# trivy

Published articles for trivy.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Cyber resiliency in practice: Lessons from recent supply chain attacks

DevFeed: [Cyber resiliency in practice: Lessons from recent supply chain attacks](<https://devfeed.tech/articles/cyber-resiliency-in-practice-lessons-from-recent-supply-chain-attacks-13017.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/cyber-resiliency-in-practice-lessons-from-recent-supply-chain-attacks>)

Published: 2026-05-08T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [resiliency](<https://devfeed.tech/topics/resiliency.md>), [supply chain attacks](<https://devfeed.tech/topics/supply-chain-attacks.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [axios](<https://devfeed.tech/topics/axios.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [litellm](<https://devfeed.tech/topics/litellm.md>), [trivy](<https://devfeed.tech/topics/trivy.md>), [npm](<https://devfeed.tech/topics/npm.md>), [PyPI](<https://devfeed.tech/topics/pypi.md>), [Python](<https://devfeed.tech/topics/python.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>)

Tags: [axios](<https://devfeed.tech/tags/axios.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [cyber-resiliency](<https://devfeed.tech/tags/cyber-resiliency.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [litellm](<https://devfeed.tech/tags/litellm.md>), [malware](<https://devfeed.tech/tags/malware.md>), [npm](<https://devfeed.tech/tags/npm.md>), [pypi](<https://devfeed.tech/tags/pypi.md>), [python](<https://devfeed.tech/tags/python.md>), [security](<https://devfeed.tech/tags/security.md>), [security-attacks](<https://devfeed.tech/tags/security-attacks.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>), [trivy](<https://devfeed.tech/tags/trivy.md>), [worm](<https://devfeed.tech/tags/worm.md>)

### AI overview

The article defines cyber resiliency as an integrated ability to anticipate, withstand, recover from, and adapt to attacks across the full Protect, Detect, Respond, and Recover lifecycle. It examines recent supply chain attacks involving Trivy, Axios, and LiteLLM, highlighting risks such as GitHub Actions misconfiguration, long-lived tokens, incomplete credential rotation, mutable Git tags, maintainer-account compromise, and malicious package releases.

### Source excerpt

Learn how modern cyber resiliency helps organizations prevent, detect, and recover from supply chain attacks like Trivy, Axios, and LiteLLM.

## 2026: The year of AI-assisted attacks

DevFeed: [2026: The year of AI-assisted attacks](<https://devfeed.tech/articles/2026-the-year-of-ai-assisted-attacks-12853.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/2026-the-year-of-ai-assisted-attacks>)

Published: 2026-04-14T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Claude Code](<https://devfeed.tech/topics/claude-code.md>), [ChatGPT](<https://devfeed.tech/topics/chatgpt.md>), [Malware](<https://devfeed.tech/topics/malware.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-assisted-attacks](<https://devfeed.tech/tags/ai-assisted-attacks.md>), [ai-containers](<https://devfeed.tech/tags/ai-containers.md>), [axios](<https://devfeed.tech/tags/axios.md>), [breach](<https://devfeed.tech/tags/breach.md>), [chainguard-for-ai](<https://devfeed.tech/tags/chainguard-for-ai.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [claude-code](<https://devfeed.tech/tags/claude-code.md>), [code](<https://devfeed.tech/tags/code.md>), [cybercrime](<https://devfeed.tech/tags/cybercrime.md>), [llm](<https://devfeed.tech/tags/llm.md>), [malicious-packages](<https://devfeed.tech/tags/malicious-packages.md>), [malwhere](<https://devfeed.tech/tags/malwhere.md>), [mythos](<https://devfeed.tech/tags/mythos.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [telnyx](<https://devfeed.tech/tags/telnyx.md>), [trivy](<https://devfeed.tech/tags/trivy.md>)

### AI overview

The article argues that AI-assisted attacks became more capable and accessible in 2025. It describes how ChatGPT, Claude Code, and other LLM-backed systems enabled nontechnical individuals and lone actors to conduct attacks previously associated with skilled hackers or organized teams, while citing increases in malicious packages, cloud intrusions, and AI-generated phishing.

### Source excerpt

AI is lowering the barrier to cybercrime. Learn why attacks are rising fast, and how eliminating entire classes of supply chain risk is the only path forward.

## Is Grype a single point of failure for Chainguard's CVE detection?

DevFeed: [Is Grype a single point of failure for Chainguard's CVE detection?](<https://devfeed.tech/articles/is-grype-a-single-point-of-failure-for-chainguard-s-cve-detection-13127.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/is-grype-a-single-point-of-failure-for-chainguards-cve-detection>)

Published: 2026-04-10T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [grype](<https://devfeed.tech/topics/grype.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Containers](<https://devfeed.tech/topics/containers.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [chainguard-scanners](<https://devfeed.tech/tags/chainguard-scanners.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cve](<https://devfeed.tech/tags/cve.md>), [grype](<https://devfeed.tech/tags/grype.md>), [malware](<https://devfeed.tech/tags/malware.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [source](<https://devfeed.tech/tags/source.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>), [trivy](<https://devfeed.tech/tags/trivy.md>)

### AI overview

The article explains why Grype is not a single point of failure in Chainguard's CVE detection system. It describes layered defenses including building Grype from source, malware detection, and alternative input-source protections to improve the reliability of security findings.

### Source excerpt

Is Grype a single point of failure? Learn how Chainguard uses layered defenses, source builds, and multiple data sources to ensure trusted CVE detection.

## Ship and patch doesn't cut it in the AI era

DevFeed: [Ship and patch doesn't cut it in the AI era](<https://devfeed.tech/articles/ship-and-patch-doesn-t-cut-it-in-the-ai-era-13229.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/ship-and-patch-doesnt-cut-it-in-the-ai-era>)

Published: 2026-04-08T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [prompt injection](<https://devfeed.tech/topics/prompt-injection.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [litellm](<https://devfeed.tech/topics/litellm.md>), [trivy](<https://devfeed.tech/topics/trivy.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-code-security](<https://devfeed.tech/tags/ai-code-security.md>), [ai-coding](<https://devfeed.tech/tags/ai-coding.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [chainguard-containers-for-ai](<https://devfeed.tech/tags/chainguard-containers-for-ai.md>), [chainguard-libraries-for-ai](<https://devfeed.tech/tags/chainguard-libraries-for-ai.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [litellm](<https://devfeed.tech/tags/litellm.md>), [prompt-injection](<https://devfeed.tech/tags/prompt-injection.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [trivy](<https://devfeed.tech/tags/trivy.md>)

### AI overview

This opinion article argues that AI-generated code and dependencies are entering software environments faster than traditional security review processes can handle, while AI also accelerates vulnerability discovery and attacks. It concludes that reactive scanning and patching alone are insufficient and emphasizes trusted inputs for software supply-chain security.

### Source excerpt

AI is accelerating code and attacks. Learn why patching alone can't keep up, and why securing the software supply chain starts with trusted inputs.

## How to protect your organization from the telnyx PyPI compromise

DevFeed: [How to protect your organization from the telnyx PyPI compromise](<https://devfeed.tech/articles/how-to-protect-your-organization-from-the-telnyx-pypi-compromise-13095.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-to-protect-your-organization-from-the-telnyx-pypi-compromise>)

Published: 2026-03-27T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [SDKs](<https://devfeed.tech/topics/sdks.md>), [C2](<https://devfeed.tech/topics/c2.md>), [Python](<https://devfeed.tech/topics/python.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>)

Tags: [api-keys](<https://devfeed.tech/tags/api-keys.md>), [c2](<https://devfeed.tech/tags/c2.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [malware](<https://devfeed.tech/tags/malware.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [pypi](<https://devfeed.tech/tags/pypi.md>), [pypi-attack](<https://devfeed.tech/tags/pypi-attack.md>), [pypi-compromise](<https://devfeed.tech/tags/pypi-compromise.md>), [rsa](<https://devfeed.tech/tags/rsa.md>), [security](<https://devfeed.tech/tags/security.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [teampcp](<https://devfeed.tech/tags/teampcp.md>), [telnyx](<https://devfeed.tech/tags/telnyx.md>), [telnyx-attack](<https://devfeed.tech/tags/telnyx-attack.md>), [telnyx-compromise](<https://devfeed.tech/tags/telnyx-compromise.md>), [trivy](<https://devfeed.tech/tags/trivy.md>)

### AI overview

The article explains that malicious versions 4.87.1 and 4.87.2 of the Telnyx Python SDK were published to PyPI after publishing credentials were compromised. The malware executes at module scope, downloads from a remote C2 server, and uses a WAV file to conceal a Windows persistence binary or credential harvester for Linux and macOS. It recommends immediate removal, version pinning, credential rotation, and persistence checks. The article also attributes the attack to TeamPCP and connects it to a broader coordinated supply chain campaign.

### Source excerpt

Malicious telnyx versions hit PyPI in a wider supply chain attack. Chainguard customers stayed protected by using source-built, verified libraries.

## Secure-by-default: Chainguard customers unaffected by the Trivy supply chain attack

DevFeed: [Secure-by-default: Chainguard customers unaffected by the Trivy supply chain attack](<https://devfeed.tech/articles/secure-by-default-chainguard-customers-unaffected-by-the-trivy-supply-chain-attack-12940.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-customers-unaffected-by-the-trivy-supply-chain-attack>)

Published: 2026-03-20T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [trivy](<https://devfeed.tech/topics/trivy.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Security](<https://devfeed.tech/topics/security.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [incident](<https://devfeed.tech/tags/incident.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [trivy](<https://devfeed.tech/tags/trivy.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Chainguard reports that its customers were unaffected by the March 19, 2026 supply chain attack involving malicious releases of the Trivy vulnerability scanner, trivy-action, and setup-trivy. The article explains how compromised credentials enabled the releases, why the incident threatened CI/CD pipeline secrets, and what organizations using the affected versions should do.

### Source excerpt

Chainguard customers are unaffected by the Trivy supply chain attack.

## Introducing Replik8s, a Modern Security Tool for Kubernetes

DevFeed: [Introducing Replik8s, a Modern Security Tool for Kubernetes](<https://devfeed.tech/articles/introducing-replik8s-a-modern-security-tool-for-kubernetes-29186.md>)

Original publisher: [Read original article](<https://www.latacora.com/blog/2025/09/22/introducing-replik8s/>)

Published: 2025-09-22T16:00:00Z

Content type: release

Language: en

Sources: [Latacora](<https://devfeed.tech/sources/latacora.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Security](<https://devfeed.tech/topics/security.md>), [Kubernetes clusters](<https://devfeed.tech/topics/kubernetes-clusters.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>)

Tags: [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [incident](<https://devfeed.tech/tags/incident.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [kubectl](<https://devfeed.tech/tags/kubectl.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kubernetes-clusters](<https://devfeed.tech/tags/kubernetes-clusters.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [other](<https://devfeed.tech/tags/other.md>), [security](<https://devfeed.tech/tags/security.md>), [security-tools](<https://devfeed.tech/tags/security-tools.md>), [trivy](<https://devfeed.tech/tags/trivy.md>)

### AI overview

Latacora introduces Replik8s, an open-source Kubernetes tool that snapshots cluster data, serves historical snapshots through a mirror API, supports kubectl and Trivy workflows, and provides query-based analysis for auditing and investigation.

### Source excerpt

Introduction # Security tools are often designed to highlight specific issues by consuming APIs and applying predefined logic. Each tool implements its own data structures, storage formats, and evaluation logic. While effective in narrow contexts, this approach creates challenges for teams managing a diverse toolset. Moreover, most tools are optimized to fetch only the data needed for specific findings, limiting their utility in broader contexts such as incident response or historical analysis.

## How Chainguard Integrates with Vulnerability Scanners

DevFeed: [How Chainguard Integrates with Vulnerability Scanners](<https://devfeed.tech/articles/this-shit-is-hard-vulnerability-scanner-integration-13292.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/this-shit-is-hard-vulnerability-scanner-integration>)

Published: 2025-06-30T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [container](<https://devfeed.tech/tags/container.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [go](<https://devfeed.tech/tags/go.md>), [grype](<https://devfeed.tech/tags/grype.md>), [oci](<https://devfeed.tech/tags/oci.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-scanners](<https://devfeed.tech/tags/open-source-scanners.md>), [orca-security](<https://devfeed.tech/tags/orca-security.md>), [popular-container-image-scanners](<https://devfeed.tech/tags/popular-container-image-scanners.md>), [scanner-integration](<https://devfeed.tech/tags/scanner-integration.md>), [trivy](<https://devfeed.tech/tags/trivy.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-scanner](<https://devfeed.tech/tags/vulnerability-scanner.md>)

### AI overview

The article explains how vulnerability scanners inspect software artifacts, identify included packages and versions, and compare them with databases of known vulnerabilities. It focuses on the challenges of integrating Chainguard software and container images with supported scanners so they can accurately report vulnerability status.

### Source excerpt

Chainguard Containers have extensive scanner integrations with many of the most popular container image scanners. Discover more about our integrations.

## Software Bill of Materials (SBOM) for your Spin Apps

DevFeed: [Software Bill of Materials (SBOM) for your Spin Apps](<https://devfeed.tech/articles/software-bill-of-materials-sbom-for-your-spin-apps-15336.md>)

Original publisher: [Read original article](<https://www.fermyon.com/blog/sbom-for-your-spin-apps>)

Author: Thorsten Hans

Published: 2025-01-16T12:00:00Z

Content type: tutorial

Language: en

Sources: [Fermyon - Experience the next wave of cloud computing.](<https://devfeed.tech/sources/fermyon-experience-the-next-wave-of-cloud-computing.md>)

Topics: [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [trivy](<https://devfeed.tech/topics/trivy.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Requirements](<https://devfeed.tech/topics/requirements.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [open-source](<https://devfeed.tech/tags/open-source.md>), [regulatory](<https://devfeed.tech/tags/regulatory.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [trivy](<https://devfeed.tech/tags/trivy.md>)

### AI overview

A tutorial on creating Software Bills of Materials for Spin apps, addressing regulatory requirements and software supply chain security with open-source tools such as Trivy.

### Source excerpt

Learn how to create SBOMs for Spin apps, meet regulatory requirements, and secure your software supply chain with open-source tools like Trivy

## Explore Chainguard CVE Visualizations: Now in Beta

DevFeed: [Explore Chainguard CVE Visualizations: Now in Beta](<https://devfeed.tech/articles/explore-chainguard-cve-visualizations-now-in-beta-13037.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/explore-chainguard-cve-visualizations-now-in-beta>)

Published: 2024-12-19T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Docker Hardened Images](<https://devfeed.tech/topics/docker-hardened-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [grype](<https://devfeed.tech/topics/grype.md>), [trivy](<https://devfeed.tech/topics/trivy.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [blog](<https://devfeed.tech/tags/blog.md>), [business](<https://devfeed.tech/tags/business.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [comparisons](<https://devfeed.tech/tags/comparisons.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-reporting](<https://devfeed.tech/tags/cve-reporting.md>), [cve-visualizations](<https://devfeed.tech/tags/cve-visualizations.md>), [cves](<https://devfeed.tech/tags/cves.md>), [developer](<https://devfeed.tech/tags/developer.md>), [grype](<https://devfeed.tech/tags/grype.md>), [nginx](<https://devfeed.tech/tags/nginx.md>), [python](<https://devfeed.tech/tags/python.md>), [security](<https://devfeed.tech/tags/security.md>), [trivy](<https://devfeed.tech/tags/trivy.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard announces the beta release of CVE Visualizations in its console. The capability compares Chainguard Images with alternative container images over time using total CVEs, severity-level trends, and image size, helping organizations communicate security, engineering, and economic benefits.

### Source excerpt

Check out Chainguard CVE Visualizations, a new capability that allows for comparisons of CVE numbers between Chainguard Images and alternative container images.

## Can auto-patched container images pass the zero CVE challenge?

DevFeed: [Can auto-patched container images pass the zero CVE challenge?](<https://devfeed.tech/articles/can-auto-patched-container-images-pass-the-zero-cve-challenge-12914.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/can-auto-patched-container-images-pass-the-zero-cve-challenge>)

Published: 2024-07-17T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [container images](<https://devfeed.tech/topics/container-images.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [grype](<https://devfeed.tech/topics/grype.md>), [trivy](<https://devfeed.tech/topics/trivy.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container](<https://devfeed.tech/tags/container.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [grype](<https://devfeed.tech/tags/grype.md>), [security](<https://devfeed.tech/tags/security.md>), [trivy](<https://devfeed.tech/tags/trivy.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article examines whether auto-patching can reduce vulnerabilities in container images. An experiment involving 20 popular images found that copacetic reduced CVEs by an average of 8%, while manually updating packages reduced them by 9%. Chainguard Images reduced CVEs by 99% in the reported comparison.

### Source excerpt

Discover how Chainguard surpasses copacetic in the zero-CVE challenge. Ensure vulnerability-free deployments with our Chainguard Images.

## The haunting of CVE-2022-3474: A ghostly tale of package detection failure

DevFeed: [The haunting of CVE-2022-3474: A ghostly tale of package detection failure](<https://devfeed.tech/articles/the-haunting-of-cve-2022-3474-a-ghostly-tale-of-package-detection-failure-13254.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-haunting-of-cve-2022-3474-a-ghostly-tale-of-package-detection-failure>)

Published: 2023-10-10T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [bazel](<https://devfeed.tech/topics/bazel.md>), [trivy](<https://devfeed.tech/topics/trivy.md>)

Tags: [bazel](<https://devfeed.tech/tags/bazel.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve-2022-3474](<https://devfeed.tech/tags/cve-2022-3474.md>), [false-negative](<https://devfeed.tech/tags/false-negative.md>), [trivy](<https://devfeed.tech/tags/trivy.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

The article explains how scanners can produce false negatives when they fail to identify a package in a container image. Using CVE-2022-3474 in Bazel 5.3.1 as an example, it describes how missing Bazel package metadata prevented Trivy from detecting the vulnerability and presents Chainguard Images' package metadata and SBOMs as a way to improve detection.

### Source excerpt

Explore the risks of scanner false negatives, the pitfalls of missing the Bazel package, and how Chainguard Images ensure accurate vulnerability detection.

## Why Chainguard uses Grype as its first line of defense for CVEs

DevFeed: [Why Chainguard uses Grype as its first line of defense for CVEs](<https://devfeed.tech/articles/why-chainguard-uses-grype-as-its-first-line-of-defense-for-cves-13327.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/why-chainguard-uses-grype-as-its-first-line-of-defense-for-cves>)

Published: 2023-10-06T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [grype](<https://devfeed.tech/topics/grype.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Go](<https://devfeed.tech/topics/go.md>), [trivy](<https://devfeed.tech/topics/trivy.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [cves](<https://devfeed.tech/tags/cves.md>), [false-negative](<https://devfeed.tech/tags/false-negative.md>), [false-positive](<https://devfeed.tech/tags/false-positive.md>), [go](<https://devfeed.tech/tags/go.md>), [grype](<https://devfeed.tech/tags/grype.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [prisma-cloud](<https://devfeed.tech/tags/prisma-cloud.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [trivy](<https://devfeed.tech/tags/trivy.md>), [vex](<https://devfeed.tech/tags/vex.md>)

### AI overview

Chainguard explains why it selected Grype as the foundation of its internal vulnerability detection system. The article describes scanning early in the software delivery pipeline, using Grype as a Go library to scan Wolfi APK packages before container images are built, and contributing vulnerability data and improvements to the open-source project. It also briefly compares Grype's open data pipeline with Trivy's.

### Source excerpt

Chainguard harnesses Grype's open-source power to ensure minimal CVEs in images, prioritizing user security.

## How a false negative obscured CVE-2023-2454 in a PostgreSQL image

DevFeed: [How a false negative obscured CVE-2023-2454 in a PostgreSQL image](<https://devfeed.tech/articles/the-haunting-of-cve-2023-2454-a-developer-s-nightmare-13255.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-haunting-of-cve-2023-2454-a-developers-nightmare>)

Published: 2023-10-03T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [container-security](<https://devfeed.tech/topics/container-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [trivy](<https://devfeed.tech/topics/trivy.md>), [PostgreSQL](<https://devfeed.tech/topics/postgresql.md>)

Tags: [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cve-2023-2454](<https://devfeed.tech/tags/cve-2023-2454.md>), [false-negative](<https://devfeed.tech/tags/false-negative.md>), [postgresql](<https://devfeed.tech/tags/postgresql.md>), [trivy](<https://devfeed.tech/tags/trivy.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-scanner](<https://devfeed.tech/tags/vulnerability-scanner.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

The article explains how insufficient vulnerability database metadata can cause a scanner to miss CVE-2023-2454 in a PostgreSQL image. It presents Chainguard Images as often containing fixes for vulnerabilities that scanners miss.

### Source excerpt

Unearth a haunting tale of overlooked threats in scanning. Discover how Chainguard Images counteract gaps, ensuring robust defense against CVEs.

## A growing ecosystem of vulnerability scanners that now support Chainguard Images and Wolfi

DevFeed: [A growing ecosystem of vulnerability scanners that now support Chainguard Images and Wolfi](<https://devfeed.tech/articles/a-growing-ecosystem-of-vulnerability-scanners-that-now-support-chainguard-images-and-wolfi-12857.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/a-growing-ecosystem-of-vulnerability-scanners-that-now-support-chainguard-images-and-wolfi>)

Published: 2023-09-21T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [trivy](<https://devfeed.tech/topics/trivy.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container](<https://devfeed.tech/tags/container.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [grype](<https://devfeed.tech/tags/grype.md>), [prisma-cloud](<https://devfeed.tech/tags/prisma-cloud.md>), [sca](<https://devfeed.tech/tags/sca.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [secure-images](<https://devfeed.tech/tags/secure-images.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [trivy](<https://devfeed.tech/tags/trivy.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [wiz](<https://devfeed.tech/tags/wiz.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard Images and the Wolfi distribution are now supported by a growing ecosystem of open-source and enterprise vulnerability scanners, including Docker Scout, Grype, Snyk, Trivy, and Wiz. The broader integration helps users monitor and prioritize scan results, verify vulnerabilities, reduce scanner noise and false positives, and build more secure software.

### Source excerpt

Secure your software with Chainguard & Wolfi, now recognized by leading vulnerability scanners.

## Chainguard Image now available for Pulumi

DevFeed: [Chainguard Image now available for Pulumi](<https://devfeed.tech/articles/chainguard-image-now-available-for-pulumi-12951.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-image-now-available-for-pulumi>)

Published: 2023-06-29T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [pulumi](<https://devfeed.tech/topics/pulumi.md>), [Infrastructure as code](<https://devfeed.tech/topics/infrastructure-as-code.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [apko](<https://devfeed.tech/tags/apko.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [iac](<https://devfeed.tech/tags/iac.md>), [multi-arch](<https://devfeed.tech/tags/multi-arch.md>), [pulumi](<https://devfeed.tech/tags/pulumi.md>), [security](<https://devfeed.tech/tags/security.md>), [trivy](<https://devfeed.tech/tags/trivy.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>), [x86-64](<https://devfeed.tech/tags/x86-64.md>)

### AI overview

Chainguard announces a Pulumi container image packaged with the Pulumi toolchain in Wolfi OS and built using apko. The image supports multiple programming-language runtimes, is multi-architecture, and is reported to be smaller and to have fewer Trivy-reported CVEs than the official Pulumi image.

### Source excerpt

See a 57% reduction in your Pulumi image sizes with more security built in by default and a 97% reduction in CVEs with the new Chainguard Pulumi Image.

## Improving the Developer Experience -- Our Application Security Journey (Part 3)

DevFeed: [Improving the Developer Experience -- Our Application Security Journey (Part 3)](<https://devfeed.tech/articles/improving-the-developer-experience-our-application-security-journey-part-3-15456.md>)

Original publisher: [Read original article](<https://medium.com/wise-engineering/improving-the-developer-experience-our-application-security-journey-part-3-757e0e6d32e4?source=rss----f2565bbe9c46---4>)

Author: Florian Wirtz

Published: 2023-01-17T11:19:44Z

Content type: article

Language: en

Sources: [Wise Engineering - Medium](<https://devfeed.tech/sources/wise-engineering-medium.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Developer experience](<https://devfeed.tech/topics/developer-experience.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [dashboards](<https://devfeed.tech/topics/dashboards.md>), [software composition analysis](<https://devfeed.tech/topics/software-composition-analysis.md>), [trivy](<https://devfeed.tech/topics/trivy.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [dashboards](<https://devfeed.tech/tags/dashboards.md>), [developer-experience](<https://devfeed.tech/tags/developer-experience.md>), [platform](<https://devfeed.tech/tags/platform.md>), [security](<https://devfeed.tech/tags/security.md>), [software-composition-analysis](<https://devfeed.tech/tags/software-composition-analysis.md>), [trivy](<https://devfeed.tech/tags/trivy.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

This third article in Wise's application security series examines how to improve developers' experience when fixing vulnerabilities. It describes feedback gathered through surveys and interviews, identifying slow dashboards and the need for developers to proactively check them as key pain points.

### Source excerpt

Improving the Developer Experience -- Our Application Security Journey (Part 3) This is the third in a series of articles on the state of Application Security at Wise, describing our integration of security in the Software Development Lifecycle. Photo by Possessed Photography on Unsplash In part three of our blog post series we will be focusing on how we can improve the developers' experience around fixing vulnerabilities. We explore how we identified the main pain points developers were facing, what we did to improve this experience and future improvement ideas that we are planning to work on. Recap: What happened so far? Over the course of the last year we have created our new setup for identifying vulnerabilities at Wise. It's centred around DefectDojo as our vulnerability management tool and we use scanners, such as Trivy for Software Composition Analysis, as inputs. You can learn more about our setup in part one of this blog series. Since then we have also created various dashboards to report vulnerabilities to our stakeholders, and also improved our Service-level agreement (SLA) with our developers to resolve new vulnerabilities. To learn more about that, please read part two of this series. What issues are our developers facing? As a next step, it's important to check in with our developers to see how they're interacting with our program. It's one thing to set up a vulnerability management program, but we also need to make sure that it actually works for our users and that the recommendations provided are actioned in a timely manner. While the initial feedback we received from developers was promising, we decided to share a survey with them to collect more actionable feedback. Our survey had a mix of multiple-choice and free-form questions and was mostly focused on how developers are using our tools and what issues they might be facing with them. We also interviewed them for analogous use cases, including what works well and what doesn't work well in other too