# cve remediation

Published articles for cve remediation.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Chainguard Libraries for Java is now GA; CVE remediation beta available for sign up

DevFeed: [Chainguard Libraries for Java is now GA; CVE remediation beta available for sign up](<https://devfeed.tech/articles/chainguard-libraries-for-java-is-now-ga-cve-remediation-beta-available-for-sign-up-12966.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-libraries-for-java-is-now-ga-and-includes-cve-remediation>)

Published: 2026-06-23T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [Java](<https://devfeed.tech/topics/java.md>), [Spring Boot](<https://devfeed.tech/topics/spring-boot.md>), [Security](<https://devfeed.tech/topics/security.md>), [Back end](<https://devfeed.tech/topics/backend.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-libraries-for-java](<https://devfeed.tech/tags/chainguard-libraries-for-java.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [java](<https://devfeed.tech/tags/java.md>), [java-packages](<https://devfeed.tech/tags/java-packages.md>), [java-spring](<https://devfeed.tech/tags/java-spring.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [scanner](<https://devfeed.tech/tags/scanner.md>), [security](<https://devfeed.tech/tags/security.md>), [zero-cve-packages](<https://devfeed.tech/tags/zero-cve-packages.md>)

### AI overview

Chainguard Libraries for Java is generally available, and its CVE remediation capability is available in beta. The article describes backported fixes for critical and high-severity CVEs across the Spring Boot ecosystem, helping teams manage risks in pinned or legacy Java dependencies while planning upgrades.

### Source excerpt

Chainguard Libraries for Java is now GA, delivering CVE-remediated dependencies with SBOMs, provenance, and scanner-recognized fixes.

## Removing supply chain friction: How PeopleTec improved developer productivity with Chainguard

DevFeed: [Removing supply chain friction: How PeopleTec improved developer productivity with Chainguard](<https://devfeed.tech/articles/removing-supply-chain-friction-how-peopletec-improved-developer-productivity-with-chainguard-13210.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/removing-supply-chain-friction-how-peopletec-improved-developer-productivity-with-chainguard>)

Published: 2026-04-02T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [code productivity](<https://devfeed.tech/topics/code-productivity.md>), [migration](<https://devfeed.tech/topics/migration.md>)

Tags: [accelerate](<https://devfeed.tech/tags/accelerate.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-assemble](<https://devfeed.tech/tags/chainguard-assemble.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-developer-experience](<https://devfeed.tech/tags/chainguard-developer-experience.md>), [chainguard-migration](<https://devfeed.tech/tags/chainguard-migration.md>), [ci](<https://devfeed.tech/tags/ci.md>), [code](<https://devfeed.tech/tags/code.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [developer](<https://devfeed.tech/tags/developer.md>), [developer-velocity](<https://devfeed.tech/tags/developer-velocity.md>), [migration](<https://devfeed.tech/tags/migration.md>), [migration-guides](<https://devfeed.tech/tags/migration-guides.md>), [peopletec](<https://devfeed.tech/tags/peopletec.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

PeopleTec describes how it used Chainguard Security controls and Chainguard Containers to reduce software supply-chain friction, address vulnerabilities in base images, improve provenance and compliance workflows, and support developer productivity. The approach emphasized early adopters, low-friction migration, and automated policy checks in CI.

### Source excerpt

Learn how PeopleTec used Chainguard to reduce security friction, accelerate adoption, and align platform consistency with developer velocity.

## Owning the boundary: Introducing the Chainguard FIPS Provider for OpenSSL 3.4.0

DevFeed: [Owning the boundary: Introducing the Chainguard FIPS Provider for OpenSSL 3.4.0](<https://devfeed.tech/articles/owning-the-boundary-introducing-the-chainguard-fips-provider-for-openssl-3-4-0-13124.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-the-chainguard-fips-provider-for-openssl-3-4-0>)

Published: 2026-03-11T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-fips](<https://devfeed.tech/tags/chainguard-fips.md>), [chainguard-fips-images](<https://devfeed.tech/tags/chainguard-fips-images.md>), [cmvp](<https://devfeed.tech/tags/cmvp.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [fips](<https://devfeed.tech/tags/fips.md>), [fips-containers](<https://devfeed.tech/tags/fips-containers.md>), [open-ssl-3-4-0](<https://devfeed.tech/tags/open-ssl-3-4-0.md>), [updates](<https://devfeed.tech/tags/updates.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard announces the Chainguard FIPS Provider for OpenSSL 3.4.0, validated under CMVP certificate #5132. Beginning March 17, 2026, Chainguard FIPS container images will upgrade to it. The article explains that owning the validated cryptographic module lets Chainguard remediate vulnerabilities within the validated boundary and manage the required resubmission process without depending on third parties.

### Source excerpt

Chainguard is the first and only to FIPS-validate OpenSSL 3.4, owning the validated cryptographic module that powers our FIPS images.

## Chainguard + Second Front: A faster, more secure path into government markets

DevFeed: [Chainguard + Second Front: A faster, more secure path into government markets](<https://devfeed.tech/articles/chainguard-second-front-a-faster-more-secure-path-into-government-markets-12980.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-second-front-a-faster-more-secure-path-into-government-markets>)

Published: 2026-02-20T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-for-compliance](<https://devfeed.tech/tags/chainguard-for-compliance.md>), [cmmc](<https://devfeed.tech/tags/cmmc.md>), [container-image-compliance](<https://devfeed.tech/tags/container-image-compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [federal-compliance](<https://devfeed.tech/tags/federal-compliance.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [government](<https://devfeed.tech/tags/government.md>), [iso](<https://devfeed.tech/tags/iso.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [second-front-systems](<https://devfeed.tech/tags/second-front-systems.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>)

### AI overview

Chainguard and Second Front are partnering to help software companies pursue federal market requirements, including FedRAMP authorization and DoD impact-level accreditations. The article describes combining Chainguard's hardened container images with Second Front's Game Warden DevSecOps platform to support secure application delivery and vulnerability reduction.

### Source excerpt

Discover how Chainguard and Second Front are partnering to help build a secure path into government markets for your organization.

## Announcing AWS Inspector scanner support for Chainguard Libraries

DevFeed: [Announcing AWS Inspector scanner support for Chainguard Libraries](<https://devfeed.tech/articles/announcing-aws-inspector-scanner-support-for-chainguard-libraries-12874.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/announcing-aws-inspector-scanner-support-for-chainguard-libraries>)

Published: 2025-11-24T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Python](<https://devfeed.tech/topics/python.md>), [Django](<https://devfeed.tech/topics/django.md>), [Flask](<https://devfeed.tech/topics/flask.md>)

Tags: [amazon-scanner-support](<https://devfeed.tech/tags/amazon-scanner-support.md>), [aws](<https://devfeed.tech/tags/aws.md>), [aws-inspector](<https://devfeed.tech/tags/aws-inspector.md>), [chainguard-aws-integration](<https://devfeed.tech/tags/chainguard-aws-integration.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-libraries-for-python](<https://devfeed.tech/tags/chainguard-libraries-for-python.md>), [chainguard-libraries-for-python-aws](<https://devfeed.tech/tags/chainguard-libraries-for-python-aws.md>), [chainguard-packages](<https://devfeed.tech/tags/chainguard-packages.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [django](<https://devfeed.tech/tags/django.md>), [flask](<https://devfeed.tech/tags/flask.md>), [malware](<https://devfeed.tech/tags/malware.md>), [malware-prevention](<https://devfeed.tech/tags/malware-prevention.md>), [python](<https://devfeed.tech/tags/python.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

Chainguard Libraries for Python now integrates with Amazon Inspector's enhanced scanning for Amazon ECR. The integration provides malware prevention, recognition of Chainguard-remediated CVEs, and a unified view of container and library vulnerabilities across AWS workloads.

### Source excerpt

Chainguard Libraries now integrates with AWS Inspector, bringing proactive malware prevention, CVE remediation, and vulnerability visibility across AWS workloads

## Custom Assembly Updates: Create Multiple, Customized Variants of a Chainguard Container

DevFeed: [Custom Assembly Updates: Create Multiple, Customized Variants of a Chainguard Container](<https://devfeed.tech/articles/custom-assembly-updates-create-multiple-customized-variants-of-a-chainguard-container-13015.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/custom-assembly-updates-create-multiple-customized-variants-of-a-chainguard-container>)

Published: 2025-10-29T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard custom assembly](<https://devfeed.tech/topics/chainguard-custom-assembly.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [cve remediation](<https://devfeed.tech/topics/cve-remediation.md>)

Tags: [assembly](<https://devfeed.tech/tags/assembly.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-custom-assembly](<https://devfeed.tech/tags/chainguard-custom-assembly.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [custom-assembly](<https://devfeed.tech/tags/custom-assembly.md>), [custom-chainguard-containers](<https://devfeed.tech/tags/custom-chainguard-containers.md>), [custom-chainguard-images](<https://devfeed.tech/tags/custom-chainguard-images.md>), [customers](<https://devfeed.tech/tags/customers.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [new-feature](<https://devfeed.tech/tags/new-feature.md>)

### AI overview

Chainguard announces enhancements to Custom Assembly that let customers create, add, delete, rename, edit, preview, and manage multiple customized variants of Chainguard container images directly in the console. The update supports self-serve provisioning and includes build history, logs, and build status.

### Source excerpt

Customize Chainguard Containers with the latest Custom Assembly update. You can create, edit, and manage secure, zero-CVE image variants directly in the console.

## Chainguard Libraries for Python: Now Generally Available with CVE Remediation and Malware Protection

DevFeed: [Chainguard Libraries for Python: Now Generally Available with CVE Remediation and Malware Protection](<https://devfeed.tech/articles/chainguard-libraries-for-python-now-generally-available-with-cve-remediation-and-malware-protection-12967.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-libraries-for-python-now-generally-available-with-cve-remediation-and-malware-protection>)

Published: 2025-10-22T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard libraries for python](<https://devfeed.tech/topics/chainguard-libraries-for-python.md>), [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [Python](<https://devfeed.tech/topics/python.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-language-libraries](<https://devfeed.tech/tags/chainguard-language-libraries.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-libraries-for-python](<https://devfeed.tech/tags/chainguard-libraries-for-python.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [language-libraries-malware](<https://devfeed.tech/tags/language-libraries-malware.md>), [malware-prevention](<https://devfeed.tech/tags/malware-prevention.md>), [malware-protection](<https://devfeed.tech/tags/malware-protection.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [python](<https://devfeed.tech/tags/python.md>), [python-libraries](<https://devfeed.tech/tags/python-libraries.md>), [secure-python-libraries](<https://devfeed.tech/tags/secure-python-libraries.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard Libraries for Python is generally available as a trusted-build distribution of open source Python libraries. It builds packages from source, distributes them through hardened infrastructure, continuously monitors them, and provides malware protection and CVE remediation through backported patches for selected critical and high-severity vulnerabilities.

### Source excerpt

Chainguard Libraries for Python, trusted open source language libraries designed for CVE remediation and malware protection, is now generally available.

## Discover the Value of Chainguard Containers with the Value Calculator

DevFeed: [Discover the Value of Chainguard Containers with the Value Calculator](<https://devfeed.tech/articles/discover-the-value-of-chainguard-containers-with-the-value-calculator-13020.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/discover-the-value-of-chainguard-containers-with-the-value-calculator>)

Published: 2025-08-28T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Tool](<https://devfeed.tech/topics/tool.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [business-value](<https://devfeed.tech/tags/business-value.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-roi](<https://devfeed.tech/tags/chainguard-roi.md>), [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [developers](<https://devfeed.tech/tags/developers.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [tool](<https://devfeed.tech/tags/tool.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

Chainguard introduces a self-serve Value Calculator that estimates the organizational value of adopting Chainguard Containers. The tool uses metrics such as developer count, revenue, container-image usage, CVE remediation time, hardening effort, organizational maturity, industry, and compliance requirements to estimate potential gains from reducing engineering toil, mitigating risk, and supporting revenue growth.

### Source excerpt

Chainguard's Value Calculator is a new tool we created to make it easy to quantify the value of using Chainguard Containers for your specific organization.

## Custom Assembly and Private APK Repositories are Now Generally Available

DevFeed: [Custom Assembly and Private APK Repositories are Now Generally Available](<https://devfeed.tech/articles/custom-assembly-and-private-apk-repositories-are-now-generally-available-13014.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/custom-assembly-and-private-apk-repositories-now-generally-available>)

Published: 2025-07-15T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [APK](<https://devfeed.tech/topics/apk.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [apk-repositories](<https://devfeed.tech/tags/apk-repositories.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [custom-assembly](<https://devfeed.tech/tags/custom-assembly.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [new-features](<https://devfeed.tech/tags/new-features.md>), [secure-image](<https://devfeed.tech/tags/secure-image.md>), [slsa](<https://devfeed.tech/tags/slsa.md>)

### AI overview

Chainguard announces the general availability of Custom Assembly and Private APK Repositories for Chainguard Containers. The features let customers customize container images, access Chainguard packages through customer-specific endpoints, and use Chainguard Factory for automated builds and ongoing maintenance.

### Source excerpt

Custom Assembly and Private APK Repositories, two new features for Chainguard Containers, are now generally available.

## The Business Costs of CVE Management and the Value of Chainguard Containers

DevFeed: [The Business Costs of CVE Management and the Value of Chainguard Containers](<https://devfeed.tech/articles/the-hidden-costs-of-cves-and-the-value-you-re-leaving-on-the-table-13257.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-hidden-costs-of-cves-and-the-value-youre-leaving-on-the-table>)

Published: 2025-06-23T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [cve remediation](<https://devfeed.tech/topics/cve-remediation.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [business-value-assessment](<https://devfeed.tech/tags/business-value-assessment.md>), [bva](<https://devfeed.tech/tags/bva.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [cves](<https://devfeed.tech/tags/cves.md>), [report](<https://devfeed.tech/tags/report.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article discusses the operational and business costs of managing CVEs in containerized software environments. It presents Chainguard's evaluation of customer benefits from using Chainguard Containers, including reported savings on CVE remediation and container-image hardening, as well as potential value from reduced security risk and redeployed engineering capacity.

### Source excerpt

Chainguard evaluated the amount of money customers are saving and unlocking by utilizing Chainguard Containers as their secure container image solution.

## One Year Later: Signing CISA's Secure by Design Pledge

DevFeed: [One Year Later: Signing CISA's Secure by Design Pledge](<https://devfeed.tech/articles/one-year-later-signing-cisa-s-secure-by-design-pledge-13194.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/one-year-update-to-signing-cisas-secure-by-design-pledge>)

Published: 2025-06-10T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [cve remediation](<https://devfeed.tech/topics/cve-remediation.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [Security](<https://devfeed.tech/topics/security.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [chainguard vms](<https://devfeed.tech/topics/chainguard-vms.md>), [ssh](<https://devfeed.tech/topics/ssh.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-vms](<https://devfeed.tech/tags/chainguard-vms.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [okta](<https://devfeed.tech/tags/okta.md>), [password](<https://devfeed.tech/tags/password.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [secure-by-design-pledge](<https://devfeed.tech/tags/secure-by-design-pledge.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [shift-left](<https://devfeed.tech/tags/shift-left.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [sso](<https://devfeed.tech/tags/sso.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

Chainguard reviews its progress one year after signing CISA's Secure by Design pledge, including CVE remediation across its container images, company-wide MFA through Okta SSO, and password-free access with automated SSH key provisioning for Chainguard VMs.

### Source excerpt

Chainguard signed CISA's Secure by Design pledge in 2024. One year later, we look at progress we've made in key areas like CVE remediation and disclosures.

## How R1 Universities Can Simplify CMMC 2.0 Compliance with Chainguard Containers

DevFeed: [How R1 Universities Can Simplify CMMC 2.0 Compliance with Chainguard Containers](<https://devfeed.tech/articles/how-r1-universities-can-simplify-cmmc-2-0-compliance-with-chainguard-containers-13093.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-r1-universities-can-simplify-cmmc-2-0-compliance-with-chainguard-containers>)

Published: 2025-06-04T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [systems](<https://devfeed.tech/topics/systems.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-factory](<https://devfeed.tech/tags/chainguard-factory.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [cmmc](<https://devfeed.tech/tags/cmmc.md>), [cmmc-2-0](<https://devfeed.tech/tags/cmmc-2-0.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [cves](<https://devfeed.tech/tags/cves.md>), [funding](<https://devfeed.tech/tags/funding.md>), [linux](<https://devfeed.tech/tags/linux.md>), [malware](<https://devfeed.tech/tags/malware.md>), [management](<https://devfeed.tech/tags/management.md>), [security](<https://devfeed.tech/tags/security.md>), [software](<https://devfeed.tech/tags/software.md>), [systems](<https://devfeed.tech/tags/systems.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

This article explains how Chainguard Containers may help R1 universities prepare for CMMC 2.0 Level 2 requirements tied to Department of Defense research contracts. It focuses on vulnerability-management controls, including timely identification, reporting, remediation, malware protection, and risk assessment, and describes Chainguard's minimal container images, Chainguard OS, and Chainguard Factory.

### Source excerpt

With CMMC 2.0 compliance becoming an important prerequisite to research funding for R1 universities, Chainguard Containers are the perfect solution. See how.

## This Shit is Hard: Inside the Chainguard Factory

DevFeed: [This Shit is Hard: Inside the Chainguard Factory](<https://devfeed.tech/articles/this-shit-is-hard-inside-the-chainguard-factory-13284.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/this-shit-is-hard-inside-the-chainguard-factory>)

Published: 2025-05-27T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Scalability](<https://devfeed.tech/topics/scalability.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [observability](<https://devfeed.tech/topics/observability.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [automation](<https://devfeed.tech/tags/automation.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-factory](<https://devfeed.tech/tags/chainguard-factory.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [linux](<https://devfeed.tech/tags/linux.md>), [observability](<https://devfeed.tech/tags/observability.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [scalability](<https://devfeed.tech/tags/scalability.md>), [speed](<https://devfeed.tech/tags/speed.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard describes how its Factory uses infrastructure, automation, and a custom Kubernetes-based build system to build and test thousands of packages and images. The article says the system replaced GitHub Actions and improved observability, scalability, and usability while supporting CVE remediation targets.

### Source excerpt

The Chainguard Factory combines world-class talent and automation to produce packages and images at a level of speed unmatched by any other Linux distribution.

## Chainguard's Catalog of 1,300+ Container Images: Secure Foundation for Every Engineering Team

DevFeed: [Chainguard's Catalog of 1,300+ Container Images: Secure Foundation for Every Engineering Team](<https://devfeed.tech/articles/chainguard-s-catalog-of-1-300-container-images-secure-foundation-for-every-engineering-team-12986.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguards-catalog-of-1-300-container-images-secure-foundation-for-every-engineering-team>)

Published: 2025-05-12T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-catalog](<https://devfeed.tech/tags/chainguard-catalog.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-factory](<https://devfeed.tech/tags/chainguard-factory.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [container](<https://devfeed.tech/tags/container.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [safe-source-for-open-source](<https://devfeed.tech/tags/safe-source-for-open-source.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [slsa](<https://devfeed.tech/tags/slsa.md>)

### AI overview

Chainguard describes its catalog of more than 1,300 minimal, zero-CVE container images, built from source on Chainguard OS and maintained through the Chainguard Factory. The article highlights daily rebuilds, automated dependency and CVE handling, and default SBOMs, SLSA provenance, and Sigstore signatures.

### Source excerpt

Chainguard Containers is a catalog of over 1,300 container images powered by Chainguard OS and the Chainguard Factory. Discover the safe source for open source.

## What FedRAMP 20x Means for You

DevFeed: [What FedRAMP 20x Means for You](<https://devfeed.tech/articles/what-fedramp-20x-means-for-you-13317.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/what-fedramp-20x-means-for-you>)

Published: 2025-04-02T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Automation](<https://devfeed.tech/topics/automation.md>), [authority to operate](<https://devfeed.tech/topics/authority-to-operate.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [cve remediation](<https://devfeed.tech/topics/cve-remediation.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [authority-to-operate](<https://devfeed.tech/tags/authority-to-operate.md>), [automation](<https://devfeed.tech/tags/automation.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [complexity](<https://devfeed.tech/tags/complexity.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cost](<https://devfeed.tech/tags/cost.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [cves](<https://devfeed.tech/tags/cves.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fedramp-20x](<https://devfeed.tech/tags/fedramp-20x.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article explains that FedRAMP 20x is intended to streamline the authority-to-operate process through automation and continuous validation. It says the core security and compliance controls are not changing and that the existing agency-based FedRAMP Rev. 5 authorization path remains active.

### Source excerpt

FedRAMP 20x is a new initiative designed to automate and simplify the FedRAMP process. Get the rundown on what is changing, and how Chainguard can help.

## Building .NET Runtime from Source - The Chainguard Way

DevFeed: [Building .NET Runtime from Source - The Chainguard Way](<https://devfeed.tech/articles/building-net-runtime-from-source-the-chainguard-way-12910.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/building-net-runtime-from-source-the-chainguard-way>)

Published: 2025-02-26T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [.NET](<https://devfeed.tech/topics/net.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>)

Tags: [built-from-source](<https://devfeed.tech/tags/built-from-source.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [integrity](<https://devfeed.tech/tags/integrity.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [net](<https://devfeed.tech/tags/net.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard describes building all .NET 8 and .NET 9 components entirely from source. The approach addresses challenges involving multiple repositories, circular dependencies, prebuilt binary dependencies, and cross-repository changes, while enabling faster CVE remediation, end-to-end integrity, and greater build transparency for .NET container images.

### Source excerpt

Chainguard builds all .NET8 and .NET9 components entirely from source to enable faster CVE remediation, full end-to-end integrity, and build transparency.

## Announcing Chainguard Custom Assembly: Image Customization Without Complexity

DevFeed: [Announcing Chainguard Custom Assembly: Image Customization Without Complexity](<https://devfeed.tech/articles/announcing-chainguard-custom-assembly-image-customization-without-complexity-12877.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/announcing-chainguard-custom-assembly-image-customization-without-complexity>)

Published: 2025-02-20T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Security](<https://devfeed.tech/topics/security.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [bash](<https://devfeed.tech/tags/bash.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-custom-assembly](<https://devfeed.tech/tags/chainguard-custom-assembly.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [complexity](<https://devfeed.tech/tags/complexity.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [curl](<https://devfeed.tech/tags/curl.md>), [custom-assembly](<https://devfeed.tech/tags/custom-assembly.md>), [customization](<https://devfeed.tech/tags/customization.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [development](<https://devfeed.tech/tags/development.md>), [docker](<https://devfeed.tech/tags/docker.md>), [image](<https://devfeed.tech/tags/image.md>), [integrity](<https://devfeed.tech/tags/integrity.md>), [maintenance](<https://devfeed.tech/tags/maintenance.md>), [no-vulnerabilities](<https://devfeed.tech/tags/no-vulnerabilities.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

Chainguard announces the beta release of Custom Assembly, a product for tailoring Chainguard Images with required packages while preserving hardened builds, security practices, and CVE remediation coverage. The article explains that the product addresses complex, maintenance-heavy customization workflows involving manual image changes, Docker builds, and proprietary pipelines.

### Source excerpt

Custom Assembly is Chainguard's new image customization product that enables companies to consume zero-CVE open source software tailored to unique requirements.

## Proposed HIPAA Security Rule Updates for Vulnerability Management

DevFeed: [Proposed HIPAA Security Rule Updates for Vulnerability Management](<https://devfeed.tech/articles/hipaa-s-new-vulnerability-management-guidelines-what-you-need-to-know-13081.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/hipaas-new-vulnerability-management-guidelines-what-you-need-to-know>)

Published: 2025-02-11T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [cve remediation](<https://devfeed.tech/topics/cve-remediation.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [cves](<https://devfeed.tech/tags/cves.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [hipaa](<https://devfeed.tech/tags/hipaa.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

The article explains proposed updates to HIPAA's Security Rule, including requirements for container security, risk analysis, data-security practices, and remediation of Common Vulnerabilities and Exposures (CVEs). It states that the proposal would require healthcare organizations to address Critical CVEs within 15 calendar days of discovery.

### Source excerpt

New guidelines for HIPAA's Security Rule have been proposed, which include updated requirements for vulnerability management, risk management, and more.

## Latest CVE patch report: Securing software supply chains

DevFeed: [Latest CVE patch report: Securing software supply chains](<https://devfeed.tech/articles/latest-cve-patch-report-securing-software-supply-chains-13140.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/latest-cve-patch-report-securing-software-supply-chains>)

Published: 2024-06-27T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [command-line](<https://devfeed.tech/tags/command-line.md>), [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2024-4603](<https://devfeed.tech/tags/cve-2024-4603.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [report](<https://devfeed.tech/tags/report.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard's latest CVE patch report describes how its remediation team patches vulnerabilities in Chainguard Images and Wolfi Packages, aiming to provide accurate scanner results and reduce false positives. It also examines CVE-2024-4603 in OpenSSL, which can cause denial-of-service attacks when untrusted, excessively large DSA parameters are checked.

### Source excerpt

Dive into our latest CVE patch report and see how Chainguard proactively mitigates vulnerabilities to enhance software supply chain security.

## Why Chainguard uses Grype as its first line of defense for CVEs

DevFeed: [Why Chainguard uses Grype as its first line of defense for CVEs](<https://devfeed.tech/articles/why-chainguard-uses-grype-as-its-first-line-of-defense-for-cves-13327.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/why-chainguard-uses-grype-as-its-first-line-of-defense-for-cves>)

Published: 2023-10-06T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [grype](<https://devfeed.tech/topics/grype.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Go](<https://devfeed.tech/topics/go.md>), [trivy](<https://devfeed.tech/topics/trivy.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [cves](<https://devfeed.tech/tags/cves.md>), [false-negative](<https://devfeed.tech/tags/false-negative.md>), [false-positive](<https://devfeed.tech/tags/false-positive.md>), [go](<https://devfeed.tech/tags/go.md>), [grype](<https://devfeed.tech/tags/grype.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [prisma-cloud](<https://devfeed.tech/tags/prisma-cloud.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [trivy](<https://devfeed.tech/tags/trivy.md>), [vex](<https://devfeed.tech/tags/vex.md>)

### AI overview

Chainguard explains why it selected Grype as the foundation of its internal vulnerability detection system. The article describes scanning early in the software delivery pipeline, using Grype as a Go library to scan Wolfi APK packages before container images are built, and contributing vulnerability data and improvements to the open-source project. It also briefly compares Grype's open data pipeline with Trivy's.

### Source excerpt

Chainguard harnesses Grype's open-source power to ensure minimal CVEs in images, prioritizing user security.

## Securing the ML supply chain with new Chainguard AI Images

DevFeed: [Securing the ML supply chain with new Chainguard AI Images](<https://devfeed.tech/articles/securing-the-ml-supply-chain-with-new-chainguard-ai-images-13225.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/securing-the-ml-supply-chain-with-new-chainguard-ai-images>)

Published: 2023-08-24T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Machine learning](<https://devfeed.tech/topics/machine-learning.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-ai](<https://devfeed.tech/tags/chainguard-ai.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [conda-image](<https://devfeed.tech/tags/conda-image.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [kubeflow-image](<https://devfeed.tech/tags/kubeflow-image.md>), [ml-security](<https://devfeed.tech/tags/ml-security.md>), [ml-supply-chain](<https://devfeed.tech/tags/ml-supply-chain.md>), [open-ai-image](<https://devfeed.tech/tags/open-ai-image.md>), [openai-image](<https://devfeed.tech/tags/openai-image.md>), [python-image](<https://devfeed.tech/tags/python-image.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-images](<https://devfeed.tech/tags/secure-images.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-signatures](<https://devfeed.tech/tags/software-signatures.md>)

### AI overview

Chainguard announces a Chainguard Images AI bundle for securing the ML supply chain across the AI workload lifecycle. The collection includes development, workflow management, deployment, and vector database images, with software signatures, SBOMs, and CVE remediation.

### Source excerpt

Chainguard AI Images: Your pathway to a secure ML supply chain with hardened, efficient AI/ML lifecycle solutions.