# cve management

Published articles for cve management.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## NIS2: Understanding key software security requirements

DevFeed: [NIS2: Understanding key software security requirements](<https://devfeed.tech/articles/nis2-understanding-key-software-security-requirements-13185.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/nis2-understanding-key-software-security-requirements>)

Published: 2025-02-25T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Critical Infrastructure](<https://devfeed.tech/topics/critical-infrastructure.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [compliance](<https://devfeed.tech/tags/compliance.md>), [cve-management](<https://devfeed.tech/tags/cve-management.md>), [cve-reporting](<https://devfeed.tech/tags/cve-reporting.md>), [energy](<https://devfeed.tech/tags/energy.md>), [eu](<https://devfeed.tech/tags/eu.md>), [europe](<https://devfeed.tech/tags/europe.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [manufacturing](<https://devfeed.tech/tags/manufacturing.md>), [nis2](<https://devfeed.tech/tags/nis2.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [transportation](<https://devfeed.tech/tags/transportation.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

This article explains how the European Union's NIS2 directive expands software security and vulnerability management requirements, shifts accountability to management and boards, and affects organizations operating in the EU. It discusses software supply chain security, open source development, SBOMs, CVE reporting, risk management, and the workload these requirements may create for security and developer teams.

### Source excerpt

The European Union's Network and Information Systems 2 is a compliance framework with strict requirements around vulnerability management.

## Chainguard CVE Visualizations: Now Generally Available

DevFeed: [Chainguard CVE Visualizations: Now Generally Available](<https://devfeed.tech/articles/chainguard-cve-visualizations-now-generally-available-12941.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-cve-visualizations-now-generally-available>)

Published: 2025-02-05T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [availability](<https://devfeed.tech/tags/availability.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-console](<https://devfeed.tech/tags/chainguard-console.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve-data](<https://devfeed.tech/tags/cve-data.md>), [cve-management](<https://devfeed.tech/tags/cve-management.md>), [cve-visualizations](<https://devfeed.tech/tags/cve-visualizations.md>), [cves](<https://devfeed.tech/tags/cves.md>), [release](<https://devfeed.tech/tags/release.md>), [reporting](<https://devfeed.tech/tags/reporting.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard announces the general availability of CVE Visualizations in the Chainguard Console. The feature helps users track remediated CVEs, compare CVE accumulation between Chainguard Images and open source alternatives, and evaluate the security and economic impact of minimal container images.

### Source excerpt

Chainguard CVE Visualizations, now generally available, is a capability that allows users to compare CVE numbers in both Chainguard Containers and upstream.

## How much time is wasted triaging known exploits?

DevFeed: [How much time is wasted triaging known exploits?](<https://devfeed.tech/articles/how-much-time-is-wasted-triaging-known-exploits-13091.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-much-time-is-wasted-triaging-known-exploits>)

Published: 2024-06-21T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [grype](<https://devfeed.tech/topics/grype.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [base-container-images](<https://devfeed.tech/tags/base-container-images.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-management](<https://devfeed.tech/tags/cve-management.md>), [cves](<https://devfeed.tech/tags/cves.md>), [efficiency](<https://devfeed.tech/tags/efficiency.md>), [exploited-vulnerabilities](<https://devfeed.tech/tags/exploited-vulnerabilities.md>), [exploits](<https://devfeed.tech/tags/exploits.md>), [grype](<https://devfeed.tech/tags/grype.md>), [kev-catalog](<https://devfeed.tech/tags/kev-catalog.md>), [known-exploited-vulnerability](<https://devfeed.tech/tags/known-exploited-vulnerability.md>), [nvd-cve](<https://devfeed.tech/tags/nvd-cve.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-detection](<https://devfeed.tech/tags/vulnerability-detection.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

The article reports that seven percent of 230 popular Bitnami container images contained CVEs listed in the Known Exploited Vulnerability catalog, but detailed triage found that none were exploitable in those container contexts. It argues that CVE triage consumes substantial staff time, while Chainguard Images historically remediated affected CVEs in an average of 2.5 days.

### Source excerpt

Stop wasting time on known exploits. Read our latest research and discover strategies to streamline your vulnerability management for maximum efficiency.

## Wolfi's approach to container security and CVE management

DevFeed: [Wolfi's approach to container security and CVE management](<https://devfeed.tech/articles/revolutionizing-container-security-and-cve-management-13213.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/revolutionizing-container-security-and-cve-management>)

Published: 2024-02-08T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [container-security](<https://devfeed.tech/topics/container-security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [apko](<https://devfeed.tech/tags/apko.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-management](<https://devfeed.tech/tags/cve-management.md>), [melange](<https://devfeed.tech/tags/melange.md>), [oci](<https://devfeed.tech/tags/oci.md>), [secure-images](<https://devfeed.tech/tags/secure-images.md>), [secure-software-supply-chain](<https://devfeed.tech/tags/secure-software-supply-chain.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

The article explains how Wolfi, a secure-by-default undistro, supports container security by helping create minimal, reproducible OCI-compliant images and reducing software supply chain risks. It also describes how Wolfi powers Chainguard Images.

### Source excerpt

Discover Wolfi, the 'secure-by-default' undistro for container security, enhancing open-source software with minimal CVE counts and robust protection.

## Why your company is wasting thousands of hours on software vulnerabilities

DevFeed: [Why your company is wasting thousands of hours on software vulnerabilities](<https://devfeed.tech/articles/why-your-company-is-wasting-thousands-of-hours-on-software-vulnerabilities-13333.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/why-your-company-is-wasting-thousands-of-hours-on-software-vulnerabilities>)

Published: 2024-02-06T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [chainguard labs](<https://devfeed.tech/topics/chainguard-labs.md>)

Tags: [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-labs](<https://devfeed.tech/tags/chainguard-labs.md>), [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cve-management](<https://devfeed.tech/tags/cve-management.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

Chainguard Labs interviewed approximately ten software professionals and found that companies building or deploying containers may spend thousands of hours each year on vulnerability management. The article attributes much of this burden to large numbers of known vulnerabilities and image-selection practices that disregard vulnerability counts.

### Source excerpt

Chainguard Labs surveyed nine companies to see how many hours they spent on vulnerability management each year. Check out this blog to see the results.