# distroless

Published articles for distroless.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Mitigating WordPress attacks with containers

DevFeed: [Mitigating WordPress attacks with containers](<https://devfeed.tech/articles/mitigating-wordpress-attacks-with-containers-13164.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/mitigating-wordpress-attacks-with-containers>)

Published: 2026-07-27T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [WordPress](<https://devfeed.tech/topics/wordpress.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [containers](<https://devfeed.tech/tags/containers.md>), [database](<https://devfeed.tech/tags/database.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [files](<https://devfeed.tech/tags/files.md>), [hardened-containers](<https://devfeed.tech/tags/hardened-containers.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [wordpress](<https://devfeed.tech/tags/wordpress.md>), [wordpress-cves](<https://devfeed.tech/tags/wordpress-cves.md>)

### AI overview

This article examines the wp2shell attack, in which two WordPress vulnerabilities can be chained to achieve remote code execution. It explains that hardened, distroless containers and read-only filesystems can limit an attacker's capabilities and simplify recovery, while emphasizing the need to update WordPress immediately.

### Source excerpt

The wp2shell WordPress exploit enables remote code execution. Learn how hardened containers help reduce the blast radius of compromise.

## Guardener automates migration from legacy Dockerfiles to secure Chainguard container images

DevFeed: [Guardener automates migration from legacy Dockerfiles to secure Chainguard container images](<https://devfeed.tech/articles/meet-guardener-the-intelligent-migration-expert-for-everyone-13154.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/meet-the-guardener>)

Published: 2026-03-17T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [AI Development](<https://devfeed.tech/topics/ai-development.md>), [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [migration](<https://devfeed.tech/topics/migration.md>), [Security](<https://devfeed.tech/topics/security.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [ai-migration-agents](<https://devfeed.tech/tags/ai-migration-agents.md>), [audit](<https://devfeed.tech/tags/audit.md>), [automation](<https://devfeed.tech/tags/automation.md>), [chainguard-ai-tools](<https://devfeed.tech/tags/chainguard-ai-tools.md>), [chainguard-guardener](<https://devfeed.tech/tags/chainguard-guardener.md>), [chainguard-the-guardener](<https://devfeed.tech/tags/chainguard-the-guardener.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [dockerfiles](<https://devfeed.tech/tags/dockerfiles.md>), [migration](<https://devfeed.tech/tags/migration.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard introduces Guardener, an AI-native agent that helps engineering teams migrate legacy Dockerfiles to minimal Chainguard container images. It gathers environmental context, rebuilds Dockerfiles layer by layer, tests the results, and provides post-migration insights on image size, CVEs, and filesystem changes.

### Source excerpt

Guardener is an AI-native agent that accelerates engineering teams' adoption of trusted open source artifacts across software development and deployment.

## Chainguard OS and the Next Generation of Distroless Software Delivery

DevFeed: [Chainguard OS and the Next Generation of Distroless Software Delivery](<https://devfeed.tech/articles/the-distroless-revolution-will-be-chainguarded-13249.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-distroless-revolution-will-be-chainguarded>)

Published: 2025-03-20T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [distroless](<https://devfeed.tech/topics/distroless.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>)

Tags: [beyond-distro](<https://devfeed.tech/tags/beyond-distro.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [chainguard-your-os](<https://devfeed.tech/tags/chainguard-your-os.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [security](<https://devfeed.tech/tags/security.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

This article proposes a next generation of open source software delivery centered on distroless, purpose-built container images and upstream-maintained software packages. It introduces Chainguard OS, which Chainguard describes as continuously rebuilding packages from upstream sources to incorporate security fixes and performance improvements.

### Source excerpt

Chainguard OS is the next generation in open source software delivery. Learn all about the principles and technology that make it possible.

## Have We Reached a Distroless Tipping Point?

DevFeed: [Have We Reached a Distroless Tipping Point?](<https://devfeed.tech/articles/have-we-reached-a-distroless-tipping-point-13080.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/have-we-reached-a-distroless-tipping-point>)

Published: 2025-03-18T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [distroless](<https://devfeed.tech/topics/distroless.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Linux](<https://devfeed.tech/topics/linux.md>)

Tags: [beyond-distro](<https://devfeed.tech/tags/beyond-distro.md>), [cgroups](<https://devfeed.tech/tags/cgroups.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [chainguard-your-os](<https://devfeed.tech/tags/chainguard-your-os.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [containers](<https://devfeed.tech/tags/containers.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [linux](<https://devfeed.tech/tags/linux.md>), [oci](<https://devfeed.tech/tags/oci.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

The article argues that containerization and cloud-native software development have created an inflection point in open source software delivery. It presents the evolution from Linux Containers to Docker and the Open Container Initiative as milestones supporting a shift from traditional Linux distributions toward distroless, secure-by-design, continuously updated software.

### Source excerpt

The world is at an inflection point in open source software delivery. See where the software distribution status quo is at, and what is next.

## 10 Docker Security Best Practices

DevFeed: [10 Docker Security Best Practices](<https://devfeed.tech/articles/10-docker-security-best-practices-7763.md>)

Original publisher: [Read original article](<https://snyk.io/blog/10-docker-image-security-best-practices/>)

Author: Liran Tal; Omer Levi Hevroni

Published: 2025-01-08T18:58:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Docker](<https://devfeed.tech/topics/docker.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [alpine](<https://devfeed.tech/tags/alpine.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [base-images](<https://devfeed.tech/tags/base-images.md>), [c](<https://devfeed.tech/tags/c.md>), [cheat-sheet](<https://devfeed.tech/tags/cheat-sheet.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [debian](<https://devfeed.tech/tags/debian.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [docker](<https://devfeed.tech/tags/docker.md>), [go](<https://devfeed.tech/tags/go.md>), [google](<https://devfeed.tech/tags/google.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [snyk-container](<https://devfeed.tech/tags/snyk-container.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article explains Docker security across image builds, container runtime, supply-chain risks, and orchestration. It presents best practices including using minimal or distroless base images, multi-stage builds, reducing attack surface, and running containers with the least privilege. It also references Docker Hub, Kubernetes, Helm, Alpine Linux, Go, C, Debian, Node, and Google distroless images.

### Source excerpt

Understand the basics of Docker security best practices with our Docker Cheat Sheet to improve container security.

## Check out Chainguard at KubeCon NA in Salt Lake City on November 12-15!

DevFeed: [Check out Chainguard at KubeCon NA in Salt Lake City on November 12-15!](<https://devfeed.tech/articles/check-out-chainguard-at-kubecon-na-in-salt-lake-city-on-november-12-15-13006.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/check-out-chainguard-at-kubecon-na-in-salt-lake-city-on-november-12-15>)

Published: 2024-10-16T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [distroless](<https://devfeed.tech/topics/distroless.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Security](<https://devfeed.tech/topics/security.md>), [devrel](<https://devfeed.tech/topics/devrel.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-native-rejekts](<https://devfeed.tech/tags/cloud-native-rejekts.md>), [conference](<https://devfeed.tech/tags/conference.md>), [container](<https://devfeed.tech/tags/container.md>), [debug](<https://devfeed.tech/tags/debug.md>), [developers](<https://devfeed.tech/tags/developers.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [event](<https://devfeed.tech/tags/event.md>), [kubecon](<https://devfeed.tech/tags/kubecon.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [multi-arch](<https://devfeed.tech/tags/multi-arch.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [sigstorecon](<https://devfeed.tech/tags/sigstorecon.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>)

### AI overview

Chainguard announces its participation in KubeCon North America 2024 in Salt Lake City, including product demonstrations of Chainguard Images and appearances at Cloud-Native Rejekts and SigstoreCon.

### Source excerpt

Chainguard is going to be at KubeCon North America 2024 in Salt Lake City. See where we'll be and how you can meet us to learn more about Chainguard Images.

## Avoid exploit chaining threats with Chainguard Images

DevFeed: [Avoid exploit chaining threats with Chainguard Images](<https://devfeed.tech/articles/avoid-exploit-chaining-threats-with-chainguard-images-12894.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/avoid-exploit-chaining-threats-with-chainguard-images>)

Published: 2024-04-23T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [Chrome](<https://devfeed.tech/topics/chrome.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [coding](<https://devfeed.tech/topics/coding.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [browsers](<https://devfeed.tech/tags/browsers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chrome](<https://devfeed.tech/tags/chrome.md>), [coding](<https://devfeed.tech/tags/coding.md>), [cve](<https://devfeed.tech/tags/cve.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [exploit-chaining](<https://devfeed.tech/tags/exploit-chaining.md>), [github](<https://devfeed.tech/tags/github.md>), [image-cve](<https://devfeed.tech/tags/image-cve.md>), [minimalism](<https://devfeed.tech/tags/minimalism.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [software](<https://devfeed.tech/tags/software.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article explains how attackers combine multiple low-severity vulnerabilities into exploit chains that can produce severe compromise. It uses examples involving Pwn2Own devices and a Chrome renderer RCE analysis to emphasize risks from complex software interactions, memory management, and sandbox escapes, and it presents Chainguard Images and secure coding as defensive considerations.

### Source excerpt

Understand exploit chaining -- linking vulnerabilities for devastating attacks. Learn defense strategies with Chainguard Images and secure coding practices.

## A more secure (and smaller) Big Bang

DevFeed: [A more secure (and smaller) Big Bang](<https://devfeed.tech/articles/a-more-secure-and-smaller-big-bang-12859.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/a-more-secure-and-smaller-big-bang>)

Published: 2024-04-09T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [big-bang](<https://devfeed.tech/tags/big-bang.md>), [certificate-to-field](<https://devfeed.tech/tags/certificate-to-field.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [ctf](<https://devfeed.tech/tags/ctf.md>), [cves](<https://devfeed.tech/tags/cves.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [hardened-container-image](<https://devfeed.tech/tags/hardened-container-image.md>), [iron-bank](<https://devfeed.tech/tags/iron-bank.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [platform-one](<https://devfeed.tech/tags/platform-one.md>), [releases](<https://devfeed.tech/tags/releases.md>), [united-states-air-force](<https://devfeed.tech/tags/united-states-air-force.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard is working with Iron Bank to mirror Chainguard Images for the core Big Bang images, offering a drop-in alternative for Big Bang's secure software factory. The article reports a 100% reduction in CVEs, a 40% reduction in software components, and a 72% reduction in image size, with more than 30 images covering all eight core components.

### Source excerpt

Chainguard enhances Big Bang with secure, smaller images: 100% fewer CVEs, 40% less components, 72% size reduction for fortified security.

## Building minimal and low CVE images for compiled languages

DevFeed: [Building minimal and low CVE images for compiled languages](<https://devfeed.tech/articles/building-minimal-and-low-cve-images-for-compiled-languages-12906.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/building-minimal-and-low-cve-images-for-compiled-languages>)

Published: 2024-02-27T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Docker Hub](<https://devfeed.tech/topics/docker-hub.md>), [Debian](<https://devfeed.tech/topics/debian.md>), [Ubuntu](<https://devfeed.tech/topics/ubuntu.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [compiled-language](<https://devfeed.tech/tags/compiled-language.md>), [containers](<https://devfeed.tech/tags/containers.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-hub](<https://devfeed.tech/tags/docker-hub.md>), [dockerfiles](<https://devfeed.tech/tags/dockerfiles.md>), [dockerhub](<https://devfeed.tech/tags/dockerhub.md>), [go](<https://devfeed.tech/tags/go.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article demonstrates how to build smaller, lower-CVE container images for compiled languages by separating build and runtime concerns and replacing full Debian or Ubuntu bases with Chainguard Images. A Go web server example reduces the image from 892 MB to 775 MB and eliminates the reported CVEs after a one-line base-image change.

### Source excerpt

Leverage Chainguard's insights to forge low-CVE, compact images for compiled languages, boosting your security posture.

## Images as Code: The pursuit of declarative image builds

DevFeed: [Images as Code: The pursuit of declarative image builds](<https://devfeed.tech/articles/images-as-code-the-pursuit-of-declarative-image-builds-13101.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/images-as-code-the-pursuit-of-declarative-image-builds>)

Published: 2024-01-22T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Code](<https://devfeed.tech/topics/code.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [bazel](<https://devfeed.tech/topics/bazel.md>), [distroless](<https://devfeed.tech/topics/distroless.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>), [Infrastructure as code](<https://devfeed.tech/topics/infrastructure-as-code.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [apk](<https://devfeed.tech/tags/apk.md>), [apko](<https://devfeed.tech/tags/apko.md>), [bazel](<https://devfeed.tech/tags/bazel.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [code](<https://devfeed.tech/tags/code.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [containers](<https://devfeed.tech/tags/containers.md>), [declarative](<https://devfeed.tech/tags/declarative.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [docker](<https://devfeed.tech/tags/docker.md>), [infrastructure-as-code](<https://devfeed.tech/tags/infrastructure-as-code.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [reproducibility](<https://devfeed.tech/tags/reproducibility.md>), [terraform](<https://devfeed.tech/tags/terraform.md>)

### AI overview

The article traces the pursuit of declarative container image builds. It critiques imperative Dockerfile-based builds for making multi-tenant, multi-architecture, and reproducible builds difficult, then discusses Bazel and distroless images as steps toward expressing intended build state. Kubernetes and Terraform are presented as examples of declarative systems, inspiring the idea of "Images as Code."

### Source excerpt

Chainguard's CTO Matt Moore describes the process of creating a declarative container image build for Chainguard Images.

## Announcing Bazel rules for extending Chainguard Images

DevFeed: [Announcing Bazel rules for extending Chainguard Images](<https://devfeed.tech/articles/announcing-bazel-rules-for-extending-chainguard-images-12875.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/announcing-bazel-rules-for-extending-chainguard-images>)

Published: 2023-10-24T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [distroless](<https://devfeed.tech/topics/distroless.md>), [Package manager](<https://devfeed.tech/topics/package-manager.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [apk](<https://devfeed.tech/tags/apk.md>), [apko](<https://devfeed.tech/tags/apko.md>), [bazel](<https://devfeed.tech/tags/bazel.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [secure-software-supply-chain](<https://devfeed.tech/tags/secure-software-supply-chain.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard and Aspect.Dev announce the general availability of rules_apko, an open source Bazel plugin for building secure, minimal Wolfi-based OCI container images. The article explains how rules_apko integrates APK packages and Wolfi-base images into existing Bazel workflows, supports reproducible builds, and provides dependency locking, integrity verification, and SBOM generation.

### Source excerpt

Explore Bazel rules for Chainguard Images, your pathway to secure, effortless image extension.

## Understanding attacker techniques in distroless containers

DevFeed: [Understanding attacker techniques in distroless containers](<https://devfeed.tech/articles/understanding-attacker-techniques-in-distroless-containers-13300.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/understanding-attacker-techniques-in-distroless-containers>)

Published: 2023-10-05T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [distroless](<https://devfeed.tech/topics/distroless.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Security](<https://devfeed.tech/topics/security.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [containers](<https://devfeed.tech/tags/containers.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [distroless-containers](<https://devfeed.tech/tags/distroless-containers.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [rce](<https://devfeed.tech/tags/rce.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article examines attacker techniques relevant to distroless containers, drawing on a DEFCON 31 talk and an example involving PHP remote code execution, reverse shells, and injected spam content. It emphasizes keeping software up to date and using defense in depth.

### Source excerpt

Explore DEFCON 31 insights on Distroless container security. Delve into RCE vulnerabilities and Chainguard's robust defense strategies for up-to-date software.

## How to use Dockerfiles with wolfi-base images

DevFeed: [How to use Dockerfiles with wolfi-base images](<https://devfeed.tech/articles/how-to-use-dockerfiles-with-wolfi-base-images-13097.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-to-use-dockerfiles-with-wolfi-base-images>)

Published: 2023-09-14T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [distroless](<https://devfeed.tech/topics/distroless.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Go](<https://devfeed.tech/topics/go.md>)

Tags: [apko](<https://devfeed.tech/tags/apko.md>), [base-images](<https://devfeed.tech/tags/base-images.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-hub](<https://devfeed.tech/tags/docker-hub.md>), [dockerfiles](<https://devfeed.tech/tags/dockerfiles.md>), [go](<https://devfeed.tech/tags/go.md>), [guide](<https://devfeed.tech/tags/guide.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [melange](<https://devfeed.tech/tags/melange.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

This tutorial explains how to use Dockerfiles with Chainguard wolfi-base and other Chainguard Images. It covers minimal static images, glibc-dynamic images, multi-stage builds, package management, and selecting image variants based on application dependencies and runtime needs.

### Source excerpt

Your guide to leveraging Dockerfiles with Wolfi-base images for hardened container images.

## Celebrating 5 years of NTIA's SBOM work

DevFeed: [Celebrating 5 years of NTIA's SBOM work](<https://devfeed.tech/articles/celebrating-5-years-of-ntia-s-sbom-work-12919.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/celebrating-5-years-of-ntias-sbom-work>)

Published: 2023-06-07T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [distroless](<https://devfeed.tech/topics/distroless.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [openvex](<https://devfeed.tech/tags/openvex.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-dark-matter](<https://devfeed.tech/tags/software-dark-matter.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [sofware-supply-chain](<https://devfeed.tech/tags/sofware-supply-chain.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>), [vex](<https://devfeed.tech/tags/vex.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

The article commemorates five years of the NTIA's Software Bill of Materials work and reviews the development of SBOMs as a foundation of software supply chain security. It describes the NTIA's initiative, its multi-stakeholder guidelines, and CISA's continuing role in advancing software transparency.

### Source excerpt

Celebrate 5 transformative years of SBOM work with Chainguard, reflecting on the journey of software bill of materials.

## Chainguard Image now available for prometheus

DevFeed: [Chainguard Image now available for prometheus](<https://devfeed.tech/articles/chainguard-image-now-available-for-prometheus-12950.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-image-now-available-for-prometheus>)

Published: 2023-04-14T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Prometheus](<https://devfeed.tech/topics/prometheus.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Go](<https://devfeed.tech/topics/go.md>), [Documentation](<https://devfeed.tech/topics/documentation.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [cosign](<https://devfeed.tech/tags/cosign.md>), [cves](<https://devfeed.tech/tags/cves.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [documentation](<https://devfeed.tech/tags/documentation.md>), [go](<https://devfeed.tech/tags/go.md>), [image](<https://devfeed.tech/tags/image.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [prometheus](<https://devfeed.tech/tags/prometheus.md>), [prometheus-image](<https://devfeed.tech/tags/prometheus-image.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [security](<https://devfeed.tech/tags/security.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [toolchain](<https://devfeed.tech/tags/toolchain.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard announces a Prometheus container image built on Wolfi with a minimal, distroless-style base, hardened toolchain, continuous patching, and fewer reported CVEs. The image includes a default configuration, source-built binaries, SBOMs, signatures, and provenance support.

### Source excerpt

Check out the new Chainguard Image for Prometheus that is minimal in size and contains fewer CVEs than other alternatives.

## It all started with a commit: Celebrating 6 years of Distroless

DevFeed: [It all started with a commit: Celebrating 6 years of Distroless](<https://devfeed.tech/articles/it-all-started-with-a-commit-celebrating-6-years-of-distroless-13129.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/it-all-started-with-a-commit-celebrating-6-years-of-distroless>)

Published: 2023-04-12T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [distroless](<https://devfeed.tech/topics/distroless.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [bazel](<https://devfeed.tech/topics/bazel.md>), [Debian](<https://devfeed.tech/topics/debian.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Go](<https://devfeed.tech/topics/go.md>)

Tags: [bazel](<https://devfeed.tech/tags/bazel.md>), [c-plus-plus](<https://devfeed.tech/tags/c-plus-plus.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [debian](<https://devfeed.tech/tags/debian.md>), [digital-signatures](<https://devfeed.tech/tags/digital-signatures.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [distroless-containers](<https://devfeed.tech/tags/distroless-containers.md>), [go](<https://devfeed.tech/tags/go.md>), [java](<https://devfeed.tech/tags/java.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [python](<https://devfeed.tech/tags/python.md>), [release-engineering](<https://devfeed.tech/tags/release-engineering.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [verify](<https://devfeed.tech/tags/verify.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

The article commemorates six years of Distroless, describing its goal of creating more secure and efficient container images by removing non-essential components. It covers the Bazel-based build tooling, language runtimes, Kubernetes adoption, vulnerability-management benefits, and later integration with Sigstore for container signing and authenticity verification. It also introduces the subsequent development of Chainguard Images.

### Source excerpt

The goal of Distroless is to provide a more secure and efficient way to package and run software in containers by using only essential components.

## apko: a year later

DevFeed: [apko: a year later](<https://devfeed.tech/articles/apko-a-year-later-12887.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/apko-a-year-later>)

Published: 2023-02-28T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Development](<https://devfeed.tech/topics/development.md>), [Package manager](<https://devfeed.tech/topics/package-manager.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Unix](<https://devfeed.tech/topics/unix.md>), [YAML](<https://devfeed.tech/topics/yaml.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>)

Tags: [alpine](<https://devfeed.tech/tags/alpine.md>), [apk](<https://devfeed.tech/tags/apk.md>), [apko](<https://devfeed.tech/tags/apko.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-enforce](<https://devfeed.tech/tags/chainguard-enforce.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [development](<https://devfeed.tech/tags/development.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [golang](<https://devfeed.tech/tags/golang.md>), [linux](<https://devfeed.tech/tags/linux.md>), [macos](<https://devfeed.tech/tags/macos.md>), [melange](<https://devfeed.tech/tags/melange.md>), [secure-software-supply-chain](<https://devfeed.tech/tags/secure-software-supply-chain.md>), [terraform-provider](<https://devfeed.tech/tags/terraform-provider.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>), [yaml](<https://devfeed.tech/tags/yaml.md>)

### AI overview

This article reviews apko one year after its public release. It describes apko's native Go implementation of the apk package manager, which runs on UNIX-like systems including macOS and BSDs, and explains how its declarative YAML interface helped support an ecosystem that includes Chainguard Images, Melange, Wolfi, and a Terraform provider. The article presents apko as a foundation for secure software supply chains through images-as-code and frequent image rebuilds.

### Source excerpt

Dive in to apko and learn more about the project; where it's been in the past year, and where it's going.