# container image security

Published articles for container image security.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Why the CVE doom cycle cannot be solved by working harder

DevFeed: [Why the CVE doom cycle cannot be solved by working harder](<https://devfeed.tech/articles/why-the-cve-doom-cycle-cannot-be-solved-by-working-harder-12284.md>)

Original publisher: [Read original article](<https://platformengineering.org/blog/why-the-cve-doom-cycle-can-not-be-solved-by-working-harder>)

Author: Sam Barlien

Published: 2026-07-23T05:40:01Z

Content type: article

Language: en

Sources: [Platform Engineering Blog](<https://devfeed.tech/sources/platform-engineering-blog.md>)

Topics: [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [configuration](<https://devfeed.tech/topics/configuration.md>)

Tags: [automation](<https://devfeed.tech/tags/automation.md>), [container-image-security](<https://devfeed.tech/tags/container-image-security.md>), [cve](<https://devfeed.tech/tags/cve.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

The article argues that the recurring cycle of scanning, triaging, patching, and redeploying container images cannot be solved by working harder or using faster scanners. Because vulnerability findings and CVEs accumulate faster than manual remediation can handle, it recommends embedding vulnerability management into the platform through secure-by-design practices, golden paths, and automation.

### Source excerpt

Manual CVE triage doesn't scale. Break the CVE doom cycle by shifting vulnerability management into the platform with golden paths and automation

## Check out Chainguard at KubeCon EU in London on April 1-4

DevFeed: [Check out Chainguard at KubeCon EU in London on April 1-4](<https://devfeed.tech/articles/check-out-chainguard-at-kubecon-eu-in-london-on-april-1-4-13003.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/check-out-chainguard-at-kubecon-eu-in-london-on-april-1-4>)

Published: 2025-03-31T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [chainguard vms](<https://devfeed.tech/topics/chainguard-vms.md>), [Security](<https://devfeed.tech/topics/security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [devrel](<https://devfeed.tech/topics/devrel.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-vms](<https://devfeed.tech/tags/chainguard-vms.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [cloud-native-rejekts](<https://devfeed.tech/tags/cloud-native-rejekts.md>), [container-image-security](<https://devfeed.tech/tags/container-image-security.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cves](<https://devfeed.tech/tags/cves.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [event](<https://devfeed.tech/tags/event.md>), [java](<https://devfeed.tech/tags/java.md>), [kubecon](<https://devfeed.tech/tags/kubecon.md>), [kubecon-eu](<https://devfeed.tech/tags/kubecon-eu.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [london](<https://devfeed.tech/tags/london.md>), [virtual-machines](<https://devfeed.tech/tags/virtual-machines.md>)

### AI overview

Chainguard announces its presence at KubeCon EU 2025 in London, where it will showcase Chainguard Containers, Chainguard Libraries, and Chainguard VMs. The article also previews talks on learning communities and container image security levels.

### Source excerpt

Chainguard will be at booth N300 at KubeCon EU 2025 in London to discuss Chainguard Libraries, Chainguard VMs, and Chainguard Containers.

## Chainguard Images: The Easy Button for FedRAMP

DevFeed: [Chainguard Images: The Easy Button for FedRAMP](<https://devfeed.tech/articles/chainguard-images-the-easy-button-for-fedramp-12960.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-images-the-easy-button-for-fedramp>)

Published: 2025-01-28T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Docker Hardened Images](<https://devfeed.tech/topics/docker-hardened-images.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [chainguard sboms](<https://devfeed.tech/topics/chainguard-sboms.md>), [Security](<https://devfeed.tech/topics/security.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [asset-management](<https://devfeed.tech/tags/asset-management.md>), [ato](<https://devfeed.tech/tags/ato.md>), [authority-to-operate](<https://devfeed.tech/tags/authority-to-operate.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container](<https://devfeed.tech/tags/container.md>), [container-image-security](<https://devfeed.tech/tags/container-image-security.md>), [cve](<https://devfeed.tech/tags/cve.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [sca](<https://devfeed.tech/tags/sca.md>), [sdlc](<https://devfeed.tech/tags/sdlc.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

This article explains how Chainguard Images can simplify and accelerate FedRAMP Authority to Operate compliance for organizations deploying containerized cloud products to federal government customers. It describes secure-by-design containers as helping address asset management, hardening, cryptography, and vulnerability management requirements, and notes Snowflake's achievement of FedRAMP High with Chainguard Images.

### Source excerpt

Chainguard Images are designed to make achieving FedRAMP compliance for container images easier. Learn more about how we make vulnerability management simple.

## Understanding NIST's latest updates on container image security

DevFeed: [Understanding NIST's latest updates on container image security](<https://devfeed.tech/articles/understanding-nist-s-latest-updates-on-container-image-security-13301.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/understanding-nists-latest-updates-on-container-image-security>)

Published: 2024-07-12T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [container-security](<https://devfeed.tech/topics/container-security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-image-security](<https://devfeed.tech/tags/container-image-security.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [image-security](<https://devfeed.tech/tags/image-security.md>), [nist](<https://devfeed.tech/tags/nist.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article explains NIST guidance relevant to container image security, including risks from misconfiguration, runtime threats, limited visibility, governance gaps, and compliance issues. It discusses NIST SP 800-161 Revision 1 and its focus on cybersecurity supply chain risk management, vulnerability monitoring, configuration management, authorization, and authentication.

### Source excerpt

Learn about NIST's latest updates on container image security and how it impacts your organization's security posture.

## NIST's role in enhancing software supply chain security

DevFeed: [NIST's role in enhancing software supply chain security](<https://devfeed.tech/articles/nist-s-role-in-enhancing-software-supply-chain-security-13186.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/nists-role-in-enhancing-software-supply-chain-security>)

Published: 2024-07-03T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>)

Tags: [container-image-security](<https://devfeed.tech/tags/container-image-security.md>), [nist](<https://devfeed.tech/tags/nist.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>)

### AI overview

The article explains NIST's role in software supply chain security, including its Cybersecurity Framework, guidance following Executive Order 14028, and recommended practices such as risk assessment, supplier controls, SBOMs, incident response, and continuous monitoring.

### Source excerpt

NIST's framework for enhancing software supply chain security: Learn how the NIST is guiding organizations to build a more secure software ecosystem.

## Chainguard's response to CVE-2023-6246 in glibc

DevFeed: [Chainguard's response to CVE-2023-6246 in glibc](<https://devfeed.tech/articles/chainguard-s-response-to-cve-2023-6246-in-glibc-12994.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguards-response-to-cve-2023-6246-in-glibc>)

Published: 2024-02-01T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [container-image-security](<https://devfeed.tech/tags/container-image-security.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2023-6246](<https://devfeed.tech/tags/cve-2023-6246.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [glibc](<https://devfeed.tech/tags/glibc.md>), [security](<https://devfeed.tech/tags/security.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard describes its response to CVE-2023-6246, a glibc heap-based buffer overflow that can enable local privilege escalation. The team patched the glibc Wolfi package and rebuilt affected Chainguard Images after coordinated disclosure.

### Source excerpt

Chainguard swiftly addresses CVE-2023-6246 in glibc, reinforcing container image security with rapid patch deployment and updated advisories.

## Celebrating innovation in open source software and container image security with Chainguard Images

DevFeed: [Celebrating innovation in open source software and container image security with Chainguard Images](<https://devfeed.tech/articles/celebrating-innovation-in-open-source-software-and-container-image-security-with-chainguard-images-12920.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/celebrating-innovation-in-open-source-software-and-container-image-security-with-chainguard-images>)

Published: 2023-11-01T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-image-security](<https://devfeed.tech/tags/container-image-security.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fips](<https://devfeed.tech/tags/fips.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-signatures](<https://devfeed.tech/tags/software-signatures.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

Chainguard describes the growth of Chainguard Images as a secure container image offering for open source software development and software supply chain security. The article highlights more than one million image builds, over 90 million pulls, a large inventory of tools and applications, reduced CVEs, passwordless token-based authentication, SBOMs, and Sigstore-verified software signatures.

### Source excerpt

Explore the fusion of open source innovation and container security with Chainguard Images.