# cve remediation

CVE remediation is the process of identifying, prioritizing, and resolving publicly disclosed software vulnerabilities across production software.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Custom Assembly Updates: Create Multiple, Customized Variants of a Chainguard Container

DevFeed: [Custom Assembly Updates: Create Multiple, Customized Variants of a Chainguard Container](<https://devfeed.tech/articles/custom-assembly-updates-create-multiple-customized-variants-of-a-chainguard-container-13015.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/custom-assembly-updates-create-multiple-customized-variants-of-a-chainguard-container>)

Published: 2025-10-29T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard custom assembly](<https://devfeed.tech/topics/chainguard-custom-assembly.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [cve remediation](<https://devfeed.tech/topics/cve-remediation.md>)

Tags: [assembly](<https://devfeed.tech/tags/assembly.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-custom-assembly](<https://devfeed.tech/tags/chainguard-custom-assembly.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [custom-assembly](<https://devfeed.tech/tags/custom-assembly.md>), [custom-chainguard-containers](<https://devfeed.tech/tags/custom-chainguard-containers.md>), [custom-chainguard-images](<https://devfeed.tech/tags/custom-chainguard-images.md>), [customers](<https://devfeed.tech/tags/customers.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [new-feature](<https://devfeed.tech/tags/new-feature.md>)

### AI overview

Chainguard announces enhancements to Custom Assembly that let customers create, add, delete, rename, edit, preview, and manage multiple customized variants of Chainguard container images directly in the console. The update supports self-serve provisioning and includes build history, logs, and build status.

### Source excerpt

Customize Chainguard Containers with the latest Custom Assembly update. You can create, edit, and manage secure, zero-CVE image variants directly in the console.

## The Business Costs of CVE Management and the Value of Chainguard Containers

DevFeed: [The Business Costs of CVE Management and the Value of Chainguard Containers](<https://devfeed.tech/articles/the-hidden-costs-of-cves-and-the-value-you-re-leaving-on-the-table-13257.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-hidden-costs-of-cves-and-the-value-youre-leaving-on-the-table>)

Published: 2025-06-23T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [cve remediation](<https://devfeed.tech/topics/cve-remediation.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [business-value-assessment](<https://devfeed.tech/tags/business-value-assessment.md>), [bva](<https://devfeed.tech/tags/bva.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [cves](<https://devfeed.tech/tags/cves.md>), [report](<https://devfeed.tech/tags/report.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article discusses the operational and business costs of managing CVEs in containerized software environments. It presents Chainguard's evaluation of customer benefits from using Chainguard Containers, including reported savings on CVE remediation and container-image hardening, as well as potential value from reduced security risk and redeployed engineering capacity.

### Source excerpt

Chainguard evaluated the amount of money customers are saving and unlocking by utilizing Chainguard Containers as their secure container image solution.

## One Year Later: Signing CISA's Secure by Design Pledge

DevFeed: [One Year Later: Signing CISA's Secure by Design Pledge](<https://devfeed.tech/articles/one-year-later-signing-cisa-s-secure-by-design-pledge-13194.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/one-year-update-to-signing-cisas-secure-by-design-pledge>)

Published: 2025-06-10T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [cve remediation](<https://devfeed.tech/topics/cve-remediation.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [Security](<https://devfeed.tech/topics/security.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [chainguard vms](<https://devfeed.tech/topics/chainguard-vms.md>), [ssh](<https://devfeed.tech/topics/ssh.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-vms](<https://devfeed.tech/tags/chainguard-vms.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [okta](<https://devfeed.tech/tags/okta.md>), [password](<https://devfeed.tech/tags/password.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [secure-by-design-pledge](<https://devfeed.tech/tags/secure-by-design-pledge.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [shift-left](<https://devfeed.tech/tags/shift-left.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [sso](<https://devfeed.tech/tags/sso.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

Chainguard reviews its progress one year after signing CISA's Secure by Design pledge, including CVE remediation across its container images, company-wide MFA through Okta SSO, and password-free access with automated SSH key provisioning for Chainguard VMs.

### Source excerpt

Chainguard signed CISA's Secure by Design pledge in 2024. One year later, we look at progress we've made in key areas like CVE remediation and disclosures.

## What FedRAMP 20x Means for You

DevFeed: [What FedRAMP 20x Means for You](<https://devfeed.tech/articles/what-fedramp-20x-means-for-you-13317.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/what-fedramp-20x-means-for-you>)

Published: 2025-04-02T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Automation](<https://devfeed.tech/topics/automation.md>), [authority to operate](<https://devfeed.tech/topics/authority-to-operate.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [cve remediation](<https://devfeed.tech/topics/cve-remediation.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [authority-to-operate](<https://devfeed.tech/tags/authority-to-operate.md>), [automation](<https://devfeed.tech/tags/automation.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [complexity](<https://devfeed.tech/tags/complexity.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cost](<https://devfeed.tech/tags/cost.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [cves](<https://devfeed.tech/tags/cves.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fedramp-20x](<https://devfeed.tech/tags/fedramp-20x.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article explains that FedRAMP 20x is intended to streamline the authority-to-operate process through automation and continuous validation. It says the core security and compliance controls are not changing and that the existing agency-based FedRAMP Rev. 5 authorization path remains active.

### Source excerpt

FedRAMP 20x is a new initiative designed to automate and simplify the FedRAMP process. Get the rundown on what is changing, and how Chainguard can help.

## Proposed HIPAA Security Rule Updates for Vulnerability Management

DevFeed: [Proposed HIPAA Security Rule Updates for Vulnerability Management](<https://devfeed.tech/articles/hipaa-s-new-vulnerability-management-guidelines-what-you-need-to-know-13081.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/hipaas-new-vulnerability-management-guidelines-what-you-need-to-know>)

Published: 2025-02-11T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [cve remediation](<https://devfeed.tech/topics/cve-remediation.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [cves](<https://devfeed.tech/tags/cves.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [hipaa](<https://devfeed.tech/tags/hipaa.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

The article explains proposed updates to HIPAA's Security Rule, including requirements for container security, risk analysis, data-security practices, and remediation of Common Vulnerabilities and Exposures (CVEs). It states that the proposal would require healthcare organizations to address Critical CVEs within 15 calendar days of discovery.

### Source excerpt

New guidelines for HIPAA's Security Rule have been proposed, which include updated requirements for vulnerability management, risk management, and more.