# hardened image

Published articles for hardened image.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## STIG hardening container images

DevFeed: [STIG hardening container images](<https://devfeed.tech/articles/stig-hardening-container-images-13239.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/stig-hardening-container-images>)

Published: 2024-06-07T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [container-security](<https://devfeed.tech/topics/container-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [containers](<https://devfeed.tech/tags/containers.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [hardened-image](<https://devfeed.tech/tags/hardened-image.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [security](<https://devfeed.tech/tags/security.md>), [security-technical-implementation-guide](<https://devfeed.tech/tags/security-technical-implementation-guide.md>), [stig](<https://devfeed.tech/tags/stig.md>), [stig-hardening](<https://devfeed.tech/tags/stig-hardening.md>)

### AI overview

The article discusses hardening container images against STIG requirements, including how to distinguish controls that apply to containers from those that apply to the host operating system or Docker service. It also notes that false positives can occur in container security scans.

### Source excerpt

Dive into the world of STIG hardening for container images. Explore expert insights, practical tips, and Chainguard solutions to fortify your container security.

## Fortify, comply and conquer FedRAMP with Chainguard Images

DevFeed: [Fortify, comply and conquer FedRAMP with Chainguard Images](<https://devfeed.tech/articles/fortify-comply-and-conquer-fedramp-with-chainguard-images-13052.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/fortify-comply-and-conquer-fedramp-with-chainguard-images>)

Published: 2023-05-25T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Linux](<https://devfeed.tech/topics/linux.md>)

Tags: [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cve](<https://devfeed.tech/tags/cve.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fips](<https://devfeed.tech/tags/fips.md>), [hardened-image](<https://devfeed.tech/tags/hardened-image.md>), [linux](<https://devfeed.tech/tags/linux.md>), [nist](<https://devfeed.tech/tags/nist.md>), [secure-container-image](<https://devfeed.tech/tags/secure-container-image.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

This article explains how Chainguard Images can help cloud service providers and federal agencies achieve or maintain FedRAMP authorization. It describes FedRAMP requirements for hardened container images, recurring vulnerability scanning, NVD identifiers, CVSSv3 scores, and vulnerability remediation tracking. It presents Chainguard Images as secure, continuously updated base images built from source on the hardened Wolfi Linux un-distribution.

### Source excerpt

Learn how Chainguard Images can you achieve or maintain your FedRAMP compliance authorization with secure-by-default base images.

## Building Chainguard's container image registry

DevFeed: [Building Chainguard's container image registry](<https://devfeed.tech/articles/building-chainguard-s-container-image-registry-12903.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/building-chainguards-container-image-registry>)

Published: 2023-05-23T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [Cloudflare](<https://devfeed.tech/topics/cloudflare.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-image-registry](<https://devfeed.tech/tags/chainguard-image-registry.md>), [cloudflare](<https://devfeed.tech/tags/cloudflare.md>), [container](<https://devfeed.tech/tags/container.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [container-image-registry](<https://devfeed.tech/tags/container-image-registry.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [github-container-registry](<https://devfeed.tech/tags/github-container-registry.md>), [hardened-image](<https://devfeed.tech/tags/hardened-image.md>), [minimal-image](<https://devfeed.tech/tags/minimal-image.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [registry](<https://devfeed.tech/tags/registry.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [secure-container-images](<https://devfeed.tech/tags/secure-container-images.md>), [secure-images](<https://devfeed.tech/tags/secure-images.md>), [secure-minimal-image](<https://devfeed.tech/tags/secure-minimal-image.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>)

### AI overview

Chainguard explains why it built its own passwordless container image registry to improve security, control distribution, and manage costs. The registry is built on Cloudflare R2, uses short-lived OIDC credentials, and allows GitHub Actions workflows--not individual employees--to push images.

### Source excerpt

We built a passwordless container image registry with a focus on security to sustain the foundation for ongoing product growth & feature additions for our users.