# vulnerability scanning

Published articles for vulnerability scanning.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## We invited a direct competitor into Security Hub Extended. Here's why.

DevFeed: [We invited a direct competitor into Security Hub Extended. Here's why.](<https://devfeed.tech/articles/we-invited-a-direct-competitor-into-security-hub-extended-here-s-why-4693.md>)

Original publisher: [Read original article](<https://aws.amazon.com/blogs/security/we-invited-a-direct-competitor-into-security-hub-extended-heres-why/>)

Author: Michael Fuller

Published: 2026-08-31T19:00:07Z

Content type: opinion

Language: en

Sources: [AWS Security Blog](<https://devfeed.tech/sources/aws-security-blog.md>)

Topics: [AWS Security Hub](<https://devfeed.tech/topics/aws-security-hub.md>), [Security & compliance, Cloud security](<https://devfeed.tech/topics/security-compliance-cloud-security.md>), [workload protection](<https://devfeed.tech/topics/workload-protection.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [eBPF](<https://devfeed.tech/topics/ebpf.md>), [Linux Kernel](<https://devfeed.tech/topics/linux-kernel.md>)

Tags: [announcements](<https://devfeed.tech/tags/announcements.md>), [aws-security-hub](<https://devfeed.tech/tags/aws-security-hub.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [container](<https://devfeed.tech/tags/container.md>), [ebpf](<https://devfeed.tech/tags/ebpf.md>), [foundational-100](<https://devfeed.tech/tags/foundational-100.md>), [linux-kernel](<https://devfeed.tech/tags/linux-kernel.md>), [security](<https://devfeed.tech/tags/security.md>), [security-blog](<https://devfeed.tech/tags/security-blog.md>), [security-identity-compliance](<https://devfeed.tech/tags/security-identity-compliance.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>), [workload-protection](<https://devfeed.tech/tags/workload-protection.md>)

### AI overview

AWS explains why it invited Upwind, a cloud security competitor, into Security Hub Extended. The post says the partnership responds to customer demand, expands choice between posture management and runtime-first protection, and simplifies integration through AWS billing, support, and operations.

### Source excerpt

When customers keep pointing you to a solution that overlaps with parts of your own offering, you have a choice to make. This post is about the choice we made with Upwind, and why we'd make it again. AWS Security Hub Extended exists because customers told us what was working for them in enterprise security [...]

## Why repository-centric security still needs an artifact access control plane

DevFeed: [Why repository-centric security still needs an artifact access control plane](<https://devfeed.tech/articles/why-repository-centric-security-still-needs-an-artifact-access-control-plane-12282.md>)

Original publisher: [Read original article](<https://platformengineering.org/blog/why-repository-centric-security-still-needs-an-artifact-access-control-plane>)

Author: Adrian Herrera

Published: 2026-07-23T05:40:01Z

Content type: article

Language: en

Sources: [Platform Engineering Blog](<https://devfeed.tech/sources/platform-engineering-blog.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [iac-security](<https://devfeed.tech/topics/iac-security.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [infrastructure-as-code](<https://devfeed.tech/tags/infrastructure-as-code.md>), [security](<https://devfeed.tech/tags/security.md>), [security-policies](<https://devfeed.tech/tags/security-policies.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

The article explains that repository-centric security controls can leave gaps because dependency access is distributed across CI runners, ephemeral build agents, public registries, developer tooling, and automation. It argues for an artifact access control plane, including Virtual Registries, to enforce security policies inline across CI/CD execution paths, complementing repository-based vulnerability scanning, license analysis, dependency governance, and remediation.

### Source excerpt

Repository security gaps: Distributed dependency access bypasses centralized analysis. Virtual Registries offer the critical inline control plane to enforce artifact security policies across your CI/CD pipeline.

## CMMC Phase 2, explained: Requirements, deadlines, and who's affected

DevFeed: [CMMC Phase 2, explained: Requirements, deadlines, and who's affected](<https://devfeed.tech/articles/cmmc-phase-2-explained-requirements-deadlines-and-who-s-affected-13009.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/cmmc-phase-2-explained>)

Published: 2026-04-29T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [MFA](<https://devfeed.tech/topics/mfa.md>)

Tags: [certificates](<https://devfeed.tech/tags/certificates.md>), [cmmc](<https://devfeed.tech/tags/cmmc.md>), [cmmc-container-images](<https://devfeed.tech/tags/cmmc-container-images.md>), [cmmc-phase-2](<https://devfeed.tech/tags/cmmc-phase-2.md>), [cmvp](<https://devfeed.tech/tags/cmvp.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cybersecurity-maturity-model-certification](<https://devfeed.tech/tags/cybersecurity-maturity-model-certification.md>), [fips](<https://devfeed.tech/tags/fips.md>), [nist](<https://devfeed.tech/tags/nist.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [stig](<https://devfeed.tech/tags/stig.md>), [stigs](<https://devfeed.tech/tags/stigs.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [u-s-dod](<https://devfeed.tech/tags/u-s-dod.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

This article explains the requirements, deadlines, and scope of CMMC Phase 2. It describes the CMMC Level 2 certification requirements for organizations handling Controlled Unclassified Information or supporting Department of Defense and certain civilian agency contracts, including MFA, encryption, vulnerability scanning, supported systems, independent assessments, and compliance documentation.

### Source excerpt

CMMC Phase 2 and NIST 800-171 are here. Learn how Chainguard helps teams meet compliance with FIPS, STIGs, and zero-CVE containers.

## SecDB is the past, OSV is the future

DevFeed: [SecDB is the past, OSV is the future](<https://devfeed.tech/articles/secdb-is-the-past-osv-is-the-future-13218.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/secdb-is-the-past-osv-is-the-future>)

Published: 2026-04-09T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [chainguard packages](<https://devfeed.tech/topics/chainguard-packages.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-scanners](<https://devfeed.tech/tags/chainguard-scanners.md>), [cves](<https://devfeed.tech/tags/cves.md>), [deprecated](<https://devfeed.tech/tags/deprecated.md>), [open-source-vulnerabilities](<https://devfeed.tech/tags/open-source-vulnerabilities.md>), [osv](<https://devfeed.tech/tags/osv.md>), [secdb](<https://devfeed.tech/tags/secdb.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-data](<https://devfeed.tech/tags/vulnerability-data.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

Chainguard is deprecating its SecDB vulnerability feed and plans to sunset it at the end of 2026. The company is moving toward the OSV schema because it supports more precise vulnerability data, including unfixed vulnerabilities and component-level advisory details.

### Source excerpt

Chainguard is deprecating SecDB in favor of OSV, delivering more accurate, granular vulnerability data and better visibility for modern software supply chains.

## It's time to rethink golden images. Chainguard can help.

DevFeed: [It's time to rethink golden images. Chainguard can help.](<https://devfeed.tech/articles/it-s-time-to-rethink-golden-images-chainguard-can-help-13130.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/its-time-to-rethink-golden-images-chainguard-can-help>)

Published: 2025-11-17T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [DevOps](<https://devfeed.tech/topics/devops.md>), [Tech Debt](<https://devfeed.tech/topics/tech-debt.md>)

Tags: [base-images](<https://devfeed.tech/tags/base-images.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-golden-images](<https://devfeed.tech/tags/chainguard-golden-images.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [development](<https://devfeed.tech/tags/development.md>), [devops](<https://devfeed.tech/tags/devops.md>), [golden-container-images](<https://devfeed.tech/tags/golden-container-images.md>), [golden-images](<https://devfeed.tech/tags/golden-images.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

Chainguard advocates developer-centric golden image programs built on secure, trusted, purpose-built container base images. The approach aims to balance governance and standardization with developer flexibility, improving delivery speed while reducing maintenance costs, vulnerabilities, and compliance concerns.

### Source excerpt

Chainguard helps teams build developer-centric golden image programs with zero-CVE, purpose-built containers--balancing speed, security, and standardization.

## Introducing Our Newest Ecosystem Integration: Anchore Enterprise

DevFeed: [Introducing Our Newest Ecosystem Integration: Anchore Enterprise](<https://devfeed.tech/articles/introducing-our-newest-ecosystem-integration-anchore-enterprise-13119.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-our-newest-ecosystem-integration-anchore-enterprise>)

Published: 2025-09-23T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [anchore](<https://devfeed.tech/topics/anchore.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>)

Tags: [anchore](<https://devfeed.tech/tags/anchore.md>), [anchore-enterprise](<https://devfeed.tech/tags/anchore-enterprise.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-partners](<https://devfeed.tech/tags/chainguard-partners.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [integration](<https://devfeed.tech/tags/integration.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

Chainguard announces a new integration with Anchore Enterprise. The integration combines Chainguard's secure-by-default container images with Anchore's SBOM management, vulnerability scanning, and automated compliance policy enforcement to support continuous software security and compliance.

### Source excerpt

Discover more about Chainguard's new integration with Anchore Enterprise.

## Introducing Scanfrog: Dodge Container Vulnerabilities

DevFeed: [Introducing Scanfrog: Dodge Container Vulnerabilities](<https://devfeed.tech/articles/introducing-scanfrog-dodge-container-vulnerabilities-13120.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-scanfrog-dodge-container-vulnerabilities>)

Published: 2025-07-30T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Containers](<https://devfeed.tech/topics/containers.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [grype](<https://devfeed.tech/topics/grype.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Security](<https://devfeed.tech/topics/security.md>), [Terminal](<https://devfeed.tech/topics/terminal.md>), [arcade](<https://devfeed.tech/topics/arcade.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [anchore](<https://devfeed.tech/tags/anchore.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [container](<https://devfeed.tech/tags/container.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [container-image-vulnerabilities](<https://devfeed.tech/tags/container-image-vulnerabilities.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [free](<https://devfeed.tech/tags/free.md>), [games](<https://devfeed.tech/tags/games.md>), [grype](<https://devfeed.tech/tags/grype.md>), [management](<https://devfeed.tech/tags/management.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [scanfrog](<https://devfeed.tech/tags/scanfrog.md>), [security](<https://devfeed.tech/tags/security.md>), [terminal](<https://devfeed.tech/tags/terminal.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-scanner](<https://devfeed.tech/tags/vulnerability-scanner.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

Scanfrog is a Frogger-style terminal game that turns vulnerabilities found in a container image into game obstacles. It uses Grype, a free and open-source vulnerability scanner, to create levels based on vulnerability-scanning results and illustrates why reducing vulnerabilities improves software security.

### Source excerpt

Scanfrog is a Frogger-style game created by one of Chainguard's engineers to showcase how difficult it can be to dodge vulnerabilities in containers.

## Chainguard Now Available on Microsoft Azure Marketplace; Scan Chainguard Container Images with Microsoft Defender for Cloud

DevFeed: [Chainguard Now Available on Microsoft Azure Marketplace; Scan Chainguard Container Images with Microsoft Defender for Cloud](<https://devfeed.tech/articles/chainguard-now-available-on-microsoft-azure-marketplace-scan-chainguard-container-images-with-microsoft-defender-for-cloud-12973.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-now-available-on-microsoft-azure-marketplace>)

Published: 2025-07-16T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Azure](<https://devfeed.tech/topics/azure.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [azure](<https://devfeed.tech/tags/azure.md>), [azure-marketplace](<https://devfeed.tech/tags/azure-marketplace.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [defender](<https://devfeed.tech/tags/defender.md>), [microsoft-defender](<https://devfeed.tech/tags/microsoft-defender.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

Chainguard Containers is now available through the Microsoft Azure Marketplace, enabling Azure customers to adopt it within existing procurement, billing, deployment, and CI/CD workflows. Microsoft Defender for Cloud can also scan Chainguard container images for vulnerabilities, improving visibility and security across container environments.

### Source excerpt

Chainguard is now listed on the Microsoft Azure Marketplace. In addition, Microsoft Defender for Cloud can now scan Chainguard container images.

## Snyk's Statement on the MITRE CVEs Program Funding Update

DevFeed: [Snyk's Statement on the MITRE CVEs Program Funding Update](<https://devfeed.tech/articles/snyk-s-statement-on-the-mitre-cves-program-funding-update-8186.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyks-statement-on-the-mitre-cves-program-funding-update/>)

Author: Danny Allan

Published: 2025-04-16T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [community](<https://devfeed.tech/tags/community.md>), [cves](<https://devfeed.tech/tags/cves.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [executive](<https://devfeed.tech/tags/executive.md>), [global](<https://devfeed.tech/tags/global.md>), [government](<https://devfeed.tech/tags/government.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-data](<https://devfeed.tech/tags/vulnerability-data.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

Snyk responds to uncertainty about federal funding for MITRE's CVE program and reports that its services and vulnerability data are not immediately affected. The statement emphasizes Snyk's independently curated vulnerability database, its ability as a CVE Numbering Authority to assign CVEs, and its willingness to collaborate on sustaining vulnerability infrastructure.

### Source excerpt

Snyk addresses the recent MITRE CVE funding news, detailing our independent vulnerability data capabilities & commitment to cybersecurity resilience.

## FedRAMP vulnerability scanning requirements explained

DevFeed: [FedRAMP vulnerability scanning requirements explained](<https://devfeed.tech/articles/fedramp-vulnerability-scanning-requirements-explained-13042.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/fedramp-vulnerability-scanning-requirements-explained>)

Author: Can secure-by-default container images or VMs speed up FedRAMP authorization

Published: 2024-11-21T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [Containers](<https://devfeed.tech/topics/containers.md>)

Tags: [audits](<https://devfeed.tech/tags/audits.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [automated](<https://devfeed.tech/tags/automated.md>), [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cve](<https://devfeed.tech/tags/cve.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fips](<https://devfeed.tech/tags/fips.md>), [requirements](<https://devfeed.tech/tags/requirements.md>), [security](<https://devfeed.tech/tags/security.md>), [stigs](<https://devfeed.tech/tags/stigs.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

This article explains FedRAMP vulnerability scanning requirements, including the required scan scope, recurring authenticated scans, reporting expectations, remediation timelines, and the role of scan data in continuous monitoring, authorization evidence, POA&Ms, and risk reviews.

### Source excerpt

Understand FedRAMP vulnerability scanning rules, scope, and SLAs. Get compliance clarity and learn how to simplify audits.

## Snyk Code now secures AI builds with support for LLM sources

DevFeed: [Snyk Code now secures AI builds with support for LLM sources](<https://devfeed.tech/articles/snyk-code-now-secures-ai-builds-with-support-for-llm-sources-8119.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-code-secures-ai-builds/>)

Author: Liqian Lim (林利蒨); Ranko Cupovic

Published: 2024-06-25T13:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk](<https://devfeed.tech/topics/snyk.md>), [snyk-code](<https://devfeed.tech/topics/snyk-code.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [Code](<https://devfeed.tech/topics/code.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [ai](<https://devfeed.tech/tags/ai.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [coding](<https://devfeed.tech/tags/coding.md>), [convert-paid](<https://devfeed.tech/tags/convert-paid.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [executive](<https://devfeed.tech/tags/executive.md>), [interest](<https://devfeed.tech/tags/interest.md>), [llms](<https://devfeed.tech/tags/llms.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

Snyk Code has been updated to treat data returned by supported LLM libraries as untrusted sources. It performs taint analysis across data flows, detects unsanitized data reaching sensitive functions or stores, and alerts developers to potential security issues in AI-enabled applications.

### Source excerpt

Snyk Code can now protect the use of supported LLM libraries in source code to detect any security issues and promptly alert users. Book a live demo.

## Vulnerability fixes in plain sight: How your scanners are missing hundreds of vulnerabilities

DevFeed: [Vulnerability fixes in plain sight: How your scanners are missing hundreds of vulnerabilities](<https://devfeed.tech/articles/vulnerability-fixes-in-plain-sight-how-your-scanners-are-missing-hundreds-of-vulnerabilities-13312.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/vulnerability-fixes-in-plain-sight-how-your-scanners-are-missing-hundreds-of-vulnerabilities>)

Published: 2024-06-12T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [NVD](<https://devfeed.tech/topics/nvd.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-list](<https://devfeed.tech/tags/cve-list.md>), [cves](<https://devfeed.tech/tags/cves.md>), [nvd](<https://devfeed.tech/tags/nvd.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [remote-code-execution-vulnerability](<https://devfeed.tech/tags/remote-code-execution-vulnerability.md>), [research](<https://devfeed.tech/tags/research.md>), [sca](<https://devfeed.tech/tags/sca.md>), [security](<https://devfeed.tech/tags/security.md>), [software-composition-analysis](<https://devfeed.tech/tags/software-composition-analysis.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-fix](<https://devfeed.tech/tags/vulnerability-fix.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

An analysis of more than 600 Wolfi-packaged projects found over 100 security fixes without associated CVEs. Because vulnerability scanners and SCA tools rely on vulnerability databases such as the NVD, organizations may miss fixes unless they keep software updated.

### Source excerpt

Are your vulnerability scanners missing critical security flaws? Discover how Chainguard's research reveals hundreds of vulnerabilities hiding in plain sight.

## Unlocking Chainguard's container security solutions

DevFeed: [Unlocking Chainguard's container security solutions](<https://devfeed.tech/articles/unlocking-chainguard-s-container-security-solutions-13304.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/unlocking-chainguards-container-security-solutions>)

Published: 2024-03-05T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Docker Hardened Images](<https://devfeed.tech/topics/docker-hardened-images.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-fatigue](<https://devfeed.tech/tags/cve-fatigue.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

This article discusses Chainguard's approach to container security, focusing on minimal hardened container images, SBOMs, signatures, vulnerability scanning, continuous monitoring, and updates. It also considers the operational trade-offs between building container images internally and using managed solutions.

### Source excerpt

Uncover insights on whether to build or buy in container lifecycle management with tips from Chainguard, balancing security and operational needs.

## Strengthening your software supply chain security

DevFeed: [Strengthening your software supply chain security](<https://devfeed.tech/articles/strengthening-your-software-supply-chain-security-13242.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/strengthening-your-software-supply-chain-security>)

Published: 2024-01-08T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Software](<https://devfeed.tech/topics/software.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [snyk](<https://devfeed.tech/topics/snyk.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cve](<https://devfeed.tech/tags/cve.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [grype](<https://devfeed.tech/tags/grype.md>), [image](<https://devfeed.tech/tags/image.md>), [reproducible-builds](<https://devfeed.tech/tags/reproducible-builds.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [software](<https://devfeed.tech/tags/software.md>), [solarwinds](<https://devfeed.tech/tags/solarwinds.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

This article explains software supply chain risks from open-source and third-party components, using the SolarWinds attack as an example. It recommends verifying artifacts, signing container images, minimizing dependencies, updating software, scanning for vulnerabilities, using smaller base images, adopting reproducible builds, and increasing SLSA maturity.

### Source excerpt

Secure your codebase with advanced supply chain security tactics: artifact authentication, minimal images and more from Chainguard.

## How a false negative obscured CVE-2023-2454 in a PostgreSQL image

DevFeed: [How a false negative obscured CVE-2023-2454 in a PostgreSQL image](<https://devfeed.tech/articles/the-haunting-of-cve-2023-2454-a-developer-s-nightmare-13255.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-haunting-of-cve-2023-2454-a-developers-nightmare>)

Published: 2023-10-03T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [container-security](<https://devfeed.tech/topics/container-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [trivy](<https://devfeed.tech/topics/trivy.md>), [PostgreSQL](<https://devfeed.tech/topics/postgresql.md>)

Tags: [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cve-2023-2454](<https://devfeed.tech/tags/cve-2023-2454.md>), [false-negative](<https://devfeed.tech/tags/false-negative.md>), [postgresql](<https://devfeed.tech/tags/postgresql.md>), [trivy](<https://devfeed.tech/tags/trivy.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-scanner](<https://devfeed.tech/tags/vulnerability-scanner.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

The article explains how insufficient vulnerability database metadata can cause a scanner to miss CVE-2023-2454 in a PostgreSQL image. It presents Chainguard Images as often containing fixes for vulnerabilities that scanners miss.

### Source excerpt

Unearth a haunting tale of overlooked threats in scanning. Discover how Chainguard Images counteract gaps, ensuring robust defense against CVEs.

## Streamline dependency updates with Mergify and Snyk

DevFeed: [Streamline dependency updates with Mergify and Snyk](<https://devfeed.tech/articles/streamline-dependency-updates-with-mergify-and-snyk-7887.md>)

Original publisher: [Read original article](<https://snyk.io/blog/dependency-updates-mergify-snyk/>)

Author: Liran Tal

Published: 2023-08-23T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Dependency management](<https://devfeed.tech/topics/dependency-management.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [pull-requests](<https://devfeed.tech/topics/pull-requests.md>), [ci](<https://devfeed.tech/topics/ci.md>), [Code review](<https://devfeed.tech/topics/code-review.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [snyk-open-source](<https://devfeed.tech/topics/snyk-open-source.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [automation](<https://devfeed.tech/tags/automation.md>), [blog](<https://devfeed.tech/tags/blog.md>), [ci](<https://devfeed.tech/tags/ci.md>), [code-review](<https://devfeed.tech/tags/code-review.md>), [dependabot](<https://devfeed.tech/tags/dependabot.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [github](<https://devfeed.tech/tags/github.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

This article explains how Mergify and Snyk can automate dependency update workflows. Snyk identifies dependency updates and creates GitHub pull requests, while Mergify can automate pull request review and merging based on defined conditions, helping teams keep dependencies current and address security fixes with less manual work.

### Source excerpt

Automate dependency updates with Mergify and Snyk.

## Fuzzy CVEs, tarfiles, and untrusted input

DevFeed: [Fuzzy CVEs, tarfiles, and untrusted input](<https://devfeed.tech/articles/fuzzy-cves-tarfiles-and-untrusted-input-13056.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/fuzzy-cves-tarfiles-and-untrusted-input>)

Published: 2023-07-27T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [common vulnerabilities and exposures](<https://devfeed.tech/topics/common-vulnerabilities-and-exposures.md>), [Python](<https://devfeed.tech/topics/python.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [NVD](<https://devfeed.tech/topics/nvd.md>)

Tags: [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cves](<https://devfeed.tech/tags/cves.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [go](<https://devfeed.tech/tags/go.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [nvd](<https://devfeed.tech/tags/nvd.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [python](<https://devfeed.tech/tags/python.md>), [scanner](<https://devfeed.tech/tags/scanner.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [vulnerability-scanner](<https://devfeed.tech/tags/vulnerability-scanner.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

This article examines CVE-2007-4559 in Python's tarfile module, why the 15-year-old issue may still appear in security scanners, and why its classification as a vulnerability is disputed. It discusses CVE processes, NVD entries, open-source maintainer constraints, and the risks of extracting untrusted tarfile inputs.

### Source excerpt

Navigate fuzzy CVEs, tarfiles, and untrusted input with Chainguard, paving the way to secure coding practices.

## How Chainguard fixes vulnerabilities before they're detected

DevFeed: [How Chainguard fixes vulnerabilities before they're detected](<https://devfeed.tech/articles/how-chainguard-fixes-vulnerabilities-before-they-re-detected-13083.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-chainguard-fixes-vulnerabilities-before-theyre-detected>)

Published: 2023-07-14T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Go](<https://devfeed.tech/topics/go.md>), [Security](<https://devfeed.tech/topics/security.md>), [Software](<https://devfeed.tech/topics/software.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>), [HTTP](<https://devfeed.tech/topics/http.md>), [releases](<https://devfeed.tech/topics/releases.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [OAI-PMH](<https://devfeed.tech/topics/oai-pmh.md>)

Tags: [automated](<https://devfeed.tech/tags/automated.md>), [base-images](<https://devfeed.tech/tags/base-images.md>), [build](<https://devfeed.tech/tags/build.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cve](<https://devfeed.tech/tags/cve.md>), [go](<https://devfeed.tech/tags/go.md>), [http](<https://devfeed.tech/tags/http.md>), [image-cves](<https://devfeed.tech/tags/image-cves.md>), [library](<https://devfeed.tech/tags/library.md>), [net](<https://devfeed.tech/tags/net.md>), [repo](<https://devfeed.tech/tags/repo.md>), [scanner](<https://devfeed.tech/tags/scanner.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard describes how Wolfi rapidly remediated CVE-2023-29406 in Go by automating upstream release monitoring, package rebuilding, testing, review, and release. The article explains that the fix reached Wolfi-packaged Go applications before vulnerability scanners had the information needed to detect it, and that the updated Go image and dependent packages were rebuilt to include the fix.

### Source excerpt

Uncover Chainguard's strategic vulnerability remediation, enhancing your software's security posture.

## Celebrating 5 years of NTIA's SBOM work

DevFeed: [Celebrating 5 years of NTIA's SBOM work](<https://devfeed.tech/articles/celebrating-5-years-of-ntia-s-sbom-work-12919.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/celebrating-5-years-of-ntias-sbom-work>)

Published: 2023-06-07T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [distroless](<https://devfeed.tech/topics/distroless.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [openvex](<https://devfeed.tech/tags/openvex.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-dark-matter](<https://devfeed.tech/tags/software-dark-matter.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [sofware-supply-chain](<https://devfeed.tech/tags/sofware-supply-chain.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>), [vex](<https://devfeed.tech/tags/vex.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

The article commemorates five years of the NTIA's Software Bill of Materials work and reviews the development of SBOMs as a foundation of software supply chain security. It describes the NTIA's initiative, its multi-stakeholder guidelines, and CISA's continuing role in advancing software transparency.

### Source excerpt

Celebrate 5 transformative years of SBOM work with Chainguard, reflecting on the journey of software bill of materials.

## Fortify, comply and conquer FedRAMP with Chainguard Images

DevFeed: [Fortify, comply and conquer FedRAMP with Chainguard Images](<https://devfeed.tech/articles/fortify-comply-and-conquer-fedramp-with-chainguard-images-13052.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/fortify-comply-and-conquer-fedramp-with-chainguard-images>)

Published: 2023-05-25T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Linux](<https://devfeed.tech/topics/linux.md>)

Tags: [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cve](<https://devfeed.tech/tags/cve.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fips](<https://devfeed.tech/tags/fips.md>), [hardened-image](<https://devfeed.tech/tags/hardened-image.md>), [linux](<https://devfeed.tech/tags/linux.md>), [nist](<https://devfeed.tech/tags/nist.md>), [secure-container-image](<https://devfeed.tech/tags/secure-container-image.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

This article explains how Chainguard Images can help cloud service providers and federal agencies achieve or maintain FedRAMP authorization. It describes FedRAMP requirements for hardened container images, recurring vulnerability scanning, NVD identifiers, CVSSv3 scores, and vulnerability remediation tracking. It presents Chainguard Images as secure, continuously updated base images built from source on the hardened Wolfi Linux un-distribution.

### Source excerpt

Learn how Chainguard Images can you achieve or maintain your FedRAMP compliance authorization with secure-by-default base images.

## Chainguard Image now available for prometheus

DevFeed: [Chainguard Image now available for prometheus](<https://devfeed.tech/articles/chainguard-image-now-available-for-prometheus-12950.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-image-now-available-for-prometheus>)

Published: 2023-04-14T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Prometheus](<https://devfeed.tech/topics/prometheus.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Go](<https://devfeed.tech/topics/go.md>), [Documentation](<https://devfeed.tech/topics/documentation.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [cosign](<https://devfeed.tech/tags/cosign.md>), [cves](<https://devfeed.tech/tags/cves.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [documentation](<https://devfeed.tech/tags/documentation.md>), [go](<https://devfeed.tech/tags/go.md>), [image](<https://devfeed.tech/tags/image.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [prometheus](<https://devfeed.tech/tags/prometheus.md>), [prometheus-image](<https://devfeed.tech/tags/prometheus-image.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [security](<https://devfeed.tech/tags/security.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [toolchain](<https://devfeed.tech/tags/toolchain.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard announces a Prometheus container image built on Wolfi with a minimal, distroless-style base, hardened toolchain, continuous patching, and fewer reported CVEs. The image includes a default configuration, source-built binaries, SBOMs, signatures, and provenance support.

### Source excerpt

Check out the new Chainguard Image for Prometheus that is minimal in size and contains fewer CVEs than other alternatives.

## Chainguard Image now available for NATS

DevFeed: [Chainguard Image now available for NATS](<https://devfeed.tech/articles/chainguard-image-now-available-for-nats-12948.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-image-now-available-for-nats>)

Published: 2023-03-27T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Messaging](<https://devfeed.tech/topics/messaging.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cli](<https://devfeed.tech/tags/cli.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cosign](<https://devfeed.tech/tags/cosign.md>), [documentation](<https://devfeed.tech/tags/documentation.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [messaging](<https://devfeed.tech/tags/messaging.md>), [minimal-image](<https://devfeed.tech/tags/minimal-image.md>), [nats-image](<https://devfeed.tech/tags/nats-image.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [secure-images](<https://devfeed.tech/tags/secure-images.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard announces a hardened Chainguard Image for NATS, built on Wolfi for containerized workloads. The image includes a development variant with the nats CLI and nsc tool, is reported to be over 50% smaller than comparable options, targets zero known CVEs, and includes source-built binaries, SBOMs, signatures, and provenance information.

### Source excerpt

Learn about our hardened Chainguard Image for NATS, which is built on Wolfi, our secure by default operating system for containerized workloads.

## Chainguard Image now available for Apache Zookeeper

DevFeed: [Chainguard Image now available for Apache Zookeeper](<https://devfeed.tech/articles/chainguard-image-now-available-for-apache-zookeeper-12945.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-image-now-available-for-apache-zookeeper>)

Published: 2023-03-20T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [apache-zookeeper](<https://devfeed.tech/tags/apache-zookeeper.md>), [built-from-source](<https://devfeed.tech/tags/built-from-source.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cosign](<https://devfeed.tech/tags/cosign.md>), [docker-zookeeper](<https://devfeed.tech/tags/docker-zookeeper.md>), [jdk](<https://devfeed.tech/tags/jdk.md>), [kafka-zookeeper](<https://devfeed.tech/tags/kafka-zookeeper.md>), [minimal-image](<https://devfeed.tech/tags/minimal-image.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [secure-images](<https://devfeed.tech/tags/secure-images.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>), [zookeeper-container](<https://devfeed.tech/tags/zookeeper-container.md>), [zookeeper-image](<https://devfeed.tech/tags/zookeeper-image.md>)

### AI overview

Chainguard announces a new Chainguard Image for Apache Zookeeper. Built from source with Wolfi and Chainguard's OpenJDK JRE, the minimal image is hardened for non-root operation and a locked-down filesystem, and is presented as more than 50% smaller than alternatives.

### Source excerpt

New Chainguard Image for Apache Zookeeper is over 50% smaller in size compared to alternatives. Powered by Wolfi, comes with our own JDK, and built from source.

## A purl of wisdom on SBOMs and vulnerabilities

DevFeed: [A purl of wisdom on SBOMs and vulnerabilities](<https://devfeed.tech/articles/a-purl-of-wisdom-on-sboms-and-vulnerabilities-12860.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/a-purl-of-wisdom-on-sboms-and-vulnerabilities>)

Published: 2023-02-14T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>)

Tags: [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [component](<https://devfeed.tech/tags/component.md>), [components](<https://devfeed.tech/tags/components.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [false-positive](<https://devfeed.tech/tags/false-positive.md>), [nvd](<https://devfeed.tech/tags/nvd.md>), [package-url](<https://devfeed.tech/tags/package-url.md>), [purl](<https://devfeed.tech/tags/purl.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [scanner](<https://devfeed.tech/tags/scanner.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-data](<https://devfeed.tech/tags/vulnerability-data.md>), [vulnerability-scanner](<https://devfeed.tech/tags/vulnerability-scanner.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

The article argues that Software Bill of Materials (SBOMs) would be more useful if the National Vulnerability Database (NVD) widely adopted the package URL (purl) naming scheme. Analysis of real scanner false positives suggests that purl information could reduce the false positive rate by more than 50%.

### Source excerpt

SBOMs could be a lot more useful if the NVD implemented widespread usage of the purl naming scheme, which could reduce the false positive rate by over 50%.

[Next page](<https://devfeed.tech/tags/vulnerability-scanning.md?cursor=WyIyMDIzLTAyLTE0VDAwOjAwOjAwKzAwOjAwIiwgIjYxNjk0OGJkLTY0MmYtNDZlNy04MjhiLTgwZmM3MGRlMzdkYyJd>)