tags/chainguard-images-directory.md>), [compare](<https://devfeed.tech/tags/compare.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cost](<https://devfeed.tech/tags/cost.md>), [cve](<https://devfeed.tech/tags/cve.md>), [demo](<https://devfeed.tech/tags/demo.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [helm](<https://devfeed.tech/tags/helm.md>), [helm-charts](<https://devfeed.tech/tags/helm-charts.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [oci](<https://devfeed.tech/tags/oci.md>), [registry](<https://devfeed.tech/tags/registry.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [updates](<https://devfeed.tech/tags/updates.md>), [zero-cve-containers](<https://devfeed.tech/tags/zero-cve-containers.md>)

### AI overview

Chainguard has updated its Images Directory with an embedded ROI calculator, Helm Charts for Kubernetes deployments, and refreshed data about the Chainguard Factory. The calculator compares CVE counts and remediation costs, while the Helm Charts provide drop-in replacements for popular open source applications using Chainguard Containers and OCI delivery.

### Source excerpt

We've improved the Chainguard Images Directory with Helm charts for faster deployments, an ROI calculator, and more refreshed data to improve your experience.

## Accelerating Platform Adoption with Developer Trust

DevFeed: [Accelerating Platform Adoption with Developer Trust](<https://devfeed.tech/articles/accelerating-platform-adoption-with-developer-trust-12861.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/accelerating-platform-adoption-with-developer-trust>)

Published: 2025-11-06T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Developer Platform](<https://devfeed.tech/topics/developer-platform.md>), [code productivity](<https://devfeed.tech/topics/code-productivity.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [developer-productivity](<https://devfeed.tech/topics/developer-productivity.md>), [software-development](<https://devfeed.tech/topics/software-development.md>)

Tags: [chainguard-adoption-story](<https://devfeed.tech/tags/chainguard-adoption-story.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [container](<https://devfeed.tech/tags/container.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [developer](<https://devfeed.tech/tags/developer.md>), [golden-images](<https://devfeed.tech/tags/golden-images.md>), [governance](<https://devfeed.tech/tags/governance.md>), [internal-developer-platform](<https://devfeed.tech/tags/internal-developer-platform.md>), [platform](<https://devfeed.tech/tags/platform.md>), [site-reliability](<https://devfeed.tech/tags/site-reliability.md>), [velocity](<https://devfeed.tech/tags/velocity.md>)

### AI overview

The article argues that internal development platforms need developer trust to achieve adoption. Platform teams should provide secure, standardized, and customizable paved paths that support diverse developer needs, including different programming languages and versions. It highlights the limitations of one-size-fits-most golden container images and the importance of balancing flexibility, governance, productivity, engineering velocity, and operational reliability.

### Source excerpt

Chainguard helps Platform teams drive adoption with zero-CVE, customizable container images that make internal development platforms secure, fast, and trusted.

## Custom Assembly Updates: Create Multiple, Customized Variants of a Chainguard Container

DevFeed: [Custom Assembly Updates: Create Multiple, Customized Variants of a Chainguard Container](<https://devfeed.tech/articles/custom-assembly-updates-create-multiple-customized-variants-of-a-chainguard-container-13015.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/custom-assembly-updates-create-multiple-customized-variants-of-a-chainguard-container>)

Published: 2025-10-29T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard custom assembly](<https://devfeed.tech/topics/chainguard-custom-assembly.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [cve remediation](<https://devfeed.tech/topics/cve-remediation.md>)

Tags: [assembly](<https://devfeed.tech/tags/assembly.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-custom-assembly](<https://devfeed.tech/tags/chainguard-custom-assembly.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [custom-assembly](<https://devfeed.tech/tags/custom-assembly.md>), [custom-chainguard-containers](<https://devfeed.tech/tags/custom-chainguard-containers.md>), [custom-chainguard-images](<https://devfeed.tech/tags/custom-chainguard-images.md>), [customers](<https://devfeed.tech/tags/customers.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [new-feature](<https://devfeed.tech/tags/new-feature.md>)

### AI overview

Chainguard announces enhancements to Custom Assembly that let customers create, add, delete, rename, edit, preview, and manage multiple customized variants of Chainguard container images directly in the console. The update supports self-serve provisioning and includes build history, logs, and build status.

### Source excerpt

Customize Chainguard Containers with the latest Custom Assembly update. You can create, edit, and manage secure, zero-CVE image variants directly in the console.

## Three Ways to Make Your SDLC Secure-by-Default

DevFeed: [Three Ways to Make Your SDLC Secure-by-Default](<https://devfeed.tech/articles/three-ways-to-make-your-sdlc-secure-by-default-13293.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/three-ways-to-make-your-sdlc-secure-by-default>)

Published: 2025-10-20T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [sdlc](<https://devfeed.tech/topics/sdlc.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-security](<https://devfeed.tech/tags/chainguard-security.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [cves](<https://devfeed.tech/tags/cves.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [sdlc](<https://devfeed.tech/tags/sdlc.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>)

### AI overview

This article presents secure-by-default software development lifecycle practices. It recommends embedding security throughout development, standardizing trusted foundations, securing dependencies and base images, and integrating security into developer tools, CI/CD workflows, and runtime artifacts.

### Source excerpt

Build secure software faster with Chainguard. Learn how secure-by-default SDLC practices eliminate CVEs, automate compliance, and embed trust from code to cloud.

## Meeting the Zero-CVE Mandate: How Chainguard Helps Businesses Ship Secure Software That Customers Trust

DevFeed: [Meeting the Zero-CVE Mandate: How Chainguard Helps Businesses Ship Secure Software That Customers Trust](<https://devfeed.tech/articles/meeting-the-zero-cve-mandate-how-chainguard-helps-businesses-ship-secure-software-that-customers-trust-13155.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/meeting-the-zero-cve-mandate-how-chainguard-helps-businesses-ship-secure-software-that-customers-trust>)

Published: 2025-10-06T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-custom-assembly](<https://devfeed.tech/tags/chainguard-custom-assembly.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cves](<https://devfeed.tech/tags/cves.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

The article explains how Chainguard helps businesses meet stricter software security requirements for self-hosted, cloud, packaged-agent, and embedded software. It focuses on zero known CVEs at delivery, verifiable SBOMs, provenance attestations, compatibility with security tooling, and the challenges of open source dependencies and container images.

### Source excerpt

Chainguard's zero-CVE containers come with broad compatibility, custom assembly, verifiable provenance and SBOMs, and more to help you ship secure software.

## A Gift for the Open Source Community: Chainguard's CVE-Free Raspberry Pi Images (Beta)

DevFeed: [A Gift for the Open Source Community: Chainguard's CVE-Free Raspberry Pi Images (Beta)](<https://devfeed.tech/articles/a-gift-for-the-open-source-community-chainguard-s-cve-free-raspberry-pi-images-beta-12856.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/a-gift-for-the-open-source-community-chainguards-cve-free-raspberry-pi-images-beta>)

Published: 2025-10-04T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Raspberry Pi](<https://devfeed.tech/topics/raspberry-pi.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Linux](<https://devfeed.tech/topics/linux.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-free-container-images](<https://devfeed.tech/tags/cve-free-container-images.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [linux](<https://devfeed.tech/tags/linux.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [raspberry-pi](<https://devfeed.tech/tags/raspberry-pi.md>), [robotics](<https://devfeed.tech/tags/robotics.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Chainguard has released beta Raspberry Pi images described as CVE-free and vulnerability-free at build time. The images apply Chainguard's security and supply-chain practices to a maker-oriented Linux platform, but are intended for tinkering and exploration rather than production or critical workloads. The article invites users to test the images and provide feedback while outlining possible future work toward continuous updates.

### Source excerpt

Chainguard has created the first-ever CVE-free, vulnerability-free Raspberry Pi image. Learn more about how it works and what makes this special.

## Chainguard Containers Catalog Expands to More Than 1,700 Minimal, Zero-CVE Images

DevFeed: [Chainguard Containers Catalog Expands to More Than 1,700 Minimal, Zero-CVE Images](<https://devfeed.tech/articles/the-industry-s-fastest-growing-secure-container-catalog-13260.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-industrys-fastest-growing-secure-container-catalog>)

Published: 2025-09-09T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>), [Serverless](<https://devfeed.tech/topics/serverless.md>)

Tags: [azure-functions](<https://devfeed.tech/tags/azure-functions.md>), [catalog-pricing](<https://devfeed.tech/tags/catalog-pricing.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cve](<https://devfeed.tech/tags/cve.md>), [pricing](<https://devfeed.tech/tags/pricing.md>), [security](<https://devfeed.tech/tags/security.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

Chainguard describes its Containers catalog, claiming more than 1,700 minimal, zero-CVE images rebuilt daily, over 600 FIPS-compliant images, and expanded support for Java and Azure Functions. It also outlines Catalog Pricing, which provides commercial customers access to the catalog and its underlying packages.

### Source excerpt

Our Chainguard Containers catalog now has more than 1,700 minimal, zero-CVE images, rebuilt from source every day - industry-leading in both breadth and depth.

## Discover the Value of Chainguard Containers with the Value Calculator

DevFeed: [Discover the Value of Chainguard Containers with the Value Calculator](<https://devfeed.tech/articles/discover-the-value-of-chainguard-containers-with-the-value-calculator-13020.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/discover-the-value-of-chainguard-containers-with-the-value-calculator>)

Published: 2025-08-28T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Tool](<https://devfeed.tech/topics/tool.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [business-value](<https://devfeed.tech/tags/business-value.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-roi](<https://devfeed.tech/tags/chainguard-roi.md>), [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [developers](<https://devfeed.tech/tags/developers.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [tool](<https://devfeed.tech/tags/tool.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

Chainguard introduces a self-serve Value Calculator that estimates the organizational value of adopting Chainguard Containers. The tool uses metrics such as developer count, revenue, container-image usage, CVE remediation time, hardening effort, organizational maturity, industry, and compliance requirements to estimate potential gains from reducing engineering toil, mitigating risk, and supporting revenue growth.

### Source excerpt

Chainguard's Value Calculator is a new tool we created to make it easy to quantify the value of using Chainguard Containers for your specific organization.

## Guest Post: Resiliency by Design and the Importance of Internal Developer Platforms

DevFeed: [Guest Post: Resiliency by Design and the Importance of Internal Developer Platforms](<https://devfeed.tech/articles/guest-post-resiliency-by-design-and-the-importance-of-internal-developer-platforms-13076.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/guest-post-resiliency-by-design-and-the-importance-of-internal-developer-platforms>)

Published: 2025-08-21T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Platform Engineering](<https://devfeed.tech/topics/platform-engineering.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [Orchestration](<https://devfeed.tech/topics/orchestration.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [observability](<https://devfeed.tech/topics/observability.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [assemble-2025](<https://devfeed.tech/tags/assemble-2025.md>), [automotive-software-engineering](<https://devfeed.tech/tags/automotive-software-engineering.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-native-ecosystem](<https://devfeed.tech/tags/cloud-native-ecosystem.md>), [disaster-recovery](<https://devfeed.tech/tags/disaster-recovery.md>), [git](<https://devfeed.tech/tags/git.md>), [idp](<https://devfeed.tech/tags/idp.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [observability](<https://devfeed.tech/tags/observability.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [resiliency-by-design](<https://devfeed.tech/tags/resiliency-by-design.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This article explains how internal developer platforms support resiliency by design. It argues that a well-designed platform can reduce the effects of cloud-native complexity by providing consistency, CI/CD integration, declarative infrastructure, observability, governance, and an orchestration layer across Git, Kubernetes, and cloud providers. It also describes standardized disaster recovery, failover, deployment, rollback, and security practices as platform capabilities.

### Source excerpt

Gaurav Saxena, a Director of Engineering at an automotive company, talks through how internal developer platforms are an important part of resiliency by design.

[Next page](<https://devfeed.tech/tags/chainguard-images.md?cursor=WyIyMDI1LTA4LTIxVDAwOjAwOjAwKzAwOjAwIiwgIjVlOTRmZDYyLWQwYmYtNGFiZi1iNmUwLTU2M2Y0ZDZiNWE0MiJd>)