# grype

Grype is a vulnerability scanner for container images and filesystems that also scans SBOMs for known vulnerabilities.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Is Grype a single point of failure for Chainguard's CVE detection?

DevFeed: [Is Grype a single point of failure for Chainguard's CVE detection?](<https://devfeed.tech/articles/is-grype-a-single-point-of-failure-for-chainguard-s-cve-detection-13127.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/is-grype-a-single-point-of-failure-for-chainguards-cve-detection>)

Published: 2026-04-10T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [grype](<https://devfeed.tech/topics/grype.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Containers](<https://devfeed.tech/topics/containers.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [chainguard-scanners](<https://devfeed.tech/tags/chainguard-scanners.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cve](<https://devfeed.tech/tags/cve.md>), [grype](<https://devfeed.tech/tags/grype.md>), [malware](<https://devfeed.tech/tags/malware.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [source](<https://devfeed.tech/tags/source.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>), [trivy](<https://devfeed.tech/tags/trivy.md>)

### AI overview

The article explains why Grype is not a single point of failure in Chainguard's CVE detection system. It describes layered defenses including building Grype from source, malware detection, and alternative input-source protections to improve the reliability of security findings.

### Source excerpt

Is Grype a single point of failure? Learn how Chainguard uses layered defenses, source builds, and multiple data sources to ensure trusted CVE detection.

## How Chainguard Automated Detection and Patching of a High-Severity CVE

DevFeed: [How Chainguard Automated Detection and Patching of a High-Severity CVE](<https://devfeed.tech/articles/this-shit-is-hard-the-life-and-death-of-a-cve-in-the-chainguard-factory-13291.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/this-shit-is-hard-the-life-and-death-of-a-cve-in-the-chainguard-factory>)

Published: 2026-02-13T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [anchore](<https://devfeed.tech/topics/anchore.md>), [grype](<https://devfeed.tech/topics/grype.md>), [ci](<https://devfeed.tech/topics/ci.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [anchore](<https://devfeed.tech/tags/anchore.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-cve-remediation](<https://devfeed.tech/tags/chainguard-cve-remediation.md>), [chainguard-factory](<https://devfeed.tech/tags/chainguard-factory.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [ci](<https://devfeed.tech/tags/ci.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [github](<https://devfeed.tech/tags/github.md>), [grype](<https://devfeed.tech/tags/grype.md>), [pull-request](<https://devfeed.tech/tags/pull-request.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

The article describes how Chainguard's Factory detected a high-severity vulnerability affecting k9s, updated Grype, opened and merged a pull request, and published a fixed package within 46 hours of the advisory. It also reports that Chainguard remediated 2,960 unique CVEs in November 2025 while meeting its stated remediation SLA.

### Source excerpt

The Chainguard Factory and DriftlessAF automate CVE detection and patching, delivering fixes in hours and maintaining industry-leading remediation SLAs.

## Introducing Scanfrog: Dodge Container Vulnerabilities

DevFeed: [Introducing Scanfrog: Dodge Container Vulnerabilities](<https://devfeed.tech/articles/introducing-scanfrog-dodge-container-vulnerabilities-13120.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-scanfrog-dodge-container-vulnerabilities>)

Published: 2025-07-30T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Containers](<https://devfeed.tech/topics/containers.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [grype](<https://devfeed.tech/topics/grype.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Security](<https://devfeed.tech/topics/security.md>), [Terminal](<https://devfeed.tech/topics/terminal.md>), [arcade](<https://devfeed.tech/topics/arcade.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [anchore](<https://devfeed.tech/tags/anchore.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [container](<https://devfeed.tech/tags/container.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [container-image-vulnerabilities](<https://devfeed.tech/tags/container-image-vulnerabilities.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [free](<https://devfeed.tech/tags/free.md>), [games](<https://devfeed.tech/tags/games.md>), [grype](<https://devfeed.tech/tags/grype.md>), [management](<https://devfeed.tech/tags/management.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [scanfrog](<https://devfeed.tech/tags/scanfrog.md>), [security](<https://devfeed.tech/tags/security.md>), [terminal](<https://devfeed.tech/tags/terminal.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-scanner](<https://devfeed.tech/tags/vulnerability-scanner.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

Scanfrog is a Frogger-style terminal game that turns vulnerabilities found in a container image into game obstacles. It uses Grype, a free and open-source vulnerability scanner, to create levels based on vulnerability-scanning results and illustrates why reducing vulnerabilities improves software security.

### Source excerpt

Scanfrog is a Frogger-style game created by one of Chainguard's engineers to showcase how difficult it can be to dodge vulnerabilities in containers.

## Guardcraft: A Minecraft Java Server with Zero CVEs

DevFeed: [Guardcraft: A Minecraft Java Server with Zero CVEs](<https://devfeed.tech/articles/guardcraft-a-minecraft-java-server-with-zero-cves-13073.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/guardcraft-a-minecraft-java-server-with-zero-cves>)

Published: 2025-02-28T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [grype](<https://devfeed.tech/topics/grype.md>), [Docker Hub](<https://devfeed.tech/topics/docker-hub.md>), [Security](<https://devfeed.tech/topics/security.md>), [Ubuntu](<https://devfeed.tech/topics/ubuntu.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Steam Deck](<https://devfeed.tech/topics/steam-deck.md>)

Tags: [bedrock](<https://devfeed.tech/tags/bedrock.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container](<https://devfeed.tech/tags/container.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [containers](<https://devfeed.tech/tags/containers.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-hub](<https://devfeed.tech/tags/docker-hub.md>), [grype](<https://devfeed.tech/tags/grype.md>), [guardcraft](<https://devfeed.tech/tags/guardcraft.md>), [linux](<https://devfeed.tech/tags/linux.md>), [security](<https://devfeed.tech/tags/security.md>), [steam-deck](<https://devfeed.tech/tags/steam-deck.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

The article describes building a Minecraft Java server with a Chainguard Image. It compares a popular Ubuntu-based Docker Hub image with the Chainguard approach, highlighting the former's 165 unresolved CVEs and the latter's stated result of zero CVEs.

### Source excerpt

We built a Minecraft Java server using a Chainguard Image, resulting in zero CVEs and a whole lot of fun!

## Can auto-patched container images pass the zero CVE challenge?

DevFeed: [Can auto-patched container images pass the zero CVE challenge?](<https://devfeed.tech/articles/can-auto-patched-container-images-pass-the-zero-cve-challenge-12914.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/can-auto-patched-container-images-pass-the-zero-cve-challenge>)

Published: 2024-07-17T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [container images](<https://devfeed.tech/topics/container-images.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [grype](<https://devfeed.tech/topics/grype.md>), [trivy](<https://devfeed.tech/topics/trivy.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container](<https://devfeed.tech/tags/container.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [grype](<https://devfeed.tech/tags/grype.md>), [security](<https://devfeed.tech/tags/security.md>), [trivy](<https://devfeed.tech/tags/trivy.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article examines whether auto-patching can reduce vulnerabilities in container images. An experiment involving 20 popular images found that copacetic reduced CVEs by an average of 8%, while manually updating packages reduced them by 9%. Chainguard Images reduced CVEs by 99% in the reported comparison.

### Source excerpt

Discover how Chainguard surpasses copacetic in the zero-CVE challenge. Ensure vulnerability-free deployments with our Chainguard Images.

## How much time is wasted triaging known exploits?

DevFeed: [How much time is wasted triaging known exploits?](<https://devfeed.tech/articles/how-much-time-is-wasted-triaging-known-exploits-13091.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-much-time-is-wasted-triaging-known-exploits>)

Published: 2024-06-21T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [grype](<https://devfeed.tech/topics/grype.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [base-container-images](<https://devfeed.tech/tags/base-container-images.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-management](<https://devfeed.tech/tags/cve-management.md>), [cves](<https://devfeed.tech/tags/cves.md>), [efficiency](<https://devfeed.tech/tags/efficiency.md>), [exploited-vulnerabilities](<https://devfeed.tech/tags/exploited-vulnerabilities.md>), [exploits](<https://devfeed.tech/tags/exploits.md>), [grype](<https://devfeed.tech/tags/grype.md>), [kev-catalog](<https://devfeed.tech/tags/kev-catalog.md>), [known-exploited-vulnerability](<https://devfeed.tech/tags/known-exploited-vulnerability.md>), [nvd-cve](<https://devfeed.tech/tags/nvd-cve.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-detection](<https://devfeed.tech/tags/vulnerability-detection.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

The article reports that seven percent of 230 popular Bitnami container images contained CVEs listed in the Known Exploited Vulnerability catalog, but detailed triage found that none were exploitable in those container contexts. It argues that CVE triage consumes substantial staff time, while Chainguard Images historically remediated affected CVEs in an average of 2.5 days.

### Source excerpt

Stop wasting time on known exploits. Read our latest research and discover strategies to streamline your vulnerability management for maximum efficiency.

## Building minimal and low CVE images for Java

DevFeed: [Building minimal and low CVE images for Java](<https://devfeed.tech/articles/building-minimal-and-low-cve-images-for-java-12907.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/building-minimal-and-low-cve-images-for-java>)

Published: 2024-06-11T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Java](<https://devfeed.tech/topics/java.md>), [Security](<https://devfeed.tech/topics/security.md>), [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [Maven](<https://devfeed.tech/topics/maven.md>), [grype](<https://devfeed.tech/topics/grype.md>), [Spring Boot](<https://devfeed.tech/topics/spring-boot.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Docker Hub](<https://devfeed.tech/topics/docker-hub.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cves](<https://devfeed.tech/tags/cves.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-hub](<https://devfeed.tech/tags/docker-hub.md>), [grype](<https://devfeed.tech/tags/grype.md>), [java](<https://devfeed.tech/tags/java.md>), [java-migration](<https://devfeed.tech/tags/java-migration.md>), [security](<https://devfeed.tech/tags/security.md>), [spring-boot](<https://devfeed.tech/tags/spring-boot.md>), [tooling](<https://devfeed.tech/tags/tooling.md>)

### AI overview

This article demonstrates how to build smaller, lower-CVE container images for Java applications with Chainguard Images. It compares a Maven-based Docker image with a Chainguard equivalent, then uses a multi-stage build to remove build tooling and source code from the production image.

### Source excerpt

Build secure, minimal Java images with fewer CVEs. Learn how Chainguard Images helps you optimize security and performance for your Java applications.

## The story of the most vulnerable Chainguard Image

DevFeed: [The story of the most vulnerable Chainguard Image](<https://devfeed.tech/articles/the-story-of-the-most-vulnerable-chainguard-image-13273.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-story-of-the-most-vulnerable-chainguard-image>)

Published: 2024-04-01T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [grype](<https://devfeed.tech/topics/grype.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [common-exposures-and-vulnerabilities](<https://devfeed.tech/tags/common-exposures-and-vulnerabilities.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [grype](<https://devfeed.tech/tags/grype.md>), [release](<https://devfeed.tech/tags/release.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard humorously announces a deliberately insecure Chainguard Image containing nearly 300,000 known vulnerabilities according to Grype. The article contrasts it with the company's hardened images and warns readers not to use the vulnerable image in production or near clusters.

### Source excerpt

Chainguard jokingly revels its 'most vulnerable' Image with 300,000 CVEs as an April Fools' joke, showcasing just how many CVEs they protect against.

## Can debloated containers pass the zero CVE test?

DevFeed: [Can debloated containers pass the zero CVE test?](<https://devfeed.tech/articles/can-debloated-containers-pass-the-zero-cve-test-12915.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/can-debloated-containers-pass-the-zero-cve-test>)

Published: 2023-11-20T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Containers](<https://devfeed.tech/topics/containers.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [grype](<https://devfeed.tech/topics/grype.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cves](<https://devfeed.tech/tags/cves.md>), [grype](<https://devfeed.tech/tags/grype.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security-research](<https://devfeed.tech/tags/software-supply-chain-security-research.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

The article analyzes 28 debloated container images and finds that they reduce CVEs by an average of 64% compared with baseline images, but still contain an average of 33 CVEs. It also reports an average of five high or critical vulnerabilities, concluding that debloated containers do not pass the zero-CVE test. The comparison uses Grype and includes Chainguard Images versions.

### Source excerpt

Exploring the efficiency of debloated containers in the Zero CVE test: Chaingaurd's analysis of security and efficiency.

## Grype Adds OpenVEX Support for Vulnerability Analysis

DevFeed: [Grype Adds OpenVEX Support for Vulnerability Analysis](<https://devfeed.tech/articles/vexed-then-grype-about-it-chainguard-and-anchore-announce-grype-supports-openvex-13311.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/vexed-then-grype-about-it-chainguard-and-anchore-announce-grype-supports-openvex>)

Published: 2023-10-10T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [grype](<https://devfeed.tech/topics/grype.md>), [openvex](<https://devfeed.tech/topics/openvex.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [anchore](<https://devfeed.tech/topics/anchore.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [anchore](<https://devfeed.tech/tags/anchore.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cybersecurity-and-infrastructure-security-agency](<https://devfeed.tech/tags/cybersecurity-and-infrastructure-security-agency.md>), [grype](<https://devfeed.tech/tags/grype.md>), [openssf](<https://devfeed.tech/tags/openssf.md>), [openvex](<https://devfeed.tech/tags/openvex.md>), [scanner](<https://devfeed.tech/tags/scanner.md>), [security](<https://devfeed.tech/tags/security.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [vex](<https://devfeed.tech/tags/vex.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [vulnerability-scanner](<https://devfeed.tech/tags/vulnerability-scanner.md>)

### AI overview

Grype, Anchore's open-source vulnerability scanner, now supports OpenVEX, a machine-readable standard for vulnerability analysis. The article explains how this can provide context for vulnerabilities and help reduce false positives and vulnerability-management effort.

### Source excerpt

Open source vulnerability scanner Grype has added support for OpenVEX, making software supply chain security easier. Learn how to implement it today.

## Why Chainguard uses Grype as its first line of defense for CVEs

DevFeed: [Why Chainguard uses Grype as its first line of defense for CVEs](<https://devfeed.tech/articles/why-chainguard-uses-grype-as-its-first-line-of-defense-for-cves-13327.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/why-chainguard-uses-grype-as-its-first-line-of-defense-for-cves>)

Published: 2023-10-06T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [grype](<https://devfeed.tech/topics/grype.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Go](<https://devfeed.tech/topics/go.md>), [trivy](<https://devfeed.tech/topics/trivy.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [cves](<https://devfeed.tech/tags/cves.md>), [false-negative](<https://devfeed.tech/tags/false-negative.md>), [false-positive](<https://devfeed.tech/tags/false-positive.md>), [go](<https://devfeed.tech/tags/go.md>), [grype](<https://devfeed.tech/tags/grype.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [prisma-cloud](<https://devfeed.tech/tags/prisma-cloud.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [trivy](<https://devfeed.tech/tags/trivy.md>), [vex](<https://devfeed.tech/tags/vex.md>)

### AI overview

Chainguard explains why it selected Grype as the foundation of its internal vulnerability detection system. The article describes scanning early in the software delivery pipeline, using Grype as a Go library to scan Wolfi APK packages before container images are built, and contributing vulnerability data and improvements to the open-source project. It also briefly compares Grype's open data pipeline with Trivy's.

### Source excerpt

Chainguard harnesses Grype's open-source power to ensure minimal CVEs in images, prioritizing user security.

## The zero CVE challenge: Can official Docker Hub images pass the test?

DevFeed: [The zero CVE challenge: Can official Docker Hub images pass the test?](<https://devfeed.tech/articles/the-zero-cve-challenge-can-official-docker-hub-images-pass-the-test-13276.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-zero-cve-challenge-can-official-docker-hub-images-pass-the-test>)

Published: 2023-08-03T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Docker](<https://devfeed.tech/topics/docker.md>), [Docker Hub](<https://devfeed.tech/topics/docker-hub.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Debian](<https://devfeed.tech/topics/debian.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [grype](<https://devfeed.tech/topics/grype.md>)

Tags: [container-security](<https://devfeed.tech/tags/container-security.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cves](<https://devfeed.tech/tags/cves.md>), [debian](<https://devfeed.tech/tags/debian.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-hub](<https://devfeed.tech/tags/docker-hub.md>), [docker-hub-image](<https://devfeed.tech/tags/docker-hub-image.md>), [docker-images](<https://devfeed.tech/tags/docker-images.md>), [grype](<https://devfeed.tech/tags/grype.md>), [image-cves](<https://devfeed.tech/tags/image-cves.md>), [security](<https://devfeed.tech/tags/security.md>), [software](<https://devfeed.tech/tags/software.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

An analysis of ten widely used official Docker Hub images found that updating all operating-system packages reduced vulnerability counts by less than 6% on average. Approximately 98% of the vulnerabilities were associated with Debian-based packages, and the average image still had 225 vulnerabilities after updates.

### Source excerpt

Uncover the findings of the Zero CVE Challenge on Official Docker Hub Images, a step towards secure containerization.