# common vulnerabilities and exposures

Published articles for common vulnerabilities and exposures.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Introducing Chainguard Agent Skills: Because your AI agent shouldn't trust strangers

DevFeed: [Introducing Chainguard Agent Skills: Because your AI agent shouldn't trust strangers](<https://devfeed.tech/articles/introducing-chainguard-agent-skills-because-your-ai-agent-shouldn-t-trust-strangers-13107.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-chainguard-agent-skills>)

Published: 2026-03-17T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard agent skills](<https://devfeed.tech/topics/chainguard-agent-skills.md>), [Agent Skills](<https://devfeed.tech/topics/agent-skills.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Malware](<https://devfeed.tech/topics/malware.md>)

Tags: [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [anthropic](<https://devfeed.tech/tags/anthropic.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-agent-skills](<https://devfeed.tech/tags/chainguard-agent-skills.md>), [chainguard-ai-tools](<https://devfeed.tech/tags/chainguard-ai-tools.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [claude](<https://devfeed.tech/tags/claude.md>), [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [hardened-ai-agent-skills](<https://devfeed.tech/tags/hardened-ai-agent-skills.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [malware](<https://devfeed.tech/tags/malware.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

Chainguard Agent Skills is introduced as a continuously maintained catalog of hardened AI agent skills. The catalog applies review, permission scoping, integrity verification, continuous hardening, and audit trails to reduce the supply-chain risks of third-party skills used with platforms such as Claude Code and OpenClaw.

### Source excerpt

Chainguard Agent Skills is a continuously maintained catalog of hardened AI agent skills.

## Chainguard + Booz Allen: Delivering Trusted Open-Source Software to U.S. Government Agencies

DevFeed: [Chainguard + Booz Allen: Delivering Trusted Open-Source Software to U.S. Government Agencies](<https://devfeed.tech/articles/chainguard-booz-allen-delivering-trusted-open-source-software-to-u-s-government-agencies-12931.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-booz-allen-delivering-trusted-open-source-software-to-u-s-government-agencies>)

Published: 2025-10-15T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [ato](<https://devfeed.tech/tags/ato.md>), [booz-allen-hamilton](<https://devfeed.tech/tags/booz-allen-hamilton.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-booz-partnership](<https://devfeed.tech/tags/chainguard-booz-partnership.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-dod-partnership](<https://devfeed.tech/tags/chainguard-dod-partnership.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fips](<https://devfeed.tech/tags/fips.md>), [government](<https://devfeed.tech/tags/government.md>), [hardened-containers](<https://devfeed.tech/tags/hardened-containers.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [stateramp](<https://devfeed.tech/tags/stateramp.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-cve-container-images](<https://devfeed.tech/tags/zero-cve-container-images.md>)

### AI overview

Chainguard and Booz Allen announced a partnership to help U.S. government agencies and defense programs secure software supply chains, reduce vulnerabilities, and accelerate compliance. The partnership combines Booz Allen's mission expertise with Chainguard's secure-by-default open-source software, including hardened containers that helped one defense-related program obtain authorization to operate in eight weeks.

### Source excerpt

Chainguard and Booz Allen partner to help federal programs eliminate vulnerabilities, save engineering time, and accelerate compliance timelines.

## Discover the Value of Chainguard Containers with the Value Calculator

DevFeed: [Discover the Value of Chainguard Containers with the Value Calculator](<https://devfeed.tech/articles/discover-the-value-of-chainguard-containers-with-the-value-calculator-13020.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/discover-the-value-of-chainguard-containers-with-the-value-calculator>)

Published: 2025-08-28T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Tool](<https://devfeed.tech/topics/tool.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [business-value](<https://devfeed.tech/tags/business-value.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-roi](<https://devfeed.tech/tags/chainguard-roi.md>), [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [developers](<https://devfeed.tech/tags/developers.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [tool](<https://devfeed.tech/tags/tool.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

Chainguard introduces a self-serve Value Calculator that estimates the organizational value of adopting Chainguard Containers. The tool uses metrics such as developer count, revenue, container-image usage, CVE remediation time, hardening effort, organizational maturity, industry, and compliance requirements to estimate potential gains from reducing engineering toil, mitigating risk, and supporting revenue growth.

### Source excerpt

Chainguard's Value Calculator is a new tool we created to make it easy to quantify the value of using Chainguard Containers for your specific organization.

## Announcing Chainguard VMs: Minimal, Zero-CVE Container Host Images

DevFeed: [Announcing Chainguard VMs: Minimal, Zero-CVE Container Host Images](<https://devfeed.tech/articles/announcing-chainguard-vms-minimal-zero-cve-container-host-images-12882.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/announcing-chainguard-vms-minimal-zero-cve-container-host-images>)

Published: 2025-03-25T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Linux](<https://devfeed.tech/topics/linux.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [blog](<https://devfeed.tech/tags/blog.md>), [blog-post](<https://devfeed.tech/tags/blog-post.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-vms](<https://devfeed.tech/tags/chainguard-vms.md>), [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [container](<https://devfeed.tech/tags/container.md>), [container-hosts](<https://devfeed.tech/tags/container-hosts.md>), [cve](<https://devfeed.tech/tags/cve.md>), [images](<https://devfeed.tech/tags/images.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [multi-cloud](<https://devfeed.tech/tags/multi-cloud.md>), [operating-systems](<https://devfeed.tech/tags/operating-systems.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [virtual-machines](<https://devfeed.tech/tags/virtual-machines.md>)

### AI overview

Chainguard VMs has entered Early Access as a catalog of guarded, minimal, zero-CVE container host images for ephemeral cloud workloads. The images are built from source, include only required container-host components, and are designed to reduce attack surface and simplify vulnerability remediation.

### Source excerpt

Chainguard VMs is a catalog of guarded, minimal, zero-CVE container host images that is now in Early Access.

## Guest Post: Securing the Foundation of Dynamic Data Governance at Velotix

DevFeed: [Guest Post: Securing the Foundation of Dynamic Data Governance at Velotix](<https://devfeed.tech/articles/guest-post-securing-the-foundation-of-dynamic-data-governance-at-velotix-13223.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/securing-the-foundation-of-dynamic-data-governance-at-velotix>)

Published: 2025-02-19T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [data-governance](<https://devfeed.tech/topics/data-governance.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Amazon OpenSearch Service](<https://devfeed.tech/topics/amazon-opensearch-service.md>), [Kafka](<https://devfeed.tech/topics/kafka.md>)

Tags: [case-study](<https://devfeed.tech/tags/case-study.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [guest-post](<https://devfeed.tech/tags/guest-post.md>), [performance](<https://devfeed.tech/tags/performance.md>), [productivity](<https://devfeed.tech/tags/productivity.md>), [security](<https://devfeed.tech/tags/security.md>), [time](<https://devfeed.tech/tags/time.md>), [velotix](<https://devfeed.tech/tags/velotix.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

A guest post explains how Velotix uses Chainguard Images to reduce CVEs across its data-governance platform. The article describes challenges with vendor-provided images and dependency upgrades, and highlights scheduled recompilation to keep infrastructure-level libraries current.

### Source excerpt

Velotix utilizes Chainguard Images to help reduce CVEs, improve performance, and save time. Learn how Chainguard helps them build a more secure infrastructure.

## FedRAMP vulnerability scanning requirements explained

DevFeed: [FedRAMP vulnerability scanning requirements explained](<https://devfeed.tech/articles/fedramp-vulnerability-scanning-requirements-explained-13042.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/fedramp-vulnerability-scanning-requirements-explained>)

Author: Can secure-by-default container images or VMs speed up FedRAMP authorization

Published: 2024-11-21T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [Containers](<https://devfeed.tech/topics/containers.md>)

Tags: [audits](<https://devfeed.tech/tags/audits.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [automated](<https://devfeed.tech/tags/automated.md>), [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cve](<https://devfeed.tech/tags/cve.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fips](<https://devfeed.tech/tags/fips.md>), [requirements](<https://devfeed.tech/tags/requirements.md>), [security](<https://devfeed.tech/tags/security.md>), [stigs](<https://devfeed.tech/tags/stigs.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

This article explains FedRAMP vulnerability scanning requirements, including the required scan scope, recurring authenticated scans, reporting expectations, remediation timelines, and the role of scan data in continuous monitoring, authorization evidence, POA&Ms, and risk reviews.

### Source excerpt

Understand FedRAMP vulnerability scanning rules, scope, and SLAs. Get compliance clarity and learn how to simplify audits.

## Latest CVE patch report: Securing software supply chains

DevFeed: [Latest CVE patch report: Securing software supply chains](<https://devfeed.tech/articles/latest-cve-patch-report-securing-software-supply-chains-13140.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/latest-cve-patch-report-securing-software-supply-chains>)

Published: 2024-06-27T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [command-line](<https://devfeed.tech/tags/command-line.md>), [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2024-4603](<https://devfeed.tech/tags/cve-2024-4603.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [report](<https://devfeed.tech/tags/report.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard's latest CVE patch report describes how its remediation team patches vulnerabilities in Chainguard Images and Wolfi Packages, aiming to provide accurate scanner results and reduce false positives. It also examines CVE-2024-4603 in OpenSSL, which can cause denial-of-service attacks when untrusted, excessively large DSA parameters are checked.

### Source excerpt

Dive into our latest CVE patch report and see how Chainguard proactively mitigates vulnerabilities to enhance software supply chain security.

## GitGuardian pioneers secure code solutions down to its source with Chainguard Images

DevFeed: [GitGuardian pioneers secure code solutions down to its source with Chainguard Images](<https://devfeed.tech/articles/gitguardian-pioneers-secure-code-solutions-down-to-its-source-with-chainguard-images-13066.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/gitguardian-pioneers-secure-code-solutions-down-to-its-source-with-chainguard-images>)

Published: 2024-03-13T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [code security](<https://devfeed.tech/topics/code-security.md>), [Containers](<https://devfeed.tech/topics/containers.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [containers](<https://devfeed.tech/tags/containers.md>), [customer-trust](<https://devfeed.tech/tags/customer-trust.md>), [gitguardian](<https://devfeed.tech/tags/gitguardian.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

This case study describes how GitGuardian partnered with Chainguard and adopted Chainguard Images to address software-container vulnerabilities, reduce CVEs, streamline vulnerability management, and meet customer SLAs and compliance requirements.

### Source excerpt

GitGuardian partners with Chainguard, utilizing Chainguard Images to reduce CVEs, enhance security, and meet compliance standards efficiently.

## Why your company is wasting thousands of hours on software vulnerabilities

DevFeed: [Why your company is wasting thousands of hours on software vulnerabilities](<https://devfeed.tech/articles/why-your-company-is-wasting-thousands-of-hours-on-software-vulnerabilities-13333.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/why-your-company-is-wasting-thousands-of-hours-on-software-vulnerabilities>)

Published: 2024-02-06T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [chainguard labs](<https://devfeed.tech/topics/chainguard-labs.md>)

Tags: [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-labs](<https://devfeed.tech/tags/chainguard-labs.md>), [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cve-management](<https://devfeed.tech/tags/cve-management.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

Chainguard Labs interviewed approximately ten software professionals and found that companies building or deploying containers may spend thousands of hours each year on vulnerability management. The article attributes much of this burden to large numbers of known vulnerabilities and image-selection practices that disregard vulnerability counts.

### Source excerpt

Chainguard Labs surveyed nine companies to see how many hours they spent on vulnerability management each year. Check out this blog to see the results.

## Building minimal, up-to-date cloud images with Wolfi

DevFeed: [Building minimal, up-to-date cloud images with Wolfi](<https://devfeed.tech/articles/building-minimal-up-to-date-cloud-images-with-wolfi-12908.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/building-minimal-up-to-date-cloud-images-with-wolfi>)

Published: 2023-12-15T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Cloud](<https://devfeed.tech/topics/cloud.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>), [DevOps](<https://devfeed.tech/topics/devops.md>)

Tags: [apk](<https://devfeed.tech/tags/apk.md>), [apko](<https://devfeed.tech/tags/apko.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [chainguard-academy](<https://devfeed.tech/tags/chainguard-academy.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [container](<https://devfeed.tech/tags/container.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [devops](<https://devfeed.tech/tags/devops.md>), [efficiency](<https://devfeed.tech/tags/efficiency.md>), [kubecon-na](<https://devfeed.tech/tags/kubecon-na.md>), [melange](<https://devfeed.tech/tags/melange.md>), [minimalism](<https://devfeed.tech/tags/minimalism.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [os](<https://devfeed.tech/tags/os.md>), [packages](<https://devfeed.tech/tags/packages.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

The article introduces Wolfi, an open source project for building minimal, up-to-date cloud and container images. It explains how Wolfi's security-first architecture, proactive updates, minimalism, and supporting tools such as melange, apko, and apk help reduce attack surfaces and CVE exposure while improving software supply chain security.

### Source excerpt

Discover Wolfi OS: Crafting minimal, always up-to-date cloud images for superior security and efficiency in the cloud.

## New year, new image: Introducing the Chainguard Images Directory

DevFeed: [New year, new image: Introducing the Chainguard Images Directory](<https://devfeed.tech/articles/new-year-new-image-introducing-the-chainguard-images-directory-13184.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/new-year-new-image-introducing-the-chainguard-images-directory>)

Published: 2023-12-13T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Docker Hardened Images](<https://devfeed.tech/topics/docker-hardened-images.md>), [Docker Hub](<https://devfeed.tech/topics/docker-hub.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-images-directory](<https://devfeed.tech/tags/chainguard-images-directory.md>), [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [container-image-registry](<https://devfeed.tech/tags/container-image-registry.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [digestabot](<https://devfeed.tech/tags/digestabot.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Chainguard introduces an updated Images Directory for discovering and using its minimal, hardened container images. The release also adds Security Advisories with information about CVE mitigation and introduces digestabot, a free GitHub Action for keeping Developer Images current.

### Source excerpt

Discover how the updated Chainguard Images Directory simplifies finding container images and critical vulnerability advisories.

## Fuzzy CVEs, tarfiles, and untrusted input

DevFeed: [Fuzzy CVEs, tarfiles, and untrusted input](<https://devfeed.tech/articles/fuzzy-cves-tarfiles-and-untrusted-input-13056.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/fuzzy-cves-tarfiles-and-untrusted-input>)

Published: 2023-07-27T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [common vulnerabilities and exposures](<https://devfeed.tech/topics/common-vulnerabilities-and-exposures.md>), [Python](<https://devfeed.tech/topics/python.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [NVD](<https://devfeed.tech/topics/nvd.md>)

Tags: [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cves](<https://devfeed.tech/tags/cves.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [go](<https://devfeed.tech/tags/go.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [nvd](<https://devfeed.tech/tags/nvd.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [python](<https://devfeed.tech/tags/python.md>), [scanner](<https://devfeed.tech/tags/scanner.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [vulnerability-scanner](<https://devfeed.tech/tags/vulnerability-scanner.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

This article examines CVE-2007-4559 in Python's tarfile module, why the 15-year-old issue may still appear in security scanners, and why its classification as a vulnerability is disputed. It discusses CVE processes, NVD entries, open-source maintainer constraints, and the risks of extracting untrusted tarfile inputs.

### Source excerpt

Navigate fuzzy CVEs, tarfiles, and untrusted input with Chainguard, paving the way to secure coding practices.