# secure container image

Published articles for secure container image.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## How to transition to secure container images with new migration guides

DevFeed: [How to transition to secure container images with new migration guides](<https://devfeed.tech/articles/how-to-transition-to-secure-container-images-with-new-migration-guides-13096.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-to-transition-to-secure-container-images-with-new-migration-guides>)

Published: 2024-05-22T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [migration](<https://devfeed.tech/topics/migration.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [APK](<https://devfeed.tech/topics/apk.md>), [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [Package manager](<https://devfeed.tech/topics/package-manager.md>), [Bash](<https://devfeed.tech/topics/bash.md>), [Zsh](<https://devfeed.tech/topics/zsh.md>), [Debian](<https://devfeed.tech/topics/debian.md>)

Tags: [and-best-practices](<https://devfeed.tech/tags/and-best-practices.md>), [apk](<https://devfeed.tech/tags/apk.md>), [base-images](<https://devfeed.tech/tags/base-images.md>), [bash](<https://devfeed.tech/tags/bash.md>), [best-practices](<https://devfeed.tech/tags/best-practices.md>), [build](<https://devfeed.tech/tags/build.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container](<https://devfeed.tech/tags/container.md>), [container-based-application](<https://devfeed.tech/tags/container-based-application.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [container-security-strategy](<https://devfeed.tech/tags/container-security-strategy.md>), [cves](<https://devfeed.tech/tags/cves.md>), [debian](<https://devfeed.tech/tags/debian.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [docker-hub-image](<https://devfeed.tech/tags/docker-hub-image.md>), [dockerfiles](<https://devfeed.tech/tags/dockerfiles.md>), [guides](<https://devfeed.tech/tags/guides.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [image-migration](<https://devfeed.tech/tags/image-migration.md>), [migration](<https://devfeed.tech/tags/migration.md>), [migration-guides](<https://devfeed.tech/tags/migration-guides.md>), [python-image](<https://devfeed.tech/tags/python-image.md>), [secure-container-image](<https://devfeed.tech/tags/secure-container-image.md>), [secure-container-images](<https://devfeed.tech/tags/secure-container-images.md>)

### AI overview

This guide explains how to migrate container images to Chainguard Images for smaller image sizes, fewer vulnerabilities, and continuous maintenance. It covers using -dev images for shells and package managers, installing bash or zsh when needed, searching for packages with apk, and adapting Dockerfiles and entrypoint scripts.

### Source excerpt

Struggling to adopt secure container images? Our new migration guides provide step-by-step instructions and best practices for a smooth transition.

## Chainguard Images April 2024: Secure, reliable, feature-rich

DevFeed: [Chainguard Images April 2024: Secure, reliable, feature-rich](<https://devfeed.tech/articles/chainguard-images-april-2024-secure-reliable-feature-rich-12953.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-images-april-2024-secure-reliable-feature-rich>)

Published: 2024-05-09T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [FFmpeg (Fast Forward Moving Picture Experts Group)](<https://devfeed.tech/topics/ffmpeg.md>), [MATLAB](<https://devfeed.tech/topics/matlab.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [ffmpeg](<https://devfeed.tech/tags/ffmpeg.md>), [fips](<https://devfeed.tech/tags/fips.md>), [fips-compliance](<https://devfeed.tech/tags/fips-compliance.md>), [harbor](<https://devfeed.tech/tags/harbor.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [release](<https://devfeed.tech/tags/release.md>), [rstudio](<https://devfeed.tech/tags/rstudio.md>), [secure-container-image](<https://devfeed.tech/tags/secure-container-image.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [tesseract](<https://devfeed.tech/tags/tesseract.md>), [valkey](<https://devfeed.tech/tags/valkey.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Chainguard announces approximately 60 new Chainguard Images in its April 2024 release. The hardened, minimal images focus on software supply chain security, reliability, and reduced CVE exposure, with FIPS variants available for some images. Featured additions include rstudio, Harbor, FFmpeg, Tesseract, and Valkey.

### Source excerpt

Explore the latest features and security enhancements in Chainguard Images (April 2024 release). Strengthen your software supply chain.

## A guide on how to use Chainguard Images for public catalog tier users

DevFeed: [A guide on how to use Chainguard Images for public catalog tier users](<https://devfeed.tech/articles/a-guide-on-how-to-use-chainguard-images-for-public-catalog-tier-users-12858.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/a-guide-on-how-to-use-chainguard-images-for-public-catalog-tier-users>)

Published: 2023-06-23T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [migration](<https://devfeed.tech/topics/migration.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chaingaurd-images](<https://devfeed.tech/tags/chaingaurd-images.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container](<https://devfeed.tech/tags/container.md>), [container-image-registry](<https://devfeed.tech/tags/container-image-registry.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [guide](<https://devfeed.tech/tags/guide.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [images](<https://devfeed.tech/tags/images.md>), [migration](<https://devfeed.tech/tags/migration.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [secure-container-image](<https://devfeed.tech/tags/secure-container-image.md>), [secure-minimal-image](<https://devfeed.tech/tags/secure-minimal-image.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

This guide explains a policy change affecting Chainguard Images public catalog users. From August 16, 2023, public-tier users can pull only the latest tags and continue to pull images by digest; access to other tags requires a Standard or Custom catalog subscription. It describes the impact on existing build processes, authentication errors, migration options, and technical approaches for using images without version tags.

### Source excerpt

Learn about the upcoming Chainguard Images catalog changes and the actions required for Public tier users.

## A thought experiment on using low-vulnerability Chainguard Images to speed government software delivery

DevFeed: [A thought experiment on using low-vulnerability Chainguard Images to speed government software delivery](<https://devfeed.tech/articles/ship-software-to-uncle-sam-faster-with-zero-known-vulnerability-containers-13230.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/ship-software-to-uncle-sam-faster-with-zero-known-vulnerability-containers>)

Published: 2023-06-20T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Containers](<https://devfeed.tech/topics/containers.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [authority to operate](<https://devfeed.tech/topics/authority-to-operate.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard labs](<https://devfeed.tech/topics/chainguard-labs.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [ato](<https://devfeed.tech/tags/ato.md>), [authority-to-operate](<https://devfeed.tech/tags/authority-to-operate.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-labs](<https://devfeed.tech/tags/chainguard-labs.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [containers](<https://devfeed.tech/tags/containers.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [government](<https://devfeed.tech/tags/government.md>), [image-cves](<https://devfeed.tech/tags/image-cves.md>), [secure-container-image](<https://devfeed.tech/tags/secure-container-image.md>), [secure-minimal-image](<https://devfeed.tech/tags/secure-minimal-image.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [vulnerability-scanner](<https://devfeed.tech/tags/vulnerability-scanner.md>)

### AI overview

This opinion article proposes studying whether Chainguard Images with zero-known or low vulnerability counts could reduce timelines and staff costs in government Authority to Operate processes. It presents this as a hypothesis requiring comparison with other ATO processes, not as a demonstrated result.

### Source excerpt

Discover how 0-known vulnerability containers from Chainguard Labs could accelerate software delivery to the government.

## Fortify, comply and conquer FedRAMP with Chainguard Images

DevFeed: [Fortify, comply and conquer FedRAMP with Chainguard Images](<https://devfeed.tech/articles/fortify-comply-and-conquer-fedramp-with-chainguard-images-13052.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/fortify-comply-and-conquer-fedramp-with-chainguard-images>)

Published: 2023-05-25T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Linux](<https://devfeed.tech/topics/linux.md>)

Tags: [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cve](<https://devfeed.tech/tags/cve.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fips](<https://devfeed.tech/tags/fips.md>), [hardened-image](<https://devfeed.tech/tags/hardened-image.md>), [linux](<https://devfeed.tech/tags/linux.md>), [nist](<https://devfeed.tech/tags/nist.md>), [secure-container-image](<https://devfeed.tech/tags/secure-container-image.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

This article explains how Chainguard Images can help cloud service providers and federal agencies achieve or maintain FedRAMP authorization. It describes FedRAMP requirements for hardened container images, recurring vulnerability scanning, NVD identifiers, CVSSv3 scores, and vulnerability remediation tracking. It presents Chainguard Images as secure, continuously updated base images built from source on the hardened Wolfi Linux un-distribution.

### Source excerpt

Learn how Chainguard Images can you achieve or maintain your FedRAMP compliance authorization with secure-by-default base images.

## How to explain the CISA software attestation requirements to your board

DevFeed: [How to explain the CISA software attestation requirements to your board](<https://devfeed.tech/articles/how-to-explain-the-cisa-software-attestation-requirements-to-your-board-13094.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-to-explain-the-cisa-software-attestation-requirements-to-your-board>)

Published: 2023-05-05T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [cybersecurity and infrastructure security agency](<https://devfeed.tech/topics/cybersecurity-and-infrastructure-security-agency.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [attestation](<https://devfeed.tech/tags/attestation.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [government](<https://devfeed.tech/tags/government.md>), [national-cybersecurity-strategy](<https://devfeed.tech/tags/national-cybersecurity-strategy.md>), [nist](<https://devfeed.tech/tags/nist.md>), [policy](<https://devfeed.tech/tags/policy.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-container-image](<https://devfeed.tech/tags/secure-container-image.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [self-attestation](<https://devfeed.tech/tags/self-attestation.md>), [signing-artifacts](<https://devfeed.tech/tags/signing-artifacts.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-artifact-signing](<https://devfeed.tech/tags/software-artifact-signing.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>)

### AI overview

This article explains how software companies can brief their boards on CISA software attestation requirements and the broader federal software supply chain security policy landscape. It discusses Executive Order 14028, SBOMs, secure software development, CISA's Secure Software Development Attestation Form, and the requirements in OMB Memorandum M-22-18, including alignment with NIST guidance.

### Source excerpt

CISA's draft self-attestation form clarifies the minimum requirements that software developers must meet to comply with OMB Memorandum M-22-18.