# zero cves

Published articles for zero cves.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Building a category: Chainguard named a Leader in the inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security

DevFeed: [Building a category: Chainguard named a Leader in the inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security](<https://devfeed.tech/articles/building-a-category-chainguard-named-a-leader-in-the-inaugural-gartner-magic-quadranttm-for-software-supply-chain-security-12901.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/building-a-category-chainguard-named-a-leader-in-the-inaugural-gartner-magic-quadrant-for-software-supply-chain-security>)

Published: 2026-06-22T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-gartner](<https://devfeed.tech/tags/chainguard-gartner.md>), [chainguard-gartner-mq](<https://devfeed.tech/tags/chainguard-gartner-mq.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [gartner](<https://devfeed.tech/tags/gartner.md>), [gartner-magic-quadrant](<https://devfeed.tech/tags/gartner-magic-quadrant.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [software-supply-chain-security-gartner](<https://devfeed.tech/tags/software-supply-chain-security-gartner.md>), [software-supply-chain-security-mq](<https://devfeed.tech/tags/software-supply-chain-security-mq.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

Chainguard's article discusses its recognition as a Leader in Gartner's inaugural Magic Quadrant for Software Supply Chain Security. It argues that accelerating vulnerability exploitation and AI-assisted development require prevention-oriented, secure-by-default supply chain security. The article highlights Chainguard Containers, which provides minimal container images rebuilt daily from source, with zero CVEs, SBOMs, and verifiable signatures, and briefly introduces Chainguard Libraries.

### Source excerpt

Gartner names Chainguard a Leader in Software Supply Chain Security, highlighting its secure-by-default approach and market vision.

## Going deep: Upstream distros and hidden CVEs

DevFeed: [Going deep: Upstream distros and hidden CVEs](<https://devfeed.tech/articles/going-deep-upstream-distros-and-hidden-cves-13069.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/going-deep-upstream-distros-and-hidden-cves>)

Published: 2026-02-25T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Docker Hardened Images](<https://devfeed.tech/topics/docker-hardened-images.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Debian](<https://devfeed.tech/topics/debian.md>), [Docker](<https://devfeed.tech/topics/docker.md>)

Tags: [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [debian](<https://devfeed.tech/tags/debian.md>), [debian-containers](<https://devfeed.tech/tags/debian-containers.md>), [dhi](<https://devfeed.tech/tags/dhi.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-containers](<https://devfeed.tech/tags/docker-containers.md>), [docker-hardened-images](<https://devfeed.tech/tags/docker-hardened-images.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vex](<https://devfeed.tech/tags/vex.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

The article argues that container vendors relying on upstream distributions such as Debian or Alpine can inherit vulnerabilities because fixes may lag between upstream availability and downstream image releases. It examines Docker Hardened Images and claims that some CVEs are suppressed through no-DSA classifications and VEX documents even when fixes exist upstream but have not been incorporated into the images.

### Source excerpt

Are all zero-CVE images truly secure? A deep dive into Debian no-DSA, VEX suppression, and why transparency matters in container supply chain security.

## How Chainguard Automated Detection and Patching of a High-Severity CVE

DevFeed: [How Chainguard Automated Detection and Patching of a High-Severity CVE](<https://devfeed.tech/articles/this-shit-is-hard-the-life-and-death-of-a-cve-in-the-chainguard-factory-13291.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/this-shit-is-hard-the-life-and-death-of-a-cve-in-the-chainguard-factory>)

Published: 2026-02-13T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [anchore](<https://devfeed.tech/topics/anchore.md>), [grype](<https://devfeed.tech/topics/grype.md>), [ci](<https://devfeed.tech/topics/ci.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [anchore](<https://devfeed.tech/tags/anchore.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-cve-remediation](<https://devfeed.tech/tags/chainguard-cve-remediation.md>), [chainguard-factory](<https://devfeed.tech/tags/chainguard-factory.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [ci](<https://devfeed.tech/tags/ci.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [github](<https://devfeed.tech/tags/github.md>), [grype](<https://devfeed.tech/tags/grype.md>), [pull-request](<https://devfeed.tech/tags/pull-request.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

The article describes how Chainguard's Factory detected a high-severity vulnerability affecting k9s, updated Grype, opened and merged a pull request, and published a fixed package within 46 hours of the advisory. It also reports that Chainguard remediated 2,960 unique CVEs in November 2025 while meeting its stated remediation SLA.

### Source excerpt

The Chainguard Factory and DriftlessAF automate CVE detection and patching, delivering fixes in hours and maintaining industry-leading remediation SLAs.

## Why Trusted Software Supply Chains Matter More Than Zero-CVE Container Claims

DevFeed: [Why Trusted Software Supply Chains Matter More Than Zero-CVE Container Claims](<https://devfeed.tech/articles/well-that-escalated-quickly-zero-cves-lots-of-vendors-13314.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/well-that-escalated-quickly-zero-cves-lots-of-vendors>)

Published: 2026-01-15T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Docker Hub](<https://devfeed.tech/topics/docker-hub.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [ceo](<https://devfeed.tech/tags/ceo.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-hub](<https://devfeed.tech/tags/docker-hub.md>), [docker-images](<https://devfeed.tech/tags/docker-images.md>), [echo-security](<https://devfeed.tech/tags/echo-security.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [minimus](<https://devfeed.tech/tags/minimus.md>), [rapidfort](<https://devfeed.tech/tags/rapidfort.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [wiz-images](<https://devfeed.tech/tags/wiz-images.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

Chainguard CEO Dan Lorenc argues that container security depends on trusting the origins and build processes of software, rather than relying primarily on post-hoc image hardening or zero-CVE claims.

### Source excerpt

Chainguard CEO Dan Lorenc explains why real security comes from trusted, from-source software supply chains, not post-hoc hardening or zero-CVE promises.

## Meeting the Zero-CVE Mandate: How Chainguard Helps Businesses Ship Secure Software That Customers Trust

DevFeed: [Meeting the Zero-CVE Mandate: How Chainguard Helps Businesses Ship Secure Software That Customers Trust](<https://devfeed.tech/articles/meeting-the-zero-cve-mandate-how-chainguard-helps-businesses-ship-secure-software-that-customers-trust-13155.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/meeting-the-zero-cve-mandate-how-chainguard-helps-businesses-ship-secure-software-that-customers-trust>)

Published: 2025-10-06T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-custom-assembly](<https://devfeed.tech/tags/chainguard-custom-assembly.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cves](<https://devfeed.tech/tags/cves.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

The article explains how Chainguard helps businesses meet stricter software security requirements for self-hosted, cloud, packaged-agent, and embedded software. It focuses on zero known CVEs at delivery, verifiable SBOMs, provenance attestations, compatibility with security tooling, and the challenges of open source dependencies and container images.

### Source excerpt

Chainguard's zero-CVE containers come with broad compatibility, custom assembly, verifiable provenance and SBOMs, and more to help you ship secure software.

## Chainguard Containers Catalog Expands to More Than 1,700 Minimal, Zero-CVE Images

DevFeed: [Chainguard Containers Catalog Expands to More Than 1,700 Minimal, Zero-CVE Images](<https://devfeed.tech/articles/the-industry-s-fastest-growing-secure-container-catalog-13260.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-industrys-fastest-growing-secure-container-catalog>)

Published: 2025-09-09T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>), [Serverless](<https://devfeed.tech/topics/serverless.md>)

Tags: [azure-functions](<https://devfeed.tech/tags/azure-functions.md>), [catalog-pricing](<https://devfeed.tech/tags/catalog-pricing.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cve](<https://devfeed.tech/tags/cve.md>), [pricing](<https://devfeed.tech/tags/pricing.md>), [security](<https://devfeed.tech/tags/security.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

Chainguard describes its Containers catalog, claiming more than 1,700 minimal, zero-CVE images rebuilt daily, over 600 FIPS-compliant images, and expanded support for Java and Azure Functions. It also outlines Catalog Pricing, which provides commercial customers access to the catalog and its underlying packages.

### Source excerpt

Our Chainguard Containers catalog now has more than 1,700 minimal, zero-CVE images, rebuilt from source every day - industry-leading in both breadth and depth.

## Expanding Chainguard VMs: Zero-CVE Application & Base Virtual Machine Images for Cloud and On-Prem

DevFeed: [Expanding Chainguard VMs: Zero-CVE Application & Base Virtual Machine Images for Cloud and On-Prem](<https://devfeed.tech/articles/expanding-chainguard-vms-zero-cve-application-base-virtual-machine-images-for-cloud-and-on-prem-13035.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/expanding-chainguard-vms-zero-cve-application-base-virtual-machine-images-for-cloud-and-on-prem>)

Published: 2025-09-03T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard vms](<https://devfeed.tech/topics/chainguard-vms.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [on-prem](<https://devfeed.tech/topics/on-prem.md>), [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [Java](<https://devfeed.tech/topics/java.md>), [Jenkins](<https://devfeed.tech/topics/jenkins.md>), [nginx](<https://devfeed.tech/topics/nginx.md>), [Python](<https://devfeed.tech/topics/python.md>)

Tags: [chainguard-vms](<https://devfeed.tech/tags/chainguard-vms.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-virtual-machines](<https://devfeed.tech/tags/cloud-virtual-machines.md>), [cve](<https://devfeed.tech/tags/cve.md>), [java](<https://devfeed.tech/tags/java.md>), [jenkins](<https://devfeed.tech/tags/jenkins.md>), [nginx](<https://devfeed.tech/tags/nginx.md>), [on-prem](<https://devfeed.tech/tags/on-prem.md>), [os](<https://devfeed.tech/tags/os.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [python](<https://devfeed.tech/tags/python.md>), [rebuilds](<https://devfeed.tech/tags/rebuilds.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [security-vm-images](<https://devfeed.tech/tags/security-vm-images.md>), [virtual-machine-images](<https://devfeed.tech/tags/virtual-machine-images.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

Chainguard VMs is expanding with zero-CVE application images for Jenkins, Nginx, and Squid Proxy, plus base images for Chainguard OS, Java, and Python. The virtual machine images support cloud and on-premises deployments and are continuously rebuilt from source with automated updates, CVE remediation, and SBOM-driven provenance attestations.

### Source excerpt

Chainguard VMs is expanding with new Application and Base VM Images -- giving teams a secure, zero-CVE foundation to build and innovate faster.

## Discover the Value of Chainguard Containers with the Value Calculator

DevFeed: [Discover the Value of Chainguard Containers with the Value Calculator](<https://devfeed.tech/articles/discover-the-value-of-chainguard-containers-with-the-value-calculator-13020.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/discover-the-value-of-chainguard-containers-with-the-value-calculator>)

Published: 2025-08-28T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Tool](<https://devfeed.tech/topics/tool.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [business-value](<https://devfeed.tech/tags/business-value.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-roi](<https://devfeed.tech/tags/chainguard-roi.md>), [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [developers](<https://devfeed.tech/tags/developers.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [tool](<https://devfeed.tech/tags/tool.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

Chainguard introduces a self-serve Value Calculator that estimates the organizational value of adopting Chainguard Containers. The tool uses metrics such as developer count, revenue, container-image usage, CVE remediation time, hardening effort, organizational maturity, industry, and compliance requirements to estimate potential gains from reducing engineering toil, mitigating risk, and supporting revenue growth.

### Source excerpt

Chainguard's Value Calculator is a new tool we created to make it easy to quantify the value of using Chainguard Containers for your specific organization.

## No CVEs, No Surprises: Chainguard and the UK Software Security Code of Practice

DevFeed: [No CVEs, No Surprises: Chainguard and the UK Software Security Code of Practice](<https://devfeed.tech/articles/no-cves-no-surprises-chainguard-and-the-uk-software-security-code-of-practice-13187.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/no-cves-no-surprises-chainguard-and-the-uk-software-security-code-of-practice>)

Published: 2025-06-09T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [sdlc](<https://devfeed.tech/topics/sdlc.md>), [Development](<https://devfeed.tech/topics/development.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [emea](<https://devfeed.tech/tags/emea.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [sscop](<https://devfeed.tech/tags/sscop.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>), [testing](<https://devfeed.tech/tags/testing.md>), [uk](<https://devfeed.tech/tags/uk.md>), [united-kingdom](<https://devfeed.tech/tags/united-kingdom.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

The article explains the United Kingdom's Software Security Code of Practice and maps its 14 principles across secure development, build integrity, deployment, and customer communication. It presents Chainguard Containers, provenance attestations, and signed SBOMs as ways Chainguard supports secure-by-default software and compliance efforts.

### Source excerpt

Chainguard Containers support compliance with the United Kingdom's Software Security Code of Practice. Check out what the framework entails and how we help.

## How R1 Universities Can Simplify CMMC 2.0 Compliance with Chainguard Containers

DevFeed: [How R1 Universities Can Simplify CMMC 2.0 Compliance with Chainguard Containers](<https://devfeed.tech/articles/how-r1-universities-can-simplify-cmmc-2-0-compliance-with-chainguard-containers-13093.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-r1-universities-can-simplify-cmmc-2-0-compliance-with-chainguard-containers>)

Published: 2025-06-04T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [systems](<https://devfeed.tech/topics/systems.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-factory](<https://devfeed.tech/tags/chainguard-factory.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [cmmc](<https://devfeed.tech/tags/cmmc.md>), [cmmc-2-0](<https://devfeed.tech/tags/cmmc-2-0.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [cves](<https://devfeed.tech/tags/cves.md>), [funding](<https://devfeed.tech/tags/funding.md>), [linux](<https://devfeed.tech/tags/linux.md>), [malware](<https://devfeed.tech/tags/malware.md>), [management](<https://devfeed.tech/tags/management.md>), [security](<https://devfeed.tech/tags/security.md>), [software](<https://devfeed.tech/tags/software.md>), [systems](<https://devfeed.tech/tags/systems.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

This article explains how Chainguard Containers may help R1 universities prepare for CMMC 2.0 Level 2 requirements tied to Department of Defense research contracts. It focuses on vulnerability-management controls, including timely identification, reporting, remediation, malware protection, and risk assessment, and describes Chainguard's minimal container images, Chainguard OS, and Chainguard Factory.

### Source excerpt

With CMMC 2.0 compliance becoming an important prerequisite to research funding for R1 universities, Chainguard Containers are the perfect solution. See how.

## ATO in a Box: Simplifying Compliance for Software Vendors with Chainguard and Ask Sage

DevFeed: [ATO in a Box: Simplifying Compliance for Software Vendors with Chainguard and Ask Sage](<https://devfeed.tech/articles/ato-in-a-box-simplifying-compliance-for-software-vendors-with-chainguard-and-ask-sage-12891.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/ato-in-a-box-simplifying-compliance-for-software-vendors-with-chainguard-and-ask-sage>)

Published: 2025-06-02T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Containers](<https://devfeed.tech/topics/containers.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [Generative AI](<https://devfeed.tech/topics/generative-ai.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ask-sage](<https://devfeed.tech/tags/ask-sage.md>), [ato](<https://devfeed.tech/tags/ato.md>), [ato-in-a-box](<https://devfeed.tech/tags/ato-in-a-box.md>), [authority-to-operate](<https://devfeed.tech/tags/authority-to-operate.md>), [automation](<https://devfeed.tech/tags/automation.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-customer](<https://devfeed.tech/tags/chainguard-customer.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [generative](<https://devfeed.tech/tags/generative.md>), [secure-container-images](<https://devfeed.tech/tags/secure-container-images.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-cve-containers](<https://devfeed.tech/tags/zero-cve-containers.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

This article presents Ask Sage's ATO in a Box, built with Chainguard Containers, automation, and AI to simplify and accelerate the Authorization to Operate process for software vendors. It describes secure container images, automated documentation and evidence collection, risk assessments, and compliance-package generation for regulated government deployments.

### Source excerpt

Chainguard customer Ask Sage utilizes Chainguard Containers to build ATO in a Box, a solution utilizing automation to speed up the authority to operate process.

## Why Golden Images still matter and how to secure them with Chainguard

DevFeed: [Why Golden Images still matter and how to secure them with Chainguard](<https://devfeed.tech/articles/why-golden-images-still-matter-and-how-to-secure-them-with-chainguard-13330.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/why-golden-images-still-matter-and-how-to-secure-them-with-chainguard>)

Published: 2025-05-22T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [DevOps](<https://devfeed.tech/topics/devops.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [Software](<https://devfeed.tech/topics/software.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [aws](<https://devfeed.tech/tags/aws.md>), [azure](<https://devfeed.tech/tags/azure.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [devops](<https://devfeed.tech/tags/devops.md>), [golden-image](<https://devfeed.tech/tags/golden-image.md>), [golden-images](<https://devfeed.tech/tags/golden-images.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

This article explains why well-managed golden image programs remain important for modern software delivery. It describes how continuously rebuilt, patched, signed, scanned, and versioned images--with SBOMs, attestations, provenance, and policy compliance--can improve security and streamline development workflows, while presenting Chainguard as an alternative to homegrown programs.

### Source excerpt

Golden container image programs can be a great way to increase efficiency and security for your engineering team. Learn how to do it right with Chainguard.

## Chainguard Starter Images Now Available in Iron Bank: Minimal, Secure, and Reliable

DevFeed: [Chainguard Starter Images Now Available in Iron Bank: Minimal, Secure, and Reliable](<https://devfeed.tech/articles/chainguard-starter-images-now-available-in-iron-bank-minimal-secure-and-reliable-12983.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-starter-images-now-available-in-iron-bank-minimal-secure-and-reliable>)

Published: 2025-03-06T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-starter-images](<https://devfeed.tech/tags/chainguard-starter-images.md>), [container](<https://devfeed.tech/tags/container.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [iron-bank](<https://devfeed.tech/tags/iron-bank.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-cve-container-images](<https://devfeed.tech/tags/zero-cve-container-images.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

Chainguard Starter Images are now available in the Iron Bank image repository. The images are designed to reduce vulnerability findings, simplify VAT remediation, and streamline the path to Authorization to Operate. Chainguard describes them as secure-by-default images built from source with signed and attested artifacts, build-time SBOMs, hardened compiler settings, and reduced attack surfaces.

### Source excerpt

Chainguard Starter Images are zero CVE container images that are now available in the Iron Bank image repository.

## Guardcraft: A Minecraft Java Server with Zero CVEs

DevFeed: [Guardcraft: A Minecraft Java Server with Zero CVEs](<https://devfeed.tech/articles/guardcraft-a-minecraft-java-server-with-zero-cves-13073.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/guardcraft-a-minecraft-java-server-with-zero-cves>)

Published: 2025-02-28T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [grype](<https://devfeed.tech/topics/grype.md>), [Docker Hub](<https://devfeed.tech/topics/docker-hub.md>), [Security](<https://devfeed.tech/topics/security.md>), [Ubuntu](<https://devfeed.tech/topics/ubuntu.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Steam Deck](<https://devfeed.tech/topics/steam-deck.md>)

Tags: [bedrock](<https://devfeed.tech/tags/bedrock.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container](<https://devfeed.tech/tags/container.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [containers](<https://devfeed.tech/tags/containers.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-hub](<https://devfeed.tech/tags/docker-hub.md>), [grype](<https://devfeed.tech/tags/grype.md>), [guardcraft](<https://devfeed.tech/tags/guardcraft.md>), [linux](<https://devfeed.tech/tags/linux.md>), [security](<https://devfeed.tech/tags/security.md>), [steam-deck](<https://devfeed.tech/tags/steam-deck.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

The article describes building a Minecraft Java server with a Chainguard Image. It compares a popular Ubuntu-based Docker Hub image with the Chainguard approach, highlighting the former's 165 unresolved CVEs and the latter's stated result of zero CVEs.

### Source excerpt

We built a Minecraft Java server using a Chainguard Image, resulting in zero CVEs and a whole lot of fun!

## Announcing Chainguard Custom Assembly: Image Customization Without Complexity

DevFeed: [Announcing Chainguard Custom Assembly: Image Customization Without Complexity](<https://devfeed.tech/articles/announcing-chainguard-custom-assembly-image-customization-without-complexity-12877.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/announcing-chainguard-custom-assembly-image-customization-without-complexity>)

Published: 2025-02-20T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Security](<https://devfeed.tech/topics/security.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [bash](<https://devfeed.tech/tags/bash.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-custom-assembly](<https://devfeed.tech/tags/chainguard-custom-assembly.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [complexity](<https://devfeed.tech/tags/complexity.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [curl](<https://devfeed.tech/tags/curl.md>), [custom-assembly](<https://devfeed.tech/tags/custom-assembly.md>), [customization](<https://devfeed.tech/tags/customization.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [development](<https://devfeed.tech/tags/development.md>), [docker](<https://devfeed.tech/tags/docker.md>), [image](<https://devfeed.tech/tags/image.md>), [integrity](<https://devfeed.tech/tags/integrity.md>), [maintenance](<https://devfeed.tech/tags/maintenance.md>), [no-vulnerabilities](<https://devfeed.tech/tags/no-vulnerabilities.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

Chainguard announces the beta release of Custom Assembly, a product for tailoring Chainguard Images with required packages while preserving hardened builds, security practices, and CVE remediation coverage. The article explains that the product addresses complex, maintenance-heavy customization workflows involving manual image changes, Docker builds, and proprietary pipelines.

### Source excerpt

Custom Assembly is Chainguard's new image customization product that enables companies to consume zero-CVE open source software tailored to unique requirements.

## Guest Post: Securing the Foundation of Dynamic Data Governance at Velotix

DevFeed: [Guest Post: Securing the Foundation of Dynamic Data Governance at Velotix](<https://devfeed.tech/articles/guest-post-securing-the-foundation-of-dynamic-data-governance-at-velotix-13223.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/securing-the-foundation-of-dynamic-data-governance-at-velotix>)

Published: 2025-02-19T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [data-governance](<https://devfeed.tech/topics/data-governance.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Amazon OpenSearch Service](<https://devfeed.tech/topics/amazon-opensearch-service.md>), [Kafka](<https://devfeed.tech/topics/kafka.md>)

Tags: [case-study](<https://devfeed.tech/tags/case-study.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [guest-post](<https://devfeed.tech/tags/guest-post.md>), [performance](<https://devfeed.tech/tags/performance.md>), [productivity](<https://devfeed.tech/tags/productivity.md>), [security](<https://devfeed.tech/tags/security.md>), [time](<https://devfeed.tech/tags/time.md>), [velotix](<https://devfeed.tech/tags/velotix.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

A guest post explains how Velotix uses Chainguard Images to reduce CVEs across its data-governance platform. The article describes challenges with vendor-provided images and dependency upgrades, and highlights scheduled recompilation to keep infrastructure-level libraries current.

### Source excerpt

Velotix utilizes Chainguard Images to help reduce CVEs, improve performance, and save time. Learn how Chainguard helps them build a more secure infrastructure.

## Enabling Secure Software Development in 2025

DevFeed: [Enabling Secure Software Development in 2025](<https://devfeed.tech/articles/enabling-secure-software-development-in-2025-13027.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/enabling-secure-software-development-in-2025>)

Published: 2025-01-14T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [DevOps](<https://devfeed.tech/topics/devops.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-customers](<https://devfeed.tech/tags/chainguard-customers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [fips](<https://devfeed.tech/tags/fips.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-attack](<https://devfeed.tech/tags/software-supply-chain-attack.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

Chainguard describes its 2025 focus on scaling secure software development through a catalog of more than 1,000 container images, source-built components, daily rebuilding, automation, vulnerability remediation, and hardened images. The company reports patching more than 55,000 CVEs and saving customers over 200,000 engineering hours in 2024.

### Source excerpt

Chainguard is building on the success they generated for their customers in 2024. Take a look back at the numbers, and see what's next for us and our users!

## New Chainguard Images November 2024: Bun, CockroachDB, Open Liberty

DevFeed: [New Chainguard Images November 2024: Bun, CockroachDB, Open Liberty](<https://devfeed.tech/articles/new-chainguard-images-november-2024-bun-cockroachdb-open-liberty-13179.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/new-chainguard-images-november-2024-bun-cockroachdb-open-liberty>)

Published: 2024-12-18T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Bun](<https://devfeed.tech/topics/bun.md>), [CockroachDB](<https://devfeed.tech/topics/cockroachdb.md>), [open liberty](<https://devfeed.tech/topics/open-liberty.md>)

Tags: [bun](<https://devfeed.tech/tags/bun.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cockroachdb](<https://devfeed.tech/tags/cockroachdb.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [open-liberty](<https://devfeed.tech/tags/open-liberty.md>), [selenium](<https://devfeed.tech/tags/selenium.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

Chainguard announces 70 container images built in November 2024, including images for Open Liberty, CockroachDB, and Bun. The article describes the new images and their stated runtime, database, and JavaScript-tooling use cases.

### Source excerpt

Check out the new zero-CVE Chainguard Images built in November 2024, including offerings for Bun, CockroachDB, Open Liberty, Selenium, and more.

## New Chainguard Images October 2024: Swift, Dart, and more

DevFeed: [New Chainguard Images October 2024: Swift, Dart, and more](<https://devfeed.tech/articles/new-chainguard-images-october-2024-swift-dart-and-more-13180.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/new-chainguard-images-october-2024-swift-dart-and-more>)

Published: 2024-11-14T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Swift](<https://devfeed.tech/topics/swift.md>), [Dart](<https://devfeed.tech/topics/dart.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [dart](<https://devfeed.tech/tags/dart.md>), [fips](<https://devfeed.tech/tags/fips.md>), [jaeger](<https://devfeed.tech/tags/jaeger.md>), [linkerd](<https://devfeed.tech/tags/linkerd.md>), [swift](<https://devfeed.tech/tags/swift.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

Chainguard's October 2024 update announces 126 new CVE-free container images, including offerings for Swift, Dart, Linkerd, and Jaeger, along with new FIPS-enabled images and a notice about upcoming Developer tier changes.

### Source excerpt

Go over all the new Chainguard container images released in October, including new offerings for Swift, Dart, Linkerd, Jaeger, and more.

## Kernel-Independent FIPS Images

DevFeed: [Kernel-Independent FIPS Images](<https://devfeed.tech/articles/kernel-independent-fips-images-13136.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/kernel-independent-fips-images>)

Published: 2024-11-13T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Security](<https://devfeed.tech/topics/security.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>)

Tags: [chainguard-fips](<https://devfeed.tech/tags/chainguard-fips.md>), [chainguard-fips-images](<https://devfeed.tech/tags/chainguard-fips-images.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [federal-information-processing-standards](<https://devfeed.tech/tags/federal-information-processing-standards.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fips](<https://devfeed.tech/tags/fips.md>), [linux](<https://devfeed.tech/tags/linux.md>), [security](<https://devfeed.tech/tags/security.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

Chainguard FIPS Images can run on any Linux kernel by replacing the kernel entropy source with a userspace entropy source. This enables FIPS workloads on current kernels, hardware, instance types, developer machines, CI/CD deployments, and non-FIPS managed cloud offerings while supporting runtimes such as NodeJS, Python, Go, PHP, .NET, and C/C++.

### Source excerpt

Chainguard's FIPS Images are available for deployment on any Linux kernel, thanks to some new innovation by our engineering team. Learn what this means.

## Milestone: 1,000 Secure Container Images and Over 100 Work Years Saved

DevFeed: [Milestone: 1,000 Secure Container Images and Over 100 Work Years Saved](<https://devfeed.tech/articles/milestone-1-000-secure-container-images-and-over-100-work-years-saved-13159.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/milestone-1-000-secure-container-images-and-over-100-work-years-saved>)

Published: 2024-11-06T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [distroless](<https://devfeed.tech/topics/distroless.md>), [Compiler](<https://devfeed.tech/topics/compiler.md>), [Software](<https://devfeed.tech/topics/software.md>), [Debian](<https://devfeed.tech/topics/debian.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [compiler](<https://devfeed.tech/tags/compiler.md>), [container](<https://devfeed.tech/tags/container.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [debian](<https://devfeed.tech/tags/debian.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [no-vulnerabilities](<https://devfeed.tech/tags/no-vulnerabilities.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-container-images](<https://devfeed.tech/tags/secure-container-images.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

Chainguard announces that its catalog has reached 1,000 secure container images and has helped more than 100 enterprise customers remediate over 54,000 CVEs, saving 216,000 engineering hours. The article reflects on the company's three-year journey and its decision to build Chainguard Images from source to provide faster vulnerability patching, comprehensive SBOMs and provenance attestations, broad version support, and compiler hardening.

### Source excerpt

Chainguard now offers over 1,000 container images with zero CVEs in our Chainguard Images Directory. Discover how we got here, and how our images can help you.

## How much time is wasted triaging known exploits?

DevFeed: [How much time is wasted triaging known exploits?](<https://devfeed.tech/articles/how-much-time-is-wasted-triaging-known-exploits-13091.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-much-time-is-wasted-triaging-known-exploits>)

Published: 2024-06-21T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [grype](<https://devfeed.tech/topics/grype.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [base-container-images](<https://devfeed.tech/tags/base-container-images.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-management](<https://devfeed.tech/tags/cve-management.md>), [cves](<https://devfeed.tech/tags/cves.md>), [efficiency](<https://devfeed.tech/tags/efficiency.md>), [exploited-vulnerabilities](<https://devfeed.tech/tags/exploited-vulnerabilities.md>), [exploits](<https://devfeed.tech/tags/exploits.md>), [grype](<https://devfeed.tech/tags/grype.md>), [kev-catalog](<https://devfeed.tech/tags/kev-catalog.md>), [known-exploited-vulnerability](<https://devfeed.tech/tags/known-exploited-vulnerability.md>), [nvd-cve](<https://devfeed.tech/tags/nvd-cve.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-detection](<https://devfeed.tech/tags/vulnerability-detection.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

The article reports that seven percent of 230 popular Bitnami container images contained CVEs listed in the Known Exploited Vulnerability catalog, but detailed triage found that none were exploitable in those container contexts. It argues that CVE triage consumes substantial staff time, while Chainguard Images historically remediated affected CVEs in an average of 2.5 days.

### Source excerpt

Stop wasting time on known exploits. Read our latest research and discover strategies to streamline your vulnerability management for maximum efficiency.

## Zero CVEs and just as fast: Chainguard's Python & Go Images

DevFeed: [Zero CVEs and just as fast: Chainguard's Python & Go Images](<https://devfeed.tech/articles/zero-cves-and-just-as-fast-chainguard-s-python-go-images-13347.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/zero-cves-and-just-as-fast-chainguards-python-go-images>)

Published: 2024-04-24T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>), [Python](<https://devfeed.tech/topics/python.md>), [benchmarking](<https://devfeed.tech/topics/benchmarking.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [benchmark](<https://devfeed.tech/tags/benchmark.md>), [benchmarking](<https://devfeed.tech/tags/benchmarking.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container](<https://devfeed.tech/tags/container.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cves](<https://devfeed.tech/tags/cves.md>), [go](<https://devfeed.tech/tags/go.md>), [performance](<https://devfeed.tech/tags/performance.md>), [python](<https://devfeed.tech/tags/python.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

Chainguard benchmarks its Python and Go container images against upstream open-source equivalents using standard test suites. The Python image averages 1.5 percent faster across 104 tests, while the Go image averages less than one percent slower across 24 tests, indicating essentially tied performance alongside low-to-no CVEs and supply-chain security features.

### Source excerpt

Upgrade your Python and Go security without sacrificing speed. Chainguard Images offer zero CVEs and blazing performance.

## Can debloated containers pass the zero CVE test?

DevFeed: [Can debloated containers pass the zero CVE test?](<https://devfeed.tech/articles/can-debloated-containers-pass-the-zero-cve-test-12915.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/can-debloated-containers-pass-the-zero-cve-test>)

Published: 2023-11-20T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Containers](<https://devfeed.tech/topics/containers.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [grype](<https://devfeed.tech/topics/grype.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cves](<https://devfeed.tech/tags/cves.md>), [grype](<https://devfeed.tech/tags/grype.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security-research](<https://devfeed.tech/tags/software-supply-chain-security-research.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

The article analyzes 28 debloated container images and finds that they reduce CVEs by an average of 64% compared with baseline images, but still contain an average of 33 CVEs. It also reports an average of five high or critical vulnerabilities, concluding that debloated containers do not pass the zero-CVE test. The comparison uses Grype and includes Chainguard Images versions.

### Source excerpt

Exploring the efficiency of debloated containers in the Zero CVE test: Chaingaurd's analysis of security and efficiency.