# wolfi

Published articles for wolfi.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Faster than the advisory

DevFeed: [Faster than the advisory](<https://devfeed.tech/articles/faster-than-the-advisory-13041.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/faster-than-the-advisory>)

Published: 2026-06-10T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [argo-cd](<https://devfeed.tech/topics/argo-cd.md>), [GitOps](<https://devfeed.tech/topics/gitops.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [anthropic](<https://devfeed.tech/topics/anthropic.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [anthropic](<https://devfeed.tech/tags/anthropic.md>), [argo-cd](<https://devfeed.tech/tags/argo-cd.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [gitops](<https://devfeed.tech/tags/gitops.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [scanner-advisories](<https://devfeed.tech/tags/scanner-advisories.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

The article explains how Chainguard Factory delivered a patched Argo CD version to Wolfi and Chainguard OS before the related security advisory reached GitHub's global advisory database. It argues that automated upstream tracking and rapid remediation are increasingly important because vulnerability exploitation and AI-assisted discovery are outpacing traditional disclosure timelines.

### Source excerpt

Chainguard often ships security fixes before advisories reach scanners. Learn why upstream speed matters in the era of AI-driven exploits.

## Guiding the future of Chainguard OS: Announcing the FUD Committee

DevFeed: [Guiding the future of Chainguard OS: Announcing the FUD Committee](<https://devfeed.tech/articles/guiding-the-future-of-chainguard-os-announcing-the-fud-committee-13077.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/guiding-the-future-of-chainguard-os-announcing-the-fud-committee>)

Published: 2026-01-22T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Linux](<https://devfeed.tech/topics/linux.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-customers](<https://devfeed.tech/tags/chainguard-customers.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [chainguard-steering-committee](<https://devfeed.tech/tags/chainguard-steering-committee.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [requirements](<https://devfeed.tech/tags/requirements.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard announces the Fully User Directed (FUD) Committee, a customer-led steering committee intended to guide the future of Chainguard OS. The committee will represent customer organizations and help shape technical decisions, standards, and the product roadmap around secure, production-scale software supply chain needs.

### Source excerpt

The Chainguard OS Fully User Directed Committee is a customer-led steering committee for Chainguard OS. Learn how you can be a member.

## How Chainguard OS Uses Automated Package Garbage Collection to Reduce Security Risk

DevFeed: [How Chainguard OS Uses Automated Package Garbage Collection to Reduce Security Risk](<https://devfeed.tech/articles/this-shit-is-hard-keeping-chainguard-os-lean-current-and-secure-the-power-of-garbage-collection-13286.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/this-shit-is-hard-keeping-chainguard-os-lean-current-and-secure-the-power-of-garbage-collection>)

Published: 2025-12-05T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [APK](<https://devfeed.tech/topics/apk.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Process](<https://devfeed.tech/topics/process.md>)

Tags: [apk](<https://devfeed.tech/tags/apk.md>), [automated](<https://devfeed.tech/tags/automated.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-operating-system](<https://devfeed.tech/tags/chainguard-operating-system.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [chainguard-wolfi](<https://devfeed.tech/tags/chainguard-wolfi.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cves](<https://devfeed.tech/tags/cves.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [security](<https://devfeed.tech/tags/security.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

The article explains how Chainguard automates garbage collection for Chainguard OS and Wolfi APK repositories. It describes filtering older packages and checking dependencies and image usage before removal to keep repositories current and reduce potential attack surface while preserving image customization workflows.

### Source excerpt

Learn how we keep Chainguard OS and Wolfi lean and secure with automated package garbage collection that cuts attack surface while preserving reproducibility.

## Avoiding Vendor Lock-in with a Compatible, Migration-Friendly, Transparent Container Distro

DevFeed: [Avoiding Vendor Lock-in with a Compatible, Migration-Friendly, Transparent Container Distro](<https://devfeed.tech/articles/avoiding-vendor-lock-in-with-a-compatible-migration-friendly-transparent-container-distro-12895.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/avoiding-vendor-lock-in-with-a-compatible-migration-friendly-transparent-container-distro>)

Published: 2025-09-22T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Containers](<https://devfeed.tech/topics/containers.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [interoperability](<https://devfeed.tech/topics/interoperability.md>), [migration](<https://devfeed.tech/topics/migration.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [toolchain](<https://devfeed.tech/topics/toolchain.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [arm](<https://devfeed.tech/tags/arm.md>), [chainguard-migration](<https://devfeed.tech/tags/chainguard-migration.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [compatibility](<https://devfeed.tech/tags/compatibility.md>), [container](<https://devfeed.tech/tags/container.md>), [distro](<https://devfeed.tech/tags/distro.md>), [linux](<https://devfeed.tech/tags/linux.md>), [migration](<https://devfeed.tech/tags/migration.md>), [migration-guide](<https://devfeed.tech/tags/migration-guide.md>), [oci](<https://devfeed.tech/tags/oci.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [toolchain](<https://devfeed.tech/tags/toolchain.md>), [vendor-lock-in](<https://devfeed.tech/tags/vendor-lock-in.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>), [x86](<https://devfeed.tech/tags/x86.md>)

### AI overview

The article explains how to evaluate a Linux distribution for containerized workloads while reducing vendor lock-in. It emphasizes compatibility with existing toolchains and CI/CD workflows, transparent build processes, migration ease, interoperability, and adherence to standards such as OCI, CycloneDX, and SPDX.

### Source excerpt

Learn how to evaluate and select the right Linux distribution to satisfy your team's needs, simplify migration, and avoid vendor lock-in.

## This Shit is Hard: Inside the Chainguard Factory

DevFeed: [This Shit is Hard: Inside the Chainguard Factory](<https://devfeed.tech/articles/this-shit-is-hard-inside-the-chainguard-factory-13284.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/this-shit-is-hard-inside-the-chainguard-factory>)

Published: 2025-05-27T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Scalability](<https://devfeed.tech/topics/scalability.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [observability](<https://devfeed.tech/topics/observability.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [automation](<https://devfeed.tech/tags/automation.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-factory](<https://devfeed.tech/tags/chainguard-factory.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [linux](<https://devfeed.tech/tags/linux.md>), [observability](<https://devfeed.tech/tags/observability.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [scalability](<https://devfeed.tech/tags/scalability.md>), [speed](<https://devfeed.tech/tags/speed.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard describes how its Factory uses infrastructure, automation, and a custom Kubernetes-based build system to build and test thousands of packages and images. The article says the system replaced GitHub Actions and improved observability, scalability, and usability while supporting CVE remediation targets.

### Source excerpt

The Chainguard Factory combines world-class talent and automation to produce packages and images at a level of speed unmatched by any other Linux distribution.

## Chainguard OS and the Next Generation of Distroless Software Delivery

DevFeed: [Chainguard OS and the Next Generation of Distroless Software Delivery](<https://devfeed.tech/articles/the-distroless-revolution-will-be-chainguarded-13249.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-distroless-revolution-will-be-chainguarded>)

Published: 2025-03-20T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [distroless](<https://devfeed.tech/topics/distroless.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>)

Tags: [beyond-distro](<https://devfeed.tech/tags/beyond-distro.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [chainguard-your-os](<https://devfeed.tech/tags/chainguard-your-os.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [security](<https://devfeed.tech/tags/security.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

This article proposes a next generation of open source software delivery centered on distroless, purpose-built container images and upstream-maintained software packages. It introduces Chainguard OS, which Chainguard describes as continuously rebuilding packages from upstream sources to incorporate security fixes and performance improvements.

### Source excerpt

Chainguard OS is the next generation in open source software delivery. Learn all about the principles and technology that make it possible.

## Have We Reached a Distroless Tipping Point?

DevFeed: [Have We Reached a Distroless Tipping Point?](<https://devfeed.tech/articles/have-we-reached-a-distroless-tipping-point-13080.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/have-we-reached-a-distroless-tipping-point>)

Published: 2025-03-18T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [distroless](<https://devfeed.tech/topics/distroless.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Linux](<https://devfeed.tech/topics/linux.md>)

Tags: [beyond-distro](<https://devfeed.tech/tags/beyond-distro.md>), [cgroups](<https://devfeed.tech/tags/cgroups.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [chainguard-your-os](<https://devfeed.tech/tags/chainguard-your-os.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [containers](<https://devfeed.tech/tags/containers.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [linux](<https://devfeed.tech/tags/linux.md>), [oci](<https://devfeed.tech/tags/oci.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

The article argues that containerization and cloud-native software development have created an inflection point in open source software delivery. It presents the evolution from Linux Containers to Docker and the Open Container Initiative as milestones supporting a shift from traditional Linux distributions toward distroless, secure-by-design, continuously updated software.

### Source excerpt

The world is at an inflection point in open source software delivery. See where the software distribution status quo is at, and what is next.

## Disrupting the Status (Distro)Quo

DevFeed: [Disrupting the Status (Distro)Quo](<https://devfeed.tech/articles/disrupting-the-status-distro-quo-13021.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/disrupting-the-status-distro>)

Published: 2025-03-10T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Open Source](<https://devfeed.tech/topics/open-source.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Operating system](<https://devfeed.tech/topics/operating-system.md>), [releases](<https://devfeed.tech/topics/releases.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [Embedded Software Dev](<https://devfeed.tech/topics/embedded-software-dev.md>)

Tags: [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [debian](<https://devfeed.tech/tags/debian.md>), [distro](<https://devfeed.tech/tags/distro.md>), [embedded-systems](<https://devfeed.tech/tags/embedded-systems.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [linux](<https://devfeed.tech/tags/linux.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [release](<https://devfeed.tech/tags/release.md>), [releases](<https://devfeed.tech/tags/releases.md>), [ubuntu](<https://devfeed.tech/tags/ubuntu.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

This first article in a three-part series traces how UNIX and Linux distributions became the dominant model for delivering open source software. It examines snapshot-based releases, differing release schedules, and the long-term maintenance concerns created by software bundled and frozen in traditional distributions.

### Source excerpt

The traditional "distro" model of open source software delivery is ready for innovation. Learn how we got to this point and what comes next.

## Wolfi Moves to usrmerge Standard

DevFeed: [Wolfi Moves to usrmerge Standard](<https://devfeed.tech/articles/wolfi-moves-to-usrmerge-standard-13339.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/wolfi-moves-to-usrmerge-standard>)

Published: 2025-03-07T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [migration](<https://devfeed.tech/topics/migration.md>), [container images](<https://devfeed.tech/topics/container-images.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [compatibility](<https://devfeed.tech/tags/compatibility.md>), [filesystem](<https://devfeed.tech/tags/filesystem.md>), [layout](<https://devfeed.tech/tags/layout.md>), [linux](<https://devfeed.tech/tags/linux.md>), [migration](<https://devfeed.tech/tags/migration.md>), [standard](<https://devfeed.tech/tags/standard.md>), [usrmerge](<https://devfeed.tech/tags/usrmerge.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard is adopting the usrmerge filesystem layout for Wolfi to improve standardization and compatibility with modern Linux applications and other major distributions. The transition moves binaries and libraries from legacy directories into /usr locations using corresponding symlinks, with the final /lib migration scheduled for June 23, 2025.

### Source excerpt

To enhance standardization and compatibility with modern Linux applications and other major distributions, Chainguard is adopting the usrmerge filesystem layout.

## Building .NET Runtime from Source - The Chainguard Way

DevFeed: [Building .NET Runtime from Source - The Chainguard Way](<https://devfeed.tech/articles/building-net-runtime-from-source-the-chainguard-way-12910.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/building-net-runtime-from-source-the-chainguard-way>)

Published: 2025-02-26T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [.NET](<https://devfeed.tech/topics/net.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>)

Tags: [built-from-source](<https://devfeed.tech/tags/built-from-source.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [integrity](<https://devfeed.tech/tags/integrity.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [net](<https://devfeed.tech/tags/net.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard describes building all .NET 8 and .NET 9 components entirely from source. The approach addresses challenges involving multiple repositories, circular dependencies, prebuilt binary dependencies, and cross-repository changes, while enabling faster CVE remediation, end-to-end integrity, and greater build transparency for .NET container images.

### Source excerpt

Chainguard builds all .NET8 and .NET9 components entirely from source to enable faster CVE remediation, full end-to-end integrity, and build transparency.

## Panic! At The Distro: A Study of Malware Prevention in Linux Distributions

DevFeed: [Panic! At The Distro: A Study of Malware Prevention in Linux Distributions](<https://devfeed.tech/articles/panic-at-the-distro-a-study-of-malware-prevention-in-linux-distributions-13202.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/panic-at-the-distro-a-study-of-malware-prevention-in-linux-distributions>)

Published: 2024-12-17T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Linux](<https://devfeed.tech/topics/linux.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Benchmark](<https://devfeed.tech/topics/benchmark.md>), [dataset](<https://devfeed.tech/topics/dataset.md>)

Tags: [alpine](<https://devfeed.tech/tags/alpine.md>), [benchmark](<https://devfeed.tech/tags/benchmark.md>), [dataset](<https://devfeed.tech/tags/dataset.md>), [debian](<https://devfeed.tech/tags/debian.md>), [distribution](<https://devfeed.tech/tags/distribution.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [linux](<https://devfeed.tech/tags/linux.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [malware](<https://devfeed.tech/tags/malware.md>), [malware-prevention](<https://devfeed.tech/tags/malware-prevention.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [reproducible-builds](<https://devfeed.tech/tags/reproducible-builds.md>), [research](<https://devfeed.tech/tags/research.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard studies malware prevention in Linux distributions through maintainer interviews and a Linux package malware benchmark dataset. The study reports that most interviewed distributions do not proactively scan repositories, while existing open-source malware scanners often produce false positives.

### Source excerpt

Chainguard wanted to know more about malware prevention in Linux distributions. So we did a study to see what maintainers are doing about it. See the results.

## Wolfi's upstream security inspection: Scanning with OpenSSF Scorecard

DevFeed: [Wolfi's upstream security inspection: Scanning with OpenSSF Scorecard](<https://devfeed.tech/articles/wolfi-s-upstream-security-inspection-scanning-with-openssf-scorecard-13340.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/wolfis-upstream-security-inspection-scanning-with-openssf-scorecard>)

Published: 2024-08-02T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [openssf](<https://devfeed.tech/topics/openssf.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>)

Tags: [chainguard-labs](<https://devfeed.tech/tags/chainguard-labs.md>), [github](<https://devfeed.tech/tags/github.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [openssf](<https://devfeed.tech/tags/openssf.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard Labs evaluated the security of 1,511 upstream Wolfi repositories using the OpenSSF Scorecard. The mean score was 5.4 out of 10; repositories associated with Ruby and C packages had lower average scores of 4.8 and 4.7, respectively.

### Source excerpt

Chainguard Labs analyzed the security of 1,500+ upstream Wolfi repositories using the OpenSSF Scorecard tool -- uncover the key findings in the latest research.

## Chainguard enhances security with OSV advisory feed

DevFeed: [Chainguard enhances security with OSV advisory feed](<https://devfeed.tech/articles/chainguard-enhances-security-with-osv-advisory-feed-12943.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-enhances-security-with-osv-advisory-feed>)

Published: 2024-07-02T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [data](<https://devfeed.tech/topics/data.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Google](<https://devfeed.tech/topics/google.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [google](<https://devfeed.tech/tags/google.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-vulnerabilities](<https://devfeed.tech/tags/open-source-vulnerabilities.md>), [openssf](<https://devfeed.tech/tags/openssf.md>), [osv](<https://devfeed.tech/tags/osv.md>), [secure-open-source](<https://devfeed.tech/tags/secure-open-source.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-data](<https://devfeed.tech/tags/vulnerability-data.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard is publishing its security advisory feed in the OSV format, improving the precision and usability of vulnerability information for open source maintainers and downstream consumers.

### Source excerpt

Explore Chainguard's new OSV advisory feed, delivering comprehensive and up-to-date vulnerability information to enhance your security posture.

## Vulnerability fixes in plain sight: How your scanners are missing hundreds of vulnerabilities

DevFeed: [Vulnerability fixes in plain sight: How your scanners are missing hundreds of vulnerabilities](<https://devfeed.tech/articles/vulnerability-fixes-in-plain-sight-how-your-scanners-are-missing-hundreds-of-vulnerabilities-13312.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/vulnerability-fixes-in-plain-sight-how-your-scanners-are-missing-hundreds-of-vulnerabilities>)

Published: 2024-06-12T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [NVD](<https://devfeed.tech/topics/nvd.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-list](<https://devfeed.tech/tags/cve-list.md>), [cves](<https://devfeed.tech/tags/cves.md>), [nvd](<https://devfeed.tech/tags/nvd.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [remote-code-execution-vulnerability](<https://devfeed.tech/tags/remote-code-execution-vulnerability.md>), [research](<https://devfeed.tech/tags/research.md>), [sca](<https://devfeed.tech/tags/sca.md>), [security](<https://devfeed.tech/tags/security.md>), [software-composition-analysis](<https://devfeed.tech/tags/software-composition-analysis.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-fix](<https://devfeed.tech/tags/vulnerability-fix.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

An analysis of more than 600 Wolfi-packaged projects found over 100 security fixes without associated CVEs. Because vulnerability scanners and SCA tools rely on vulnerability databases such as the NVD, organizations may miss fixes unless they keep software updated.

### Source excerpt

Are your vulnerability scanners missing critical security flaws? Discover how Chainguard's research reveals hundreds of vulnerabilities hiding in plain sight.

## Migrating a Node.js application to Chainguard Images

DevFeed: [Migrating a Node.js application to Chainguard Images](<https://devfeed.tech/articles/migrating-a-node-js-application-to-chainguard-images-13157.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/migrating-a-node-js-application-to-chainguard-images>)

Published: 2024-06-05T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Node.js](<https://devfeed.tech/topics/node-js.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [Docker](<https://devfeed.tech/topics/docker.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [debian](<https://devfeed.tech/tags/debian.md>), [docker](<https://devfeed.tech/tags/docker.md>), [express](<https://devfeed.tech/tags/express.md>), [minimal-image](<https://devfeed.tech/tags/minimal-image.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [node-js-migration](<https://devfeed.tech/tags/node-js-migration.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

A tutorial on migrating a containerized Node.js application from the official Node image to Chainguard Images. It covers dependency updates, moving from restify to express, adapting Dockerfile build steps for Wolfi, and using minimal images to reduce container size, tooling, and known vulnerabilities.

### Source excerpt

Secure and streamline your Node.js applications with Chainguard Images. Learn how to migrate seamlessly and enhance your software supply chain security.

## Wolfi at work: Minimal developer workstations in the cloud

DevFeed: [Wolfi at work: Minimal developer workstations in the cloud](<https://devfeed.tech/articles/wolfi-at-work-minimal-developer-workstations-in-the-cloud-13338.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/wolfi-at-work-minimal-developer-workstations-in-the-cloud>)

Published: 2024-05-29T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Cloud](<https://devfeed.tech/topics/cloud.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [Security](<https://devfeed.tech/topics/security.md>), [Visual Studio Code](<https://devfeed.tech/topics/visual-studio-code.md>), [ssh](<https://devfeed.tech/topics/ssh.md>)

Tags: [automation](<https://devfeed.tech/tags/automation.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [developer](<https://devfeed.tech/tags/developer.md>), [ephemerality](<https://devfeed.tech/tags/ephemerality.md>), [linux](<https://devfeed.tech/tags/linux.md>), [minimalism](<https://devfeed.tech/tags/minimalism.md>), [security](<https://devfeed.tech/tags/security.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [terraform](<https://devfeed.tech/tags/terraform.md>), [visual-studio-code](<https://devfeed.tech/tags/visual-studio-code.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard describes using minimal Wolfi-based cloud workstations to provide standardized, ephemeral development environments for engineers. The workstations use regularly rebuilt and attested images, automatic timeouts, and Terraform-managed resources to keep packages current and reduce configuration differences.

### Source excerpt

Secure development environments with cloud workstations powered by Chainguard's Wolfi. Learn how to reduce attack surface and improve developer productivity.

## Reducing vulnerabilities in Backstage with Chainguard's Wolfi

DevFeed: [Reducing vulnerabilities in Backstage with Chainguard's Wolfi](<https://devfeed.tech/articles/reducing-vulnerabilities-in-backstage-with-chainguard-s-wolfi-13207.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/reducing-vulnerabilities-in-backstage-with-chainguards-wolfi>)

Published: 2024-05-16T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Backstage](<https://devfeed.tech/topics/backstage.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [internal developer portal](<https://devfeed.tech/topics/internal-developer-portal.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Developer experience](<https://devfeed.tech/topics/developer-experience.md>), [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>)

Tags: [backstage](<https://devfeed.tech/tags/backstage.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [developer-experience](<https://devfeed.tech/tags/developer-experience.md>), [developer-portal](<https://devfeed.tech/tags/developer-portal.md>), [docker](<https://devfeed.tech/tags/docker.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

This guest post describes how American Airlines evaluated Chainguard's Wolfi and wolfi-base image as an alternative base for its Backstage developer portal. The author reports that the original base image contained 74 vulnerabilities and that the default Docker build added 330 more, motivating a Dockerfile refactoring effort focused on reducing packages, image size, vulnerabilities, and software supply-chain risk while maintaining compatibility.

### Source excerpt

Learn how American Airlines enhanced Backstage security with Chainguard's Wolfi.

## Changes to static, Git, and BusyBox Developer Images

DevFeed: [Changes to static, Git, and BusyBox Developer Images](<https://devfeed.tech/articles/changes-to-static-git-and-busybox-developer-images-13001.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/changes-to-static-git-and-busybox-developer-images>)

Published: 2024-05-15T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Docker Hub](<https://devfeed.tech/topics/docker-hub.md>)

Tags: [alpine](<https://devfeed.tech/tags/alpine.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-hub](<https://devfeed.tech/tags/docker-hub.md>), [security](<https://devfeed.tech/tags/security.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>), [x86](<https://devfeed.tech/tags/x86.md>)

### AI overview

Chainguard is moving its static, Git, and BusyBox Developer Images from Alpine Linux bases to Wolfi bases on July 15, 2024, to improve their security posture. Users should test the Wolfi-based images beforehand, especially when using unsupported architectures or Alpine-specific behavior. Alpine-based alternatives are available on ghcr.io for some cases, but they will not receive monitoring or be synchronized to Docker Hub.

### Source excerpt

Learn about the latest changes to Chainguard's static, git and busybox Developer Images. Enhance your software development with improved security and efficiency.

## A more secure (and smaller) Big Bang

DevFeed: [A more secure (and smaller) Big Bang](<https://devfeed.tech/articles/a-more-secure-and-smaller-big-bang-12859.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/a-more-secure-and-smaller-big-bang>)

Published: 2024-04-09T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [big-bang](<https://devfeed.tech/tags/big-bang.md>), [certificate-to-field](<https://devfeed.tech/tags/certificate-to-field.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [ctf](<https://devfeed.tech/tags/ctf.md>), [cves](<https://devfeed.tech/tags/cves.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [hardened-container-image](<https://devfeed.tech/tags/hardened-container-image.md>), [iron-bank](<https://devfeed.tech/tags/iron-bank.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [platform-one](<https://devfeed.tech/tags/platform-one.md>), [releases](<https://devfeed.tech/tags/releases.md>), [united-states-air-force](<https://devfeed.tech/tags/united-states-air-force.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard is working with Iron Bank to mirror Chainguard Images for the core Big Bang images, offering a drop-in alternative for Big Bang's secure software factory. The article reports a 100% reduction in CVEs, a 40% reduction in software components, and a 72% reduction in image size, with more than 30 images covering all eight core components.

### Source excerpt

Chainguard enhances Big Bang with secure, smaller images: 100% fewer CVEs, 40% less components, 72% size reduction for fortified security.

## Chainguard patches 3 "silent" Golang CVEs in under 24 hours

DevFeed: [Chainguard patches 3 "silent" Golang CVEs in under 24 hours](<https://devfeed.tech/articles/chainguard-patches-3-silent-golang-cves-in-under-24-hours-12975.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-patches-3-silent-golang-cves-in-under-24-hours>)

Published: 2024-03-21T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Go](<https://devfeed.tech/topics/go.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [toolchain](<https://devfeed.tech/topics/toolchain.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>), [Linux](<https://devfeed.tech/topics/linux.md>)

Tags: [automation](<https://devfeed.tech/tags/automation.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cves](<https://devfeed.tech/tags/cves.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [github](<https://devfeed.tech/tags/github.md>), [go](<https://devfeed.tech/tags/go.md>), [golang](<https://devfeed.tech/tags/golang.md>), [golang-patch](<https://devfeed.tech/tags/golang-patch.md>), [linux](<https://devfeed.tech/tags/linux.md>), [melange](<https://devfeed.tech/tags/melange.md>), [merge](<https://devfeed.tech/tags/merge.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [safe-source-for-open-source](<https://devfeed.tech/tags/safe-source-for-open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [silent-cve](<https://devfeed.tech/tags/silent-cve.md>), [tooling](<https://devfeed.tech/tags/tooling.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard describes how it patched three Golang CVEs in under 24 hours. Its automation monitored new Go releases, opened a pull request, rebuilt the Wolfi package, and updated Chainguard Images containing Go.

### Source excerpt

See how Chainguard swiftly patched three Golang CVEs in under 24 hours, showcasing rapid response and dedication to secure software.

## Get 'em while they're hot! How and why Wolfi releases are so fast

DevFeed: [Get 'em while they're hot! How and why Wolfi releases are so fast](<https://devfeed.tech/articles/get-em-while-they-re-hot-how-and-why-wolfi-releases-are-so-fast-13058.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/get-em-while-theyre-hot-how-and-why-wolfi-releases-are-so-fast>)

Published: 2024-02-22T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [releases](<https://devfeed.tech/topics/releases.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Linux](<https://devfeed.tech/topics/linux.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [github](<https://devfeed.tech/tags/github.md>), [releases](<https://devfeed.tech/tags/releases.md>), [security-solutions](<https://devfeed.tech/tags/security-solutions.md>), [upstream-release](<https://devfeed.tech/tags/upstream-release.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

The article explains how Wolfi achieves rapid package updates, with more than 80% completed within 24 hours and a median update time of four hours. It connects this speed to reducing known vulnerabilities in Chainguard Images.

### Source excerpt

Explore Wolfi's speedy updates: A key to securing Chainguard Images against vulnerabilities and delivering up-to-date software swiftly.

## Reimagining the Linux distro with Wolfi

DevFeed: [Reimagining the Linux distro with Wolfi](<https://devfeed.tech/articles/reimagining-the-linux-distro-with-wolfi-13209.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/reimagining-the-linux-distro-with-wolfi>)

Published: 2024-02-21T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Linux](<https://devfeed.tech/topics/linux.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Package Management](<https://devfeed.tech/topics/package-management.md>), [APK](<https://devfeed.tech/topics/apk.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [apk](<https://devfeed.tech/tags/apk.md>), [apko](<https://devfeed.tech/tags/apko.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cve](<https://devfeed.tech/tags/cve.md>), [linux](<https://devfeed.tech/tags/linux.md>), [melange](<https://devfeed.tech/tags/melange.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [package-management](<https://devfeed.tech/tags/package-management.md>), [secure-container-images](<https://devfeed.tech/tags/secure-container-images.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

The article explains why Chainguard created Wolfi, a minimal Linux distribution designed for modern container use. It describes the roles of Melange for building APK packages and Apko for assembling reproducible container images, along with Wolfi's security advisory and vulnerability-management capabilities.

### Source excerpt

Discover Wolfi: Chainguard's answer to modern container security, creating minimal, secure Linux distributions for today's needs.

## Continuous hardening of Chainguard's internal software supply chain

DevFeed: [Continuous hardening of Chainguard's internal software supply chain](<https://devfeed.tech/articles/continuous-hardening-of-chainguard-s-internal-software-supply-chain-13013.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/continuous-hardening-of-chainguards-internal-software-supply-chain>)

Published: 2024-02-21T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [Security](<https://devfeed.tech/topics/security.md>), [Docker Compose](<https://devfeed.tech/topics/docker-compose.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cosign](<https://devfeed.tech/tags/cosign.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [github-vulnerability](<https://devfeed.tech/tags/github-vulnerability.md>), [hardending](<https://devfeed.tech/tags/hardending.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [integrity](<https://devfeed.tech/tags/integrity.md>), [least-privilege](<https://devfeed.tech/tags/least-privilege.md>), [minimalism](<https://devfeed.tech/tags/minimalism.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [terraform-provider](<https://devfeed.tech/tags/terraform-provider.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard describes how it mitigated a potentially vulnerable GitHub Actions workflow that could have affected the integrity of Docker images signed by its cosign Terraform Provider. The team responded within 24 hours and explains how least privilege, minimal defaults, and dependency minimization support software supply chain security.

### Source excerpt

See how Chainguard mitigated the potential vulnerable GitHub actions workflow "Pwn request" in less than 24 hours.

## Wolfi's approach to container security and CVE management

DevFeed: [Wolfi's approach to container security and CVE management](<https://devfeed.tech/articles/revolutionizing-container-security-and-cve-management-13213.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/revolutionizing-container-security-and-cve-management>)

Published: 2024-02-08T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [container-security](<https://devfeed.tech/topics/container-security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [apko](<https://devfeed.tech/tags/apko.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-management](<https://devfeed.tech/tags/cve-management.md>), [melange](<https://devfeed.tech/tags/melange.md>), [oci](<https://devfeed.tech/tags/oci.md>), [secure-images](<https://devfeed.tech/tags/secure-images.md>), [secure-software-supply-chain](<https://devfeed.tech/tags/secure-software-supply-chain.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

The article explains how Wolfi, a secure-by-default undistro, supports container security by helping create minimal, reproducible OCI-compliant images and reducing software supply chain risks. It also describes how Wolfi powers Chainguard Images.

### Source excerpt

Discover Wolfi, the 'secure-by-default' undistro for container security, enhancing open-source software with minimal CVE counts and robust protection.

[Next page](<https://devfeed.tech/tags/wolfi.md?cursor=WyIyMDI0LTAyLTA4VDAwOjAwOjAwKzAwOjAwIiwgIjU2ZWJkNzUwLTIwMjktNDI5YS1iNDIxLWM5ZDA5NTk0ZjNlMSJd>)