# hardened images

Published articles for hardened images.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Managing third-party images at scale

DevFeed: [Managing third-party images at scale](<https://devfeed.tech/articles/managing-third-party-images-at-scale-13147.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/managing-third-party-images-at-scale>)

Published: 2026-04-16T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [container images](<https://devfeed.tech/topics/container-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [code productivity](<https://devfeed.tech/topics/code-productivity.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [appian](<https://devfeed.tech/tags/appian.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [developer-velocity](<https://devfeed.tech/tags/developer-velocity.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [scale](<https://devfeed.tech/tags/scale.md>), [security](<https://devfeed.tech/tags/security.md>), [third-party-container-images](<https://devfeed.tech/tags/third-party-container-images.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article explains how Appian approached managing third-party container images at scale with Chainguard. It describes the operational burden caused by image dependencies, vulnerabilities, maintenance, and compliance requirements, including the ongoing work needed for regulated environments such as FedRAMP. It also estimates that building a complete internal hardened-image program would require a dedicated team of 15 to 20 engineers.

### Source excerpt

Learn how companies can scale third-party container image management with Chainguard to reduce risk, cut toil, and accelerate compliance and developer velocity.

## How I learned to stop worrying and love the latest tag

DevFeed: [How I learned to stop worrying and love the latest tag](<https://devfeed.tech/articles/how-i-learned-to-stop-worrying-and-love-the-latest-tag-13090.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-i-learned-to-stop-worrying-and-love-the-latest-tag>)

Published: 2026-02-11T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [container images](<https://devfeed.tech/topics/container-images.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Docker Hardened Images](<https://devfeed.tech/topics/docker-hardened-images.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [YAML](<https://devfeed.tech/topics/yaml.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-automations](<https://devfeed.tech/tags/chainguard-automations.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-factory](<https://devfeed.tech/tags/chainguard-factory.md>), [container-image-digests](<https://devfeed.tech/tags/container-image-digests.md>), [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [digestabot](<https://devfeed.tech/tags/digestabot.md>), [digests](<https://devfeed.tech/tags/digests.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-hardened-images](<https://devfeed.tech/tags/docker-hardened-images.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [latest-tag](<https://devfeed.tech/tags/latest-tag.md>), [reproducibility](<https://devfeed.tech/tags/reproducibility.md>)

### AI overview

The article explains how to use the latest tag as part of a secure container image update strategy. It recommends pinning images to cryptographic digests to ensure reproducibility, enable reliable rollbacks, and prevent unexpected version changes, while retaining tags for readability and tooling. It also introduces automated workflows for finding and updating digests.

### Source excerpt

The latest tag isn't unsafe by default -- pin images to digests for reproducible, secure updates while staying current with automated workflows.

## Why Trusted Software Supply Chains Matter More Than Zero-CVE Container Claims

DevFeed: [Why Trusted Software Supply Chains Matter More Than Zero-CVE Container Claims](<https://devfeed.tech/articles/well-that-escalated-quickly-zero-cves-lots-of-vendors-13314.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/well-that-escalated-quickly-zero-cves-lots-of-vendors>)

Published: 2026-01-15T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Docker Hub](<https://devfeed.tech/topics/docker-hub.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [ceo](<https://devfeed.tech/tags/ceo.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-hub](<https://devfeed.tech/tags/docker-hub.md>), [docker-images](<https://devfeed.tech/tags/docker-images.md>), [echo-security](<https://devfeed.tech/tags/echo-security.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [minimus](<https://devfeed.tech/tags/minimus.md>), [rapidfort](<https://devfeed.tech/tags/rapidfort.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [wiz-images](<https://devfeed.tech/tags/wiz-images.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

Chainguard CEO Dan Lorenc argues that container security depends on trusting the origins and build processes of software, rather than relying primarily on post-hoc image hardening or zero-CVE claims.

### Source excerpt

Chainguard CEO Dan Lorenc explains why real security comes from trusted, from-source software supply chains, not post-hoc hardening or zero-CVE promises.

## How Collaboration.Ai Saved 2 Years and $2 Million with Chainguard, Second Front, and AWS

DevFeed: [How Collaboration.Ai Saved 2 Years and $2 Million with Chainguard, Second Front, and AWS](<https://devfeed.tech/articles/how-collaboration-ai-saved-2-years-and-2-million-with-chainguard-second-front-and-aws-13085.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-collaboration-ai-saved-2-years-and-2-million-with-chainguard-second-front-and-aws>)

Published: 2025-07-23T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>)

Tags: [ato](<https://devfeed.tech/tags/ato.md>), [authority-to-operate](<https://devfeed.tech/tags/authority-to-operate.md>), [aws](<https://devfeed.tech/tags/aws.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cost](<https://devfeed.tech/tags/cost.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fedramp-ato](<https://devfeed.tech/tags/fedramp-ato.md>), [fedramp-containers](<https://devfeed.tech/tags/fedramp-containers.md>), [govcloud](<https://devfeed.tech/tags/govcloud.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [secondfront](<https://devfeed.tech/tags/secondfront.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Collaboration.Ai used Chainguard Containers, Second Front's Game Warden platform, and AWS GovCloud to accelerate CrowdVector's path toward DoD compliance. The combination reduced vulnerabilities by 97% and lowered compliance costs by $2 million.

### Source excerpt

Collaboraton.AI used a combination of Chainguard Containers, Second Front, and AWS to reduce vulnerabilities by 97% and lower compliance costs by $2 million.

## Chainguard x Azul: Secure Java Containers without Compromise

DevFeed: [Chainguard x Azul: Secure Java Containers without Compromise](<https://devfeed.tech/articles/chainguard-x-azul-secure-java-containers-without-compromise-12930.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-azul-secure-java-containers-without-compromise>)

Published: 2025-06-12T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Java](<https://devfeed.tech/topics/java.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [azul](<https://devfeed.tech/tags/azul.md>), [catalog](<https://devfeed.tech/tags/catalog.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [containers](<https://devfeed.tech/tags/containers.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [java](<https://devfeed.tech/tags/java.md>), [java-container-images](<https://devfeed.tech/tags/java-container-images.md>), [openjdk](<https://devfeed.tech/tags/openjdk.md>), [partnership](<https://devfeed.tech/tags/partnership.md>), [productivity](<https://devfeed.tech/tags/productivity.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>)

### AI overview

Chainguard announces a partnership with Azul to offer curated Azul OpenJDK distributions in the Chainguard Catalog. The distributions are built from Azul source code in the Chainguard Factory and delivered as minimal, zero-CVE container images with commercial support, Java compatibility testing, and security testing.

### Source excerpt

We're excited to announce a strategic partnership with Azul that brings its curated OpenJDK® distributions to the Chainguard Catalog.

## Build a golden image program with Chainguard Images and JFrog Artifactory and Xray

DevFeed: [Build a golden image program with Chainguard Images and JFrog Artifactory and Xray](<https://devfeed.tech/articles/build-a-golden-image-program-with-chainguard-images-and-jfrog-artifactory-and-xray-12899.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/build-a-golden-image-program-with-chainguard-images-and-jfrog-artifactory-and-xray>)

Published: 2024-07-09T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [container-security](<https://devfeed.tech/topics/container-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Platform Engineering](<https://devfeed.tech/topics/platform-engineering.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [DevOps](<https://devfeed.tech/topics/devops.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [build](<https://devfeed.tech/tags/build.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container](<https://devfeed.tech/tags/container.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cves](<https://devfeed.tech/tags/cves.md>), [developers](<https://devfeed.tech/tags/developers.md>), [development](<https://devfeed.tech/tags/development.md>), [devops](<https://devfeed.tech/tags/devops.md>), [golden-image](<https://devfeed.tech/tags/golden-image.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [integration](<https://devfeed.tech/tags/integration.md>), [jfrog](<https://devfeed.tech/tags/jfrog.md>), [jfrog-artifactory](<https://devfeed.tech/tags/jfrog-artifactory.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [safe-source-for-open-source](<https://devfeed.tech/tags/safe-source-for-open-source.md>), [xray](<https://devfeed.tech/tags/xray.md>)

### AI overview

The article explains how to build a secure golden image program by combining Chainguard Images with JFrog Artifactory and Xray. It describes using hardened container images, centralized artifact management, continuous vulnerability scanning, and a curated open source catalog to support platform and DevOps teams.

### Source excerpt

Learn how to create a secure and streamlined golden image program with Chainguard Images, JFrog Artifactory, and Xray.

## Chainguard Images now available on Docker Hub

DevFeed: [Chainguard Images now available on Docker Hub](<https://devfeed.tech/articles/chainguard-images-now-available-on-docker-hub-12957.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-images-now-available-on-docker-hub>)

Published: 2024-03-14T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Docker Hub](<https://devfeed.tech/topics/docker-hub.md>), [Docker Verified Publisher](<https://devfeed.tech/topics/docker-verified-publisher.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [developer](<https://devfeed.tech/tags/developer.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-hub](<https://devfeed.tech/tags/docker-hub.md>), [docker-hub-verified-publisher](<https://devfeed.tech/tags/docker-hub-verified-publisher.md>), [docker-verified-publisher](<https://devfeed.tech/tags/docker-verified-publisher.md>), [dockerhub](<https://devfeed.tech/tags/dockerhub.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [verified-publisher](<https://devfeed.tech/tags/verified-publisher.md>)

### AI overview

Chainguard Images are now available on Docker Hub after Chainguard joined the Docker Verified Publisher program. The partnership gives developers access to minimal, secure, hardened images for open source and cloud-native projects, with guidance for finding and pulling verified images.

### Source excerpt

Chainguard Images joins Docker Hub as a Verified Publisher, offering developers secure, hardened images for open source projects.

## Unlocking Chainguard's container security solutions

DevFeed: [Unlocking Chainguard's container security solutions](<https://devfeed.tech/articles/unlocking-chainguard-s-container-security-solutions-13304.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/unlocking-chainguards-container-security-solutions>)

Published: 2024-03-05T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Docker Hardened Images](<https://devfeed.tech/topics/docker-hardened-images.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-fatigue](<https://devfeed.tech/tags/cve-fatigue.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

This article discusses Chainguard's approach to container security, focusing on minimal hardened container images, SBOMs, signatures, vulnerability scanning, continuous monitoring, and updates. It also considers the operational trade-offs between building container images internally and using managed solutions.

### Source excerpt

Uncover insights on whether to build or buy in container lifecycle management with tips from Chainguard, balancing security and operational needs.

## Continuous hardening of Chainguard's internal software supply chain

DevFeed: [Continuous hardening of Chainguard's internal software supply chain](<https://devfeed.tech/articles/continuous-hardening-of-chainguard-s-internal-software-supply-chain-13013.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/continuous-hardening-of-chainguards-internal-software-supply-chain>)

Published: 2024-02-21T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [Security](<https://devfeed.tech/topics/security.md>), [Docker Compose](<https://devfeed.tech/topics/docker-compose.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cosign](<https://devfeed.tech/tags/cosign.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [github-vulnerability](<https://devfeed.tech/tags/github-vulnerability.md>), [hardending](<https://devfeed.tech/tags/hardending.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [integrity](<https://devfeed.tech/tags/integrity.md>), [least-privilege](<https://devfeed.tech/tags/least-privilege.md>), [minimalism](<https://devfeed.tech/tags/minimalism.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [terraform-provider](<https://devfeed.tech/tags/terraform-provider.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard describes how it mitigated a potentially vulnerable GitHub Actions workflow that could have affected the integrity of Docker images signed by its cosign Terraform Provider. The team responded within 24 hours and explains how least privilege, minimal defaults, and dependency minimization support software supply chain security.

### Source excerpt

See how Chainguard mitigated the potential vulnerable GitHub actions workflow "Pwn request" in less than 24 hours.

## The incremental path to container images: Chainguard Images

DevFeed: [The incremental path to container images: Chainguard Images](<https://devfeed.tech/articles/the-incremental-path-to-container-images-chainguard-images-13259.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-incremental-path-to-container-images-chainguard-images>)

Published: 2023-11-28T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [alpine](<https://devfeed.tech/tags/alpine.md>), [apk](<https://devfeed.tech/tags/apk.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [distroless-containers](<https://devfeed.tech/tags/distroless-containers.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [helm](<https://devfeed.tech/tags/helm.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kyverno](<https://devfeed.tech/tags/kyverno.md>), [prometheus](<https://devfeed.tech/tags/prometheus.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article explains an incremental approach to migrating existing container images to Chainguard Images. It recommends starting with hardened Application Images that can often be adopted as drop-in replacements, then progressing toward Base Images.

### Source excerpt

Explore how easy it is to migrate existing container images to Chainguard Images, whether you are adopting Application Images or Base Images.

## Can debloated containers pass the zero CVE test?

DevFeed: [Can debloated containers pass the zero CVE test?](<https://devfeed.tech/articles/can-debloated-containers-pass-the-zero-cve-test-12915.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/can-debloated-containers-pass-the-zero-cve-test>)

Published: 2023-11-20T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Containers](<https://devfeed.tech/topics/containers.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [grype](<https://devfeed.tech/topics/grype.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cves](<https://devfeed.tech/tags/cves.md>), [grype](<https://devfeed.tech/tags/grype.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security-research](<https://devfeed.tech/tags/software-supply-chain-security-research.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

The article analyzes 28 debloated container images and finds that they reduce CVEs by an average of 64% compared with baseline images, but still contain an average of 33 CVEs. It also reports an average of five high or critical vulnerabilities, concluding that debloated containers do not pass the zero-CVE test. The comparison uses Grype and includes Chainguard Images versions.

### Source excerpt

Exploring the efficiency of debloated containers in the Zero CVE test: Chaingaurd's analysis of security and efficiency.

## Reproducing Chainguard's reproducible image builds

DevFeed: [Reproducing Chainguard's reproducible image builds](<https://devfeed.tech/articles/reproducing-chainguard-s-reproducible-image-builds-13211.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/reproducing-chainguards-reproducible-image-builds>)

Published: 2023-07-05T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>)

Tags: [apko](<https://devfeed.tech/tags/apko.md>), [attestation](<https://devfeed.tech/tags/attestation.md>), [build](<https://devfeed.tech/tags/build.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [cosign](<https://devfeed.tech/tags/cosign.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [locks](<https://devfeed.tech/tags/locks.md>), [reproducibility](<https://devfeed.tech/tags/reproducibility.md>), [reproducible-builds](<https://devfeed.tech/tags/reproducible-builds.md>), [secure-image](<https://devfeed.tech/tags/secure-image.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

A tutorial explaining how to reproduce a Chainguard Images build using cosign and apko. It describes locking image configurations and notes caveats involving tooling changes and withdrawn packages.

### Source excerpt

Learn how to reproduce a Chainguard Images build using cosign and apko.

## Enforce against vulnerability sprawl with up-to-date images

DevFeed: [Enforce against vulnerability sprawl with up-to-date images](<https://devfeed.tech/articles/enforce-against-vulnerability-sprawl-with-up-to-date-images-13028.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/enforce-against-vulnerability-sprawl-with-up-to-date-images>)

Published: 2023-05-03T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Docker Hub](<https://devfeed.tech/topics/docker-hub.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [development](<https://devfeed.tech/tags/development.md>), [docker-hub](<https://devfeed.tech/tags/docker-hub.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [image-scanning](<https://devfeed.tech/tags/image-scanning.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

This article reports on a 60-day Chainguard analysis comparing vulnerability accumulation in six popular Docker Hub images with six equivalent Chainguard Images. It recommends frequent image rebuilds and minimal, hardened containers to reduce vulnerability sprawl, security risk, and triage effort.

### Source excerpt

60-day study by Chainguard reveals vulnerability differences in Docker Hub vs. Chainguard Images.

## Chainguard Image now available for NATS

DevFeed: [Chainguard Image now available for NATS](<https://devfeed.tech/articles/chainguard-image-now-available-for-nats-12948.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-image-now-available-for-nats>)

Published: 2023-03-27T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Messaging](<https://devfeed.tech/topics/messaging.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cli](<https://devfeed.tech/tags/cli.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cosign](<https://devfeed.tech/tags/cosign.md>), [documentation](<https://devfeed.tech/tags/documentation.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [messaging](<https://devfeed.tech/tags/messaging.md>), [minimal-image](<https://devfeed.tech/tags/minimal-image.md>), [nats-image](<https://devfeed.tech/tags/nats-image.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [secure-images](<https://devfeed.tech/tags/secure-images.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard announces a hardened Chainguard Image for NATS, built on Wolfi for containerized workloads. The image includes a development variant with the nats CLI and nsc tool, is reported to be over 50% smaller than comparable options, targets zero known CVEs, and includes source-built binaries, SBOMs, signatures, and provenance information.

### Source excerpt

Learn about our hardened Chainguard Image for NATS, which is built on Wolfi, our secure by default operating system for containerized workloads.