# chainguard labs

Chainguard Labs is a research organization that interviewed software professionals about vulnerability management in container-based software.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Project Safe Source: Identifying potential vulnerabilities in Wolfi upstream

DevFeed: [Project Safe Source: Identifying potential vulnerabilities in Wolfi upstream](<https://devfeed.tech/articles/project-safe-source-identifying-potential-vulnerabilities-in-wolfi-upstream-13204.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/project-safe-source-identifying-potential-vulnerabilities-in-wolfi-upstream>)

Author: About the Author

Published: 2024-08-23T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard labs](<https://devfeed.tech/topics/chainguard-labs.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>), [Code](<https://devfeed.tech/topics/code.md>), [Bot](<https://devfeed.tech/topics/bot.md>)

Tags: [automated](<https://devfeed.tech/tags/automated.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-labs](<https://devfeed.tech/tags/chainguard-labs.md>), [code](<https://devfeed.tech/tags/code.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [project](<https://devfeed.tech/tags/project.md>), [pull-requests](<https://devfeed.tech/tags/pull-requests.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard's Project Safe Source used CodeQL to scan more than 1,000 open source projects packaged in Wolfi. The scan identified seven classes of potential vulnerabilities across 226 projects, totaling 1,878 alerts, and highlighted candidates for automated pull requests.

### Source excerpt

Chainguard's Project Safe Source uses CodeQL to identify & fix vulnerabilities in open source projects packaged in Wolfi with automated pull requests.

## Why your company is wasting thousands of hours on software vulnerabilities

DevFeed: [Why your company is wasting thousands of hours on software vulnerabilities](<https://devfeed.tech/articles/why-your-company-is-wasting-thousands-of-hours-on-software-vulnerabilities-13333.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/why-your-company-is-wasting-thousands-of-hours-on-software-vulnerabilities>)

Published: 2024-02-06T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [chainguard labs](<https://devfeed.tech/topics/chainguard-labs.md>)

Tags: [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-labs](<https://devfeed.tech/tags/chainguard-labs.md>), [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cve-management](<https://devfeed.tech/tags/cve-management.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

Chainguard Labs interviewed approximately ten software professionals and found that companies building or deploying containers may spend thousands of hours each year on vulnerability management. The article attributes much of this burden to large numbers of known vulnerabilities and image-selection practices that disregard vulnerability counts.

### Source excerpt

Chainguard Labs surveyed nine companies to see how many hours they spent on vulnerability management each year. Check out this blog to see the results.

## A thought experiment on using low-vulnerability Chainguard Images to speed government software delivery

DevFeed: [A thought experiment on using low-vulnerability Chainguard Images to speed government software delivery](<https://devfeed.tech/articles/ship-software-to-uncle-sam-faster-with-zero-known-vulnerability-containers-13230.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/ship-software-to-uncle-sam-faster-with-zero-known-vulnerability-containers>)

Published: 2023-06-20T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Containers](<https://devfeed.tech/topics/containers.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [authority to operate](<https://devfeed.tech/topics/authority-to-operate.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard labs](<https://devfeed.tech/topics/chainguard-labs.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [ato](<https://devfeed.tech/tags/ato.md>), [authority-to-operate](<https://devfeed.tech/tags/authority-to-operate.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-labs](<https://devfeed.tech/tags/chainguard-labs.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [containers](<https://devfeed.tech/tags/containers.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [government](<https://devfeed.tech/tags/government.md>), [image-cves](<https://devfeed.tech/tags/image-cves.md>), [secure-container-image](<https://devfeed.tech/tags/secure-container-image.md>), [secure-minimal-image](<https://devfeed.tech/tags/secure-minimal-image.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [vulnerability-scanner](<https://devfeed.tech/tags/vulnerability-scanner.md>)

### AI overview

This opinion article proposes studying whether Chainguard Images with zero-known or low vulnerability counts could reduce timelines and staff costs in government Authority to Operate processes. It presents this as a hypothesis requiring comparison with other ATO processes, not as a demonstrated result.

### Source excerpt

Discover how 0-known vulnerability containers from Chainguard Labs could accelerate software delivery to the government.