# melange

Published articles for melange.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Chainguard patches 3 "silent" Golang CVEs in under 24 hours

DevFeed: [Chainguard patches 3 "silent" Golang CVEs in under 24 hours](<https://devfeed.tech/articles/chainguard-patches-3-silent-golang-cves-in-under-24-hours-12975.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-patches-3-silent-golang-cves-in-under-24-hours>)

Published: 2024-03-21T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Go](<https://devfeed.tech/topics/go.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [toolchain](<https://devfeed.tech/topics/toolchain.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>), [Linux](<https://devfeed.tech/topics/linux.md>)

Tags: [automation](<https://devfeed.tech/tags/automation.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cves](<https://devfeed.tech/tags/cves.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [github](<https://devfeed.tech/tags/github.md>), [go](<https://devfeed.tech/tags/go.md>), [golang](<https://devfeed.tech/tags/golang.md>), [golang-patch](<https://devfeed.tech/tags/golang-patch.md>), [linux](<https://devfeed.tech/tags/linux.md>), [melange](<https://devfeed.tech/tags/melange.md>), [merge](<https://devfeed.tech/tags/merge.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [safe-source-for-open-source](<https://devfeed.tech/tags/safe-source-for-open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [silent-cve](<https://devfeed.tech/tags/silent-cve.md>), [tooling](<https://devfeed.tech/tags/tooling.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard describes how it patched three Golang CVEs in under 24 hours. Its automation monitored new Go releases, opened a pull request, rebuilt the Wolfi package, and updated Chainguard Images containing Go.

### Source excerpt

See how Chainguard swiftly patched three Golang CVEs in under 24 hours, showcasing rapid response and dedication to secure software.

## Reimagining the Linux distro with Wolfi

DevFeed: [Reimagining the Linux distro with Wolfi](<https://devfeed.tech/articles/reimagining-the-linux-distro-with-wolfi-13209.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/reimagining-the-linux-distro-with-wolfi>)

Published: 2024-02-21T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Linux](<https://devfeed.tech/topics/linux.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Package Management](<https://devfeed.tech/topics/package-management.md>), [APK](<https://devfeed.tech/topics/apk.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [apk](<https://devfeed.tech/tags/apk.md>), [apko](<https://devfeed.tech/tags/apko.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cve](<https://devfeed.tech/tags/cve.md>), [linux](<https://devfeed.tech/tags/linux.md>), [melange](<https://devfeed.tech/tags/melange.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [package-management](<https://devfeed.tech/tags/package-management.md>), [secure-container-images](<https://devfeed.tech/tags/secure-container-images.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

The article explains why Chainguard created Wolfi, a minimal Linux distribution designed for modern container use. It describes the roles of Melange for building APK packages and Apko for assembling reproducible container images, along with Wolfi's security advisory and vulnerability-management capabilities.

### Source excerpt

Discover Wolfi: Chainguard's answer to modern container security, creating minimal, secure Linux distributions for today's needs.

## Wolfi's approach to container security and CVE management

DevFeed: [Wolfi's approach to container security and CVE management](<https://devfeed.tech/articles/revolutionizing-container-security-and-cve-management-13213.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/revolutionizing-container-security-and-cve-management>)

Published: 2024-02-08T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [container-security](<https://devfeed.tech/topics/container-security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [apko](<https://devfeed.tech/tags/apko.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-management](<https://devfeed.tech/tags/cve-management.md>), [melange](<https://devfeed.tech/tags/melange.md>), [oci](<https://devfeed.tech/tags/oci.md>), [secure-images](<https://devfeed.tech/tags/secure-images.md>), [secure-software-supply-chain](<https://devfeed.tech/tags/secure-software-supply-chain.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

The article explains how Wolfi, a secure-by-default undistro, supports container security by helping create minimal, reproducible OCI-compliant images and reducing software supply chain risks. It also describes how Wolfi powers Chainguard Images.

### Source excerpt

Discover Wolfi, the 'secure-by-default' undistro for container security, enhancing open-source software with minimal CVE counts and robust protection.

## Wolfi: a new paradigm in Linux for containers

DevFeed: [Wolfi: a new paradigm in Linux for containers](<https://devfeed.tech/articles/wolfi-a-new-paradigm-in-linux-for-containers-13336.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/wolfi-a-new-paradigm-in-linux-for-containers>)

Published: 2024-01-17T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Linux](<https://devfeed.tech/topics/linux.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Package Management](<https://devfeed.tech/topics/package-management.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [apk](<https://devfeed.tech/tags/apk.md>), [apko](<https://devfeed.tech/tags/apko.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [linux](<https://devfeed.tech/tags/linux.md>), [melange](<https://devfeed.tech/tags/melange.md>), [package-management](<https://devfeed.tech/tags/package-management.md>), [security](<https://devfeed.tech/tags/security.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Wolfi is a minimal Linux distribution designed for containerized applications. The article describes its focus on efficiency, security, rapid updates, reproducible APK-based package management, and container image creation through melange and apko.

### Source excerpt

Wolfi is a Linux distribution built specifically for containerized applications. See how it can speed up your development process.

## Building minimal, up-to-date cloud images with Wolfi

DevFeed: [Building minimal, up-to-date cloud images with Wolfi](<https://devfeed.tech/articles/building-minimal-up-to-date-cloud-images-with-wolfi-12908.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/building-minimal-up-to-date-cloud-images-with-wolfi>)

Published: 2023-12-15T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Cloud](<https://devfeed.tech/topics/cloud.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>), [DevOps](<https://devfeed.tech/topics/devops.md>)

Tags: [apk](<https://devfeed.tech/tags/apk.md>), [apko](<https://devfeed.tech/tags/apko.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [chainguard-academy](<https://devfeed.tech/tags/chainguard-academy.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [container](<https://devfeed.tech/tags/container.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [devops](<https://devfeed.tech/tags/devops.md>), [efficiency](<https://devfeed.tech/tags/efficiency.md>), [kubecon-na](<https://devfeed.tech/tags/kubecon-na.md>), [melange](<https://devfeed.tech/tags/melange.md>), [minimalism](<https://devfeed.tech/tags/minimalism.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [os](<https://devfeed.tech/tags/os.md>), [packages](<https://devfeed.tech/tags/packages.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

The article introduces Wolfi, an open source project for building minimal, up-to-date cloud and container images. It explains how Wolfi's security-first architecture, proactive updates, minimalism, and supporting tools such as melange, apko, and apk help reduce attack surfaces and CVE exposure while improving software supply chain security.

### Source excerpt

Discover Wolfi OS: Crafting minimal, always up-to-date cloud images for superior security and efficiency in the cloud.

## Small octopus and a big idea: The story of how a one-year old Linux un-distro is improving the cloud's software supply chain

DevFeed: [Small octopus and a big idea: The story of how a one-year old Linux un-distro is improving the cloud's software supply chain](<https://devfeed.tech/articles/small-octopus-and-a-big-idea-the-story-of-how-a-one-year-old-linux-un-distro-is-improving-the-cloud-s-software-supply-chain-13234.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/small-octopus-and-a-big-idea-the-story-of-how-a-one-year-old-linux-un-distro-is-improving-the-clouds-software-supply-chain>)

Published: 2023-09-27T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Linux](<https://devfeed.tech/topics/linux.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>)

Tags: [apko](<https://devfeed.tech/tags/apko.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [containers](<https://devfeed.tech/tags/containers.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [linux](<https://devfeed.tech/tags/linux.md>), [melange](<https://devfeed.tech/tags/melange.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard reviews Wolfi's first year as a minimal Linux un-distro focused on rapid package updates, fast CVE remediation, and cloud-native software supply chain security. The article reports package, repository, contributor, update-interval, and vulnerability-scanning milestones, and describes Wolfi's rolling-release approach and wolfi-act integration with GitHub Actions.

### Source excerpt

Explore Wolfi's journey: A Linux un-distro revolutionizing cloud-native development with agile updates for robust software security.

## How to use Dockerfiles with wolfi-base images

DevFeed: [How to use Dockerfiles with wolfi-base images](<https://devfeed.tech/articles/how-to-use-dockerfiles-with-wolfi-base-images-13097.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-to-use-dockerfiles-with-wolfi-base-images>)

Published: 2023-09-14T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [distroless](<https://devfeed.tech/topics/distroless.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Go](<https://devfeed.tech/topics/go.md>)

Tags: [apko](<https://devfeed.tech/tags/apko.md>), [base-images](<https://devfeed.tech/tags/base-images.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-hub](<https://devfeed.tech/tags/docker-hub.md>), [dockerfiles](<https://devfeed.tech/tags/dockerfiles.md>), [go](<https://devfeed.tech/tags/go.md>), [guide](<https://devfeed.tech/tags/guide.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [melange](<https://devfeed.tech/tags/melange.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

This tutorial explains how to use Dockerfiles with Chainguard wolfi-base and other Chainguard Images. It covers minimal static images, glibc-dynamic images, multi-stage builds, package management, and selecting image variants based on application dependencies and runtime needs.

### Source excerpt

Your guide to leveraging Dockerfiles with Wolfi-base images for hardened container images.

## apko: a year later

DevFeed: [apko: a year later](<https://devfeed.tech/articles/apko-a-year-later-12887.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/apko-a-year-later>)

Published: 2023-02-28T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Development](<https://devfeed.tech/topics/development.md>), [Package manager](<https://devfeed.tech/topics/package-manager.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Unix](<https://devfeed.tech/topics/unix.md>), [YAML](<https://devfeed.tech/topics/yaml.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>)

Tags: [alpine](<https://devfeed.tech/tags/alpine.md>), [apk](<https://devfeed.tech/tags/apk.md>), [apko](<https://devfeed.tech/tags/apko.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-enforce](<https://devfeed.tech/tags/chainguard-enforce.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [development](<https://devfeed.tech/tags/development.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [golang](<https://devfeed.tech/tags/golang.md>), [linux](<https://devfeed.tech/tags/linux.md>), [macos](<https://devfeed.tech/tags/macos.md>), [melange](<https://devfeed.tech/tags/melange.md>), [secure-software-supply-chain](<https://devfeed.tech/tags/secure-software-supply-chain.md>), [terraform-provider](<https://devfeed.tech/tags/terraform-provider.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>), [yaml](<https://devfeed.tech/tags/yaml.md>)

### AI overview

This article reviews apko one year after its public release. It describes apko's native Go implementation of the apk package manager, which runs on UNIX-like systems including macOS and BSDs, and explains how its declarative YAML interface helped support an ecosystem that includes Chainguard Images, Melange, Wolfi, and a Terraform provider. The article presents apko as a foundation for secure software supply chains through images-as-code and frequent image rebuilds.

### Source excerpt

Dive in to apko and learn more about the project; where it's been in the past year, and where it's going.

## Make SBOMs, not GuessBOMs: Why we need to shift left on SBOM generation

DevFeed: [Make SBOMs, not GuessBOMs: Why we need to shift left on SBOM generation](<https://devfeed.tech/articles/make-sboms-not-guessboms-why-we-need-to-shift-left-on-sbom-generation-13142.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/make-sboms-not-guessboms-why-we-need-to-shift-left-on-sbom-generation>)

Published: 2023-01-26T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [software dark matter](<https://devfeed.tech/topics/software-dark-matter.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Reverse Engineering](<https://devfeed.tech/topics/reverse-engineering.md>), [Containers](<https://devfeed.tech/topics/containers.md>)

Tags: [apko](<https://devfeed.tech/tags/apko.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [guessbom](<https://devfeed.tech/tags/guessbom.md>), [melange](<https://devfeed.tech/tags/melange.md>), [reverse-engineering](<https://devfeed.tech/tags/reverse-engineering.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [sca](<https://devfeed.tech/tags/sca.md>), [shift-left](<https://devfeed.tech/tags/shift-left.md>), [software-composition-analysis](<https://devfeed.tech/tags/software-composition-analysis.md>), [software-dark-matter](<https://devfeed.tech/tags/software-dark-matter.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The article argues that SBOMs generated after a build by software composition analysis tools can be incomplete because they may miss components that bypass recorded metadata, such as files copied through Dockerfiles. It presents build-time generation as a better way to produce complete SBOMs and describes untracked files as software dark matter, which can make post-build SBOMs closer to best guesses than reliable inventories.

### Source excerpt

GuessBOMs, SBOMs generated by reverse-engineering software artifacts, have severe limitations. The optimal point for generating complete SBOMs is at build time.