# container-security

The cybersecurity discipline of securing application containers and their lifecycle, including images, runtimes, registries, and orchestration.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## A Bootiful Podcast: BellSoft's Catherine Edelveis on hardened runtime images, container security, and more

DevFeed: [A Bootiful Podcast: BellSoft's Catherine Edelveis on hardened runtime images, container security, and more](<https://devfeed.tech/articles/a-bootiful-podcast-bellsoft-s-catherine-edelveis-on-hardened-runtime-images-container-security-and-more-3534.md>)

Original publisher: [Read original article](<https://spring.io/blog/2026/09/03/a-bootiful-podcast-catherine-edelvais>)

Author: joshlong

Published: 2026-09-03T00:00:00Z

Content type: article

Language: en

Sources: [Spring](<https://devfeed.tech/sources/spring.md>)

Topics: [container-security](<https://devfeed.tech/topics/container-security.md>)

Tags: [batch](<https://devfeed.tech/tags/batch.md>), [boot](<https://devfeed.tech/tags/boot.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [event-driven](<https://devfeed.tech/tags/event-driven.md>), [java](<https://devfeed.tech/tags/java.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [podcast](<https://devfeed.tech/tags/podcast.md>), [reactive](<https://devfeed.tech/tags/reactive.md>), [security](<https://devfeed.tech/tags/security.md>), [serverless](<https://devfeed.tech/tags/serverless.md>), [spring](<https://devfeed.tech/tags/spring.md>), [spring-boot](<https://devfeed.tech/tags/spring-boot.md>), [web-applications](<https://devfeed.tech/tags/web-applications.md>)

### AI overview

A podcast conversation about using buildpacks and hardened images to ship Spring Boot applications with stronger security, cleaner defaults, and less Dockerfile work.

### Source excerpt

Hi, Spring fans! I chat with BellSoft's Catherine Edelweiss about using buildpacks and hardened images to ship Spring Boot apps with stronger security, cleaner defaults, and far less Dockerfile pain. #BellSoft #Docker #Java #JRE #SpringBoot

## Why the CVE doom cycle cannot be solved by working harder

DevFeed: [Why the CVE doom cycle cannot be solved by working harder](<https://devfeed.tech/articles/why-the-cve-doom-cycle-cannot-be-solved-by-working-harder-12284.md>)

Original publisher: [Read original article](<https://platformengineering.org/blog/why-the-cve-doom-cycle-can-not-be-solved-by-working-harder>)

Author: Sam Barlien

Published: 2026-07-23T05:40:01Z

Content type: article

Language: en

Sources: [Platform Engineering Blog](<https://devfeed.tech/sources/platform-engineering-blog.md>)

Topics: [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [configuration](<https://devfeed.tech/topics/configuration.md>)

Tags: [automation](<https://devfeed.tech/tags/automation.md>), [container-image-security](<https://devfeed.tech/tags/container-image-security.md>), [cve](<https://devfeed.tech/tags/cve.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

The article argues that the recurring cycle of scanning, triaging, patching, and redeploying container images cannot be solved by working harder or using faster scanners. Because vulnerability findings and CVEs accumulate faster than manual remediation can handle, it recommends embedding vulnerability management into the platform through secure-by-design practices, golden paths, and automation.

### Source excerpt

Manual CVE triage doesn't scale. Break the CVE doom cycle by shifting vulnerability management into the platform with golden paths and automation

## Secure What Matters: Scaling Effortless Container Security for the AI Era

DevFeed: [Secure What Matters: Scaling Effortless Container Security for the AI Era](<https://devfeed.tech/articles/secure-what-matters-scaling-effortless-container-security-for-the-ai-era-8072.md>)

Original publisher: [Read original article](<https://snyk.io/blog/scale-container-security-effortlessly/>)

Author: Pratip Banerji; Brendan Hann

Published: 2026-04-07T04:00:00Z

Content type: release

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [container-security](<https://devfeed.tech/topics/container-security.md>), [snyk-container](<https://devfeed.tech/topics/snyk-container.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [americas](<https://devfeed.tech/tags/americas.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cli](<https://devfeed.tech/tags/cli.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [containers](<https://devfeed.tech/tags/containers.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [docker](<https://devfeed.tech/tags/docker.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [go](<https://devfeed.tech/tags/go.md>), [interest](<https://devfeed.tech/tags/interest.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-container](<https://devfeed.tech/tags/snyk-container.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [tech](<https://devfeed.tech/tags/tech.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

### AI overview

Snyk announces the general availability of Container Registry Sync, which automates the discovery, scanning, and pruning of container images. The article also previews a unified product experience for managing container-image risk across CLI, CI/CD, and registries.

### Source excerpt

Announcing Snyk Container Registry Sync GA for automated image management and runtime intelligence. Scale container security effortlessly for the fast-paced AI era.

## Forrester TEI study: Chainguard Containers delivered 233% return on investment

DevFeed: [Forrester TEI study: Chainguard Containers delivered 233% return on investment](<https://devfeed.tech/articles/forrester-tei-study-chainguard-containers-delivered-233-return-on-investment-13051.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/forrester-tei-study-chainguard-containers-delivered-233-return-on-investment>)

Published: 2026-02-18T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-forrester](<https://devfeed.tech/tags/chainguard-forrester.md>), [chainguard-roi](<https://devfeed.tech/tags/chainguard-roi.md>), [chainguard-value](<https://devfeed.tech/tags/chainguard-value.md>), [cmmc](<https://devfeed.tech/tags/cmmc.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [containers](<https://devfeed.tech/tags/containers.md>), [forrester-tei](<https://devfeed.tech/tags/forrester-tei.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

A Forrester Consulting Total Economic Impact study commissioned by Chainguard reports that customers using Chainguard Containers achieved a 233% return on investment over three years, with $2.5 million in benefits and payback in less than six months. The article attributes these results to reduced vulnerabilities, simpler maintenance, and lower compliance overhead, supported by minimal zero-CVE container images and automated remediation.

### Source excerpt

Explore the latest Forrester Consulting Total Economic Impact™ (TEI) study, commissioned by Chainguard.

## Why Trusted Software Supply Chains Matter More Than Zero-CVE Container Claims

DevFeed: [Why Trusted Software Supply Chains Matter More Than Zero-CVE Container Claims](<https://devfeed.tech/articles/well-that-escalated-quickly-zero-cves-lots-of-vendors-13314.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/well-that-escalated-quickly-zero-cves-lots-of-vendors>)

Published: 2026-01-15T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Docker Hub](<https://devfeed.tech/topics/docker-hub.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [ceo](<https://devfeed.tech/tags/ceo.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-hub](<https://devfeed.tech/tags/docker-hub.md>), [docker-images](<https://devfeed.tech/tags/docker-images.md>), [echo-security](<https://devfeed.tech/tags/echo-security.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [minimus](<https://devfeed.tech/tags/minimus.md>), [rapidfort](<https://devfeed.tech/tags/rapidfort.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [wiz-images](<https://devfeed.tech/tags/wiz-images.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

Chainguard CEO Dan Lorenc argues that container security depends on trusting the origins and build processes of software, rather than relying primarily on post-hoc image hardening or zero-CVE claims.

### Source excerpt

Chainguard CEO Dan Lorenc explains why real security comes from trusted, from-source software supply chains, not post-hoc hardening or zero-CVE promises.

## The only rule: Don't look at the code

DevFeed: [The only rule: Don't look at the code](<https://devfeed.tech/articles/the-only-rule-don-t-look-at-the-code-13264.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-only-rule-dont-look-at-the-code>)

Published: 2025-12-29T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Vibe coding](<https://devfeed.tech/topics/vibe-coding.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-assisted-coding](<https://devfeed.tech/tags/ai-assisted-coding.md>), [ai-engineering](<https://devfeed.tech/tags/ai-engineering.md>), [chainguard-ai](<https://devfeed.tech/tags/chainguard-ai.md>), [chainguard-vibelympics](<https://devfeed.tech/tags/chainguard-vibelympics.md>), [code-quality](<https://devfeed.tech/tags/code-quality.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [vibe-coding](<https://devfeed.tech/tags/vibe-coding.md>)

### AI overview

Chainguard's Vibelympics was a vibe-coding tournament in which 59 individuals and teams built software without looking at the generated code. The article describes the competition's challenges, including an emoji-only interface and a package ecosystem security auditor, and highlights selected submissions and results.

### Source excerpt

Chainguard's Vibelympics competition brought out the best and most creative ideas in vibe coding and AI-assisted software development.

## Beyond the Scan: The Future of Snyk Container

DevFeed: [Beyond the Scan: The Future of Snyk Container](<https://devfeed.tech/articles/beyond-the-scan-the-future-of-snyk-container-7934.md>)

Original publisher: [Read original article](<https://snyk.io/blog/future-snyk-container/>)

Author: Brendan Hann; Pratip Banerji

Published: 2025-11-04T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [container-security](<https://devfeed.tech/topics/container-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [developer](<https://devfeed.tech/tags/developer.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-hub](<https://devfeed.tech/tags/docker-hub.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-container](<https://devfeed.tech/tags/snyk-container.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Snyk outlines a developer-first vision for container security that connects the IDE, CI/CD pipeline, container registry, and production. It highlights continuous registry monitoring to identify newly disclosed vulnerabilities in previously built images.

### Source excerpt

Snyk Container rethinks security, moving beyond scans to deliver a comprehensive, end-to-end solution. It connects the entire lifecycle, from IDE to production, with continuous monitoring and AI-powered remediation.

## Agentic Container Security with Snyk MCP Server

DevFeed: [Agentic Container Security with Snyk MCP Server](<https://devfeed.tech/articles/agentic-container-security-with-snyk-mcp-server-7795.md>)

Original publisher: [Read original article](<https://snyk.io/blog/agentic-container-security-with-snyk-mcp-server/>)

Author: Liran Tal

Published: 2025-08-13T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [container-security](<https://devfeed.tech/topics/container-security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [ci](<https://devfeed.tech/topics/ci.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [blog](<https://devfeed.tech/tags/blog.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [containers](<https://devfeed.tech/tags/containers.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [ide](<https://devfeed.tech/tags/ide.md>), [interest](<https://devfeed.tech/tags/interest.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [mcp-server](<https://devfeed.tech/tags/mcp-server.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The article discusses using Snyk's MCP server in AI-powered IDE workflows to scan container vulnerabilities and recommend base-image changes earlier in development.

### Source excerpt

Learn how Snyk's MCP server brings agentic security to container workflows. Automate vulnerability scanning and base image recommendations directly within your AI-powered IDE.

## Chainguard Now Available on Microsoft Azure Marketplace; Scan Chainguard Container Images with Microsoft Defender for Cloud

DevFeed: [Chainguard Now Available on Microsoft Azure Marketplace; Scan Chainguard Container Images with Microsoft Defender for Cloud](<https://devfeed.tech/articles/chainguard-now-available-on-microsoft-azure-marketplace-scan-chainguard-container-images-with-microsoft-defender-for-cloud-12973.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-now-available-on-microsoft-azure-marketplace>)

Published: 2025-07-16T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Azure](<https://devfeed.tech/topics/azure.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [azure](<https://devfeed.tech/tags/azure.md>), [azure-marketplace](<https://devfeed.tech/tags/azure-marketplace.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [defender](<https://devfeed.tech/tags/defender.md>), [microsoft-defender](<https://devfeed.tech/tags/microsoft-defender.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

Chainguard Containers is now available through the Microsoft Azure Marketplace, enabling Azure customers to adopt it within existing procurement, billing, deployment, and CI/CD workflows. Microsoft Defender for Cloud can also scan Chainguard container images for vulnerabilities, improving visibility and security across container environments.

### Source excerpt

Chainguard is now listed on the Microsoft Azure Marketplace. In addition, Microsoft Defender for Cloud can now scan Chainguard container images.

## Fork yeah: We're bringing kaniko back

DevFeed: [Fork yeah: We're bringing kaniko back](<https://devfeed.tech/articles/fork-yeah-we-re-bringing-kaniko-back-13050.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/fork-yeah-were-bringing-kaniko-back>)

Published: 2025-06-05T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [container](<https://devfeed.tech/tags/container.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [deprecated](<https://devfeed.tech/tags/deprecated.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-images](<https://devfeed.tech/tags/docker-images.md>), [fork](<https://devfeed.tech/tags/fork.md>), [google](<https://devfeed.tech/tags/google.md>), [kaniko](<https://devfeed.tech/tags/kaniko.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [maintenance](<https://devfeed.tech/tags/maintenance.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [safe-source-for-open-source](<https://devfeed.tech/tags/safe-source-for-open-source.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>)

### AI overview

Chainguard is forking and taking over maintenance of Kaniko after Google announced plans to archive it. The project will remain open and upstream, with a focus on maintenance and minor bug fixes rather than new features, while Chainguard also offers commercial Kaniko images for organizations needing zero-CVE or FIPS versions.

### Source excerpt

Chainguard is taking over the maintenance of the Kaniko project, recently deprecated by Google. Learn more about why we're doing it and what is next.

## Chainguard's Catalog of 1,300+ Container Images: Secure Foundation for Every Engineering Team

DevFeed: [Chainguard's Catalog of 1,300+ Container Images: Secure Foundation for Every Engineering Team](<https://devfeed.tech/articles/chainguard-s-catalog-of-1-300-container-images-secure-foundation-for-every-engineering-team-12986.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguards-catalog-of-1-300-container-images-secure-foundation-for-every-engineering-team>)

Published: 2025-05-12T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-catalog](<https://devfeed.tech/tags/chainguard-catalog.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-factory](<https://devfeed.tech/tags/chainguard-factory.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [container](<https://devfeed.tech/tags/container.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [safe-source-for-open-source](<https://devfeed.tech/tags/safe-source-for-open-source.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [slsa](<https://devfeed.tech/tags/slsa.md>)

### AI overview

Chainguard describes its catalog of more than 1,300 minimal, zero-CVE container images, built from source on Chainguard OS and maintained through the Chainguard Factory. The article highlights daily rebuilds, automated dependency and CVE handling, and default SBOMs, SLSA provenance, and Sigstore signatures.

### Source excerpt

Chainguard Containers is a catalog of over 1,300 container images powered by Chainguard OS and the Chainguard Factory. Discover the safe source for open source.

## Evaluating Container Security with Container Hardening Priorities: Some CHPs for Your SLSA

DevFeed: [Evaluating Container Security with Container Hardening Priorities: Some CHPs for Your SLSA](<https://devfeed.tech/articles/evaluating-container-security-with-container-hardening-priorities-some-chps-for-your-slsa-13031.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/evaluating-container-security-with-container-hardening-priorities-some-chps-for-your-slsa>)

Published: 2025-04-03T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [container-security](<https://devfeed.tech/topics/container-security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [best-practices](<https://devfeed.tech/tags/best-practices.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chps](<https://devfeed.tech/tags/chps.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [container-hardening-priorities](<https://devfeed.tech/tags/container-hardening-priorities.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [minimalism](<https://devfeed.tech/tags/minimalism.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [standard](<https://devfeed.tech/tags/standard.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard introduces Container Hardening Priorities (CHPs), a framework for assessing container image security. CHPs complements SLSA and focuses initially on build-time characteristics including minimalism, provenance, configuration and metadata, and vulnerabilities.

### Source excerpt

Chainguard has announced Container Hardening Priorities (CHPs), a new framework to assess the security of container images. Learn how it works.

## What FedRAMP 20x Means for You

DevFeed: [What FedRAMP 20x Means for You](<https://devfeed.tech/articles/what-fedramp-20x-means-for-you-13317.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/what-fedramp-20x-means-for-you>)

Published: 2025-04-02T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Automation](<https://devfeed.tech/topics/automation.md>), [authority to operate](<https://devfeed.tech/topics/authority-to-operate.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [cve remediation](<https://devfeed.tech/topics/cve-remediation.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [authority-to-operate](<https://devfeed.tech/tags/authority-to-operate.md>), [automation](<https://devfeed.tech/tags/automation.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [complexity](<https://devfeed.tech/tags/complexity.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cost](<https://devfeed.tech/tags/cost.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [cves](<https://devfeed.tech/tags/cves.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fedramp-20x](<https://devfeed.tech/tags/fedramp-20x.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article explains that FedRAMP 20x is intended to streamline the authority-to-operate process through automation and continuous validation. It says the core security and compliance controls are not changing and that the existing agency-based FedRAMP Rev. 5 authorization path remains active.

### Source excerpt

FedRAMP 20x is a new initiative designed to automate and simplify the FedRAMP process. Get the rundown on what is changing, and how Chainguard can help.

## Chainguard Images are the Gold Standard for PCI DSS v4.0

DevFeed: [Chainguard Images are the Gold Standard for PCI DSS v4.0](<https://devfeed.tech/articles/chainguard-images-are-the-gold-standard-for-pci-dss-v4-0-12954.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-images-are-the-gold-standard-for-pci-dss-v4-0>)

Published: 2025-02-03T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-sboms](<https://devfeed.tech/tags/chainguard-sboms.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container](<https://devfeed.tech/tags/container.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [container-image-compliance](<https://devfeed.tech/tags/container-image-compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [financial](<https://devfeed.tech/tags/financial.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [pci-dss-v4-0](<https://devfeed.tech/tags/pci-dss-v4-0.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-composition-analysis](<https://devfeed.tech/tags/software-composition-analysis.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [stig](<https://devfeed.tech/tags/stig.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

The article explains how Chainguard Images can support selected PCI DSS v4.0 container-security controls. It focuses on asset and vulnerability management, hardened images, FIPS cryptography, build-time SBOMs, software supply chain inventory, and continuously updated containers.

### Source excerpt

Chainguard Images are designed to make container image compliance for PCI DSS v4.0 easy for any company involved in card transactions.

## Chainguard Images: The Easy Button for FedRAMP

DevFeed: [Chainguard Images: The Easy Button for FedRAMP](<https://devfeed.tech/articles/chainguard-images-the-easy-button-for-fedramp-12960.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-images-the-easy-button-for-fedramp>)

Published: 2025-01-28T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Docker Hardened Images](<https://devfeed.tech/topics/docker-hardened-images.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [chainguard sboms](<https://devfeed.tech/topics/chainguard-sboms.md>), [Security](<https://devfeed.tech/topics/security.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [asset-management](<https://devfeed.tech/tags/asset-management.md>), [ato](<https://devfeed.tech/tags/ato.md>), [authority-to-operate](<https://devfeed.tech/tags/authority-to-operate.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container](<https://devfeed.tech/tags/container.md>), [container-image-security](<https://devfeed.tech/tags/container-image-security.md>), [cve](<https://devfeed.tech/tags/cve.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [sca](<https://devfeed.tech/tags/sca.md>), [sdlc](<https://devfeed.tech/tags/sdlc.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

This article explains how Chainguard Images can simplify and accelerate FedRAMP Authority to Operate compliance for organizations deploying containerized cloud products to federal government customers. It describes secure-by-design containers as helping address asset management, hardening, cryptography, and vulnerability management requirements, and notes Snowflake's achievement of FedRAMP High with Chainguard Images.

### Source excerpt

Chainguard Images are designed to make achieving FedRAMP compliance for container images easier. Learn more about how we make vulnerability management simple.

## 10 Docker Security Best Practices

DevFeed: [10 Docker Security Best Practices](<https://devfeed.tech/articles/10-docker-security-best-practices-7763.md>)

Original publisher: [Read original article](<https://snyk.io/blog/10-docker-image-security-best-practices/>)

Author: Liran Tal; Omer Levi Hevroni

Published: 2025-01-08T18:58:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Docker](<https://devfeed.tech/topics/docker.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [alpine](<https://devfeed.tech/tags/alpine.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [base-images](<https://devfeed.tech/tags/base-images.md>), [c](<https://devfeed.tech/tags/c.md>), [cheat-sheet](<https://devfeed.tech/tags/cheat-sheet.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [debian](<https://devfeed.tech/tags/debian.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [docker](<https://devfeed.tech/tags/docker.md>), [go](<https://devfeed.tech/tags/go.md>), [google](<https://devfeed.tech/tags/google.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [snyk-container](<https://devfeed.tech/tags/snyk-container.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article explains Docker security across image builds, container runtime, supply-chain risks, and orchestration. It presents best practices including using minimal or distroless base images, multi-stage builds, reducing attack surface, and running containers with the least privilege. It also references Docker Hub, Kubernetes, Helm, Alpine Linux, Go, C, Debian, Node, and Google distroless images.

### Source excerpt

Understand the basics of Docker security best practices with our Docker Cheat Sheet to improve container security.

## Blog: How to Deploy Falco with k8s-metacollector + k8smeta Plugin

DevFeed: [Blog: How to Deploy Falco with k8s-metacollector + k8smeta Plugin](<https://devfeed.tech/articles/blog-how-to-deploy-falco-with-k8s-metacollector-k8smeta-plugin-32498.md>)

Original publisher: [Read original article](<https://falco.org/blog/falco-k8smeta-plugin/>)

Published: 2024-10-14T00:00:00Z

Content type: tutorial

Language: en

Sources: [Falco - Falco](<https://devfeed.tech/sources/falco-falco.md>), [Falco - The Falco blog](<https://devfeed.tech/sources/falco-the-falco-blog.md>)

Topics: [Falco](<https://devfeed.tech/topics/falco.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [Kubernetes clusters](<https://devfeed.tech/topics/kubernetes-clusters.md>), [monitor](<https://devfeed.tech/topics/monitor.md>)

Tags: [clusters](<https://devfeed.tech/tags/clusters.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [enrichment](<https://devfeed.tech/tags/enrichment.md>), [falco](<https://devfeed.tech/tags/falco.md>), [helm](<https://devfeed.tech/tags/helm.md>), [k8s-metacollector](<https://devfeed.tech/tags/k8s-metacollector.md>), [k8smeta](<https://devfeed.tech/tags/k8smeta.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [monitor](<https://devfeed.tech/tags/monitor.md>), [plugin](<https://devfeed.tech/tags/plugin.md>), [security](<https://devfeed.tech/tags/security.md>), [tutorial](<https://devfeed.tech/tags/tutorial.md>)

### AI overview

This tutorial explains how to deploy Falco with the k8s-metacollector and k8smeta plugin on Kubernetes. It shows how these components add Kubernetes metadata such as pod names, namespaces, and deployment details to Falco security alerts, and how Falco's append_output feature can add extra metadata fields without modifying rules.

### Source excerpt

In today's cloud-native world, securing Kubernetes environments has become increasingly critical as containerized workloads gain complexity. Falco is designed to monitor and detect anomalous activities in Kubernetes clusters and container environments. By continuously observing system calls and enriching event data with metadata, Falco ensures that any suspicious behavior is detected in real-time, protecting against threats like privilege escalations, file tampering, and network anomalies. In this tutorial, we will guide you through deploying Falco with two powerful components: k8s-metacollector and the k8smeta plugin. These tools significantly enhance Falco's security event detection by adding important Kubernetes context, such as pod names, namespaces, deployment details, to the alerts. Additionally, we will explore how to leverage the new append_output feature introduced in Falco version 0.39.0. This feature allows you to append extra metadata fields to Falco's output, without the need to modify your rules. By the end of this guide, you will have a Falco setup capable of detecting security issues in Kubernetes with enriched metadata output, ensuring you get a complete picture of your cluster's security posture. Whether you're an experienced Kubernetes administrator or just starting to explore container security, this guide will help you make the most of Falco's capabilities in a Kubernetes environment. What You'll Learn: The purpose and benefits of using the k8s-metacollector and k8smeta plugin to enrich Falco alerts with Kubernetes-specific data. How to deploy Falco with the k8smeta plugin on a Kubernetes cluster. How to configure and use the append_output feature to enhance Falco alerts with additional metadata fields. Prerequisites: A working Kubernetes cluster and some familiarity with Kubernetes concepts. Basic knowledge of Falco and how it works. Helm installed on your system (for easy deployment of Falco). Let's dive in and set up a Falco deployment that w

## Proactive AppSec continuous vulnerability management for developers and security teams

DevFeed: [Proactive AppSec continuous vulnerability management for developers and security teams](<https://devfeed.tech/articles/proactive-appsec-continuous-vulnerability-management-for-developers-and-security-teams-8055.md>)

Original publisher: [Read original article](<https://snyk.io/blog/proactive-appsec-continuous-vulnerability-management/>)

Author: Liran Tal

Published: 2024-10-02T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [GitHub Copilot](<https://devfeed.tech/topics/github-copilot.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [npm](<https://devfeed.tech/topics/npm.md>), [React](<https://devfeed.tech/topics/react.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [c-cpp](<https://devfeed.tech/tags/c-cpp.md>), [code](<https://devfeed.tech/tags/code.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [container](<https://devfeed.tech/tags/container.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [developer](<https://devfeed.tech/tags/developer.md>), [developers](<https://devfeed.tech/tags/developers.md>), [development](<https://devfeed.tech/tags/development.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [docker](<https://devfeed.tech/tags/docker.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [open](<https://devfeed.tech/tags/open.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [ruby](<https://devfeed.tech/tags/ruby.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-container](<https://devfeed.tech/tags/snyk-container.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [software](<https://devfeed.tech/tags/software.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [source](<https://devfeed.tech/tags/source.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>), [vs-code](<https://devfeed.tech/tags/vs-code.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

The article explains why developers and security teams need continuous vulnerability management across the software development lifecycle. It covers risks from open-source dependencies, vendor-controlled supply chains, AI-generated code, prompt injection, GitHub Copilot, and containerized applications, and emphasizes automating vulnerability identification, remediation, dependency scanning, and container security.

### Source excerpt

Protect against modern threats like open-source supply chain attacks and AI-generated code vulnerabilities. Automate dependency scanning, remediation, and container security to ensure your applications are safe and compliant. Secure your software development with Snyk's comprehensive vulnerability management solution.

## Meet Chainguard at Black Hat USA 2024 in Vegas!

DevFeed: [Meet Chainguard at Black Hat USA 2024 in Vegas!](<https://devfeed.tech/articles/meet-chainguard-at-black-hat-usa-2024-in-vegas-13150.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/meet-chainguard-at-black-hat-usa-2024-in-vegas>)

Published: 2024-07-19T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [black-hat](<https://devfeed.tech/tags/black-hat.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [charity](<https://devfeed.tech/tags/charity.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cves](<https://devfeed.tech/tags/cves.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [developers](<https://devfeed.tech/tags/developers.md>), [events](<https://devfeed.tech/tags/events.md>), [insights](<https://devfeed.tech/tags/insights.md>), [music](<https://devfeed.tech/tags/music.md>), [networking](<https://devfeed.tech/tags/networking.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [organization](<https://devfeed.tech/tags/organization.md>), [protection](<https://devfeed.tech/tags/protection.md>), [security](<https://devfeed.tech/tags/security.md>), [sponsor](<https://devfeed.tech/tags/sponsor.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [us](<https://devfeed.tech/tags/us.md>)

### AI overview

Chainguard announces its participation in Black Hat USA 2024 in Las Vegas, including a booth, a cybersecurity breakfast co-hosted with GitGuardian, social events, and a container security capture-the-flag challenge at DEF CON 32.

### Source excerpt

Join Chainguard at Black Hat USA 2024 for cybersecurity insights, networking, and fun in Las Vegas this August. Don't miss our exciting events and activities!

## Understanding NIST's latest updates on container image security

DevFeed: [Understanding NIST's latest updates on container image security](<https://devfeed.tech/articles/understanding-nist-s-latest-updates-on-container-image-security-13301.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/understanding-nists-latest-updates-on-container-image-security>)

Published: 2024-07-12T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [container-security](<https://devfeed.tech/topics/container-security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-image-security](<https://devfeed.tech/tags/container-image-security.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [image-security](<https://devfeed.tech/tags/image-security.md>), [nist](<https://devfeed.tech/tags/nist.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article explains NIST guidance relevant to container image security, including risks from misconfiguration, runtime threats, limited visibility, governance gaps, and compliance issues. It discusses NIST SP 800-161 Revision 1 and its focus on cybersecurity supply chain risk management, vulnerability monitoring, configuration management, authorization, and authentication.

### Source excerpt

Learn about NIST's latest updates on container image security and how it impacts your organization's security posture.

## Chainguard's STIG-Hardened FIPS Images now generally available

DevFeed: [Chainguard's STIG-Hardened FIPS Images now generally available](<https://devfeed.tech/articles/chainguard-s-stig-hardened-fips-images-now-generally-available-12996.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguards-stig-hardened-fips-images-now-generally-available>)

Published: 2024-07-11T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Security](<https://devfeed.tech/topics/security.md>), [Operating system](<https://devfeed.tech/topics/operating-system.md>), [Docker Hardened Images](<https://devfeed.tech/topics/docker-hardened-images.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [fips](<https://devfeed.tech/tags/fips.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [html](<https://devfeed.tech/tags/html.md>), [report](<https://devfeed.tech/tags/report.md>), [security](<https://devfeed.tech/tags/security.md>), [security-technical-implementation-guide](<https://devfeed.tech/tags/security-technical-implementation-guide.md>), [stig](<https://devfeed.tech/tags/stig.md>), [stigs](<https://devfeed.tech/tags/stigs.md>)

### AI overview

Chainguard announced the general availability of STIG-hardened FIPS Images. The release maps applicable GPOS SRG controls to containers and provides the STIG in XCCDF format for validation with SCAP tools, supporting FedRAMP compliance workflows.

### Source excerpt

Enhance your container security with Chainguard's STIG-hardened FIPS images, now generally available, offering unparalleled compliance and protection.

## Build a golden image program with Chainguard Images and JFrog Artifactory and Xray

DevFeed: [Build a golden image program with Chainguard Images and JFrog Artifactory and Xray](<https://devfeed.tech/articles/build-a-golden-image-program-with-chainguard-images-and-jfrog-artifactory-and-xray-12899.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/build-a-golden-image-program-with-chainguard-images-and-jfrog-artifactory-and-xray>)

Published: 2024-07-09T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [container-security](<https://devfeed.tech/topics/container-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Platform Engineering](<https://devfeed.tech/topics/platform-engineering.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [DevOps](<https://devfeed.tech/topics/devops.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [build](<https://devfeed.tech/tags/build.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container](<https://devfeed.tech/tags/container.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cves](<https://devfeed.tech/tags/cves.md>), [developers](<https://devfeed.tech/tags/developers.md>), [development](<https://devfeed.tech/tags/development.md>), [devops](<https://devfeed.tech/tags/devops.md>), [golden-image](<https://devfeed.tech/tags/golden-image.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [integration](<https://devfeed.tech/tags/integration.md>), [jfrog](<https://devfeed.tech/tags/jfrog.md>), [jfrog-artifactory](<https://devfeed.tech/tags/jfrog-artifactory.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [safe-source-for-open-source](<https://devfeed.tech/tags/safe-source-for-open-source.md>), [xray](<https://devfeed.tech/tags/xray.md>)

### AI overview

The article explains how to build a secure golden image program by combining Chainguard Images with JFrog Artifactory and Xray. It describes using hardened container images, centralized artifact management, continuous vulnerability scanning, and a curated open source catalog to support platform and DevOps teams.

### Source excerpt

Learn how to create a secure and streamlined golden image program with Chainguard Images, JFrog Artifactory, and Xray.

## Get Smart in Five Minutes: Is your software supply chain secure?

DevFeed: [Get Smart in Five Minutes: Is your software supply chain secure?](<https://devfeed.tech/articles/get-smart-in-five-minutes-is-your-software-supply-chain-secure-13062.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/get-smart-in-five-minutes-is-your-software-supply-chain-secure>)

Published: 2024-06-18T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [article](<https://devfeed.tech/tags/article.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [dan-lorenc](<https://devfeed.tech/tags/dan-lorenc.md>), [get-smart](<https://devfeed.tech/tags/get-smart.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [sscs](<https://devfeed.tech/tags/sscs.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>)

### AI overview

This article presents Episode 2 of "Get Smart in 5 Minutes," focused on software supply chain security. It explains risks from vulnerable software components, the benefits and risks of open-source software, supply chain attacks, inventory management, and choosing well-maintained components. Dan Lorenc of Chainguard provides expert commentary.

### Source excerpt

Worried about your software supply chain? Take 5 minutes to learn about the risks and how to mitigate them. Secure your software today.

## STIG hardening container images

DevFeed: [STIG hardening container images](<https://devfeed.tech/articles/stig-hardening-container-images-13239.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/stig-hardening-container-images>)

Published: 2024-06-07T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [container-security](<https://devfeed.tech/topics/container-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [containers](<https://devfeed.tech/tags/containers.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [hardened-image](<https://devfeed.tech/tags/hardened-image.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [security](<https://devfeed.tech/tags/security.md>), [security-technical-implementation-guide](<https://devfeed.tech/tags/security-technical-implementation-guide.md>), [stig](<https://devfeed.tech/tags/stig.md>), [stig-hardening](<https://devfeed.tech/tags/stig-hardening.md>)

### AI overview

The article discusses hardening container images against STIG requirements, including how to distinguish controls that apply to containers from those that apply to the host operating system or Docker service. It also notes that false positives can occur in container security scans.

### Source excerpt

Dive into the world of STIG hardening for container images. Explore expert insights, practical tips, and Chainguard solutions to fortify your container security.

[Next page](<https://devfeed.tech/topics/container-security.md?cursor=WyIyMDI0LTA2LTA3VDAwOjAwOjAwKzAwOjAwIiwgIjc1OTE4MDE4LTdjMTUtNDNkMC05MzRmLTAxMjEzOGFkYWVkMSJd>)