# vulnerability scanning

A technique or automated process for identifying hosts, assets, defects, and associated security vulnerabilities.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## We invited a direct competitor into Security Hub Extended. Here's why.

DevFeed: [We invited a direct competitor into Security Hub Extended. Here's why.](<https://devfeed.tech/articles/we-invited-a-direct-competitor-into-security-hub-extended-here-s-why-4693.md>)

Original publisher: [Read original article](<https://aws.amazon.com/blogs/security/we-invited-a-direct-competitor-into-security-hub-extended-heres-why/>)

Author: Michael Fuller

Published: 2026-08-31T19:00:07Z

Content type: opinion

Language: en

Sources: [AWS Security Blog](<https://devfeed.tech/sources/aws-security-blog.md>)

Topics: [AWS Security Hub](<https://devfeed.tech/topics/aws-security-hub.md>), [Security & compliance, Cloud security](<https://devfeed.tech/topics/security-compliance-cloud-security.md>), [workload protection](<https://devfeed.tech/topics/workload-protection.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [eBPF](<https://devfeed.tech/topics/ebpf.md>), [Linux Kernel](<https://devfeed.tech/topics/linux-kernel.md>)

Tags: [announcements](<https://devfeed.tech/tags/announcements.md>), [aws-security-hub](<https://devfeed.tech/tags/aws-security-hub.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [container](<https://devfeed.tech/tags/container.md>), [ebpf](<https://devfeed.tech/tags/ebpf.md>), [foundational-100](<https://devfeed.tech/tags/foundational-100.md>), [linux-kernel](<https://devfeed.tech/tags/linux-kernel.md>), [security](<https://devfeed.tech/tags/security.md>), [security-blog](<https://devfeed.tech/tags/security-blog.md>), [security-identity-compliance](<https://devfeed.tech/tags/security-identity-compliance.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>), [workload-protection](<https://devfeed.tech/tags/workload-protection.md>)

### AI overview

AWS explains why it invited Upwind, a cloud security competitor, into Security Hub Extended. The post says the partnership responds to customer demand, expands choice between posture management and runtime-first protection, and simplifies integration through AWS billing, support, and operations.

### Source excerpt

When customers keep pointing you to a solution that overlaps with parts of your own offering, you have a choice to make. This post is about the choice we made with Upwind, and why we'd make it again. AWS Security Hub Extended exists because customers told us what was working for them in enterprise security [...]

## CMMC Phase 2, explained: Requirements, deadlines, and who's affected

DevFeed: [CMMC Phase 2, explained: Requirements, deadlines, and who's affected](<https://devfeed.tech/articles/cmmc-phase-2-explained-requirements-deadlines-and-who-s-affected-13009.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/cmmc-phase-2-explained>)

Published: 2026-04-29T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [MFA](<https://devfeed.tech/topics/mfa.md>)

Tags: [certificates](<https://devfeed.tech/tags/certificates.md>), [cmmc](<https://devfeed.tech/tags/cmmc.md>), [cmmc-container-images](<https://devfeed.tech/tags/cmmc-container-images.md>), [cmmc-phase-2](<https://devfeed.tech/tags/cmmc-phase-2.md>), [cmvp](<https://devfeed.tech/tags/cmvp.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cybersecurity-maturity-model-certification](<https://devfeed.tech/tags/cybersecurity-maturity-model-certification.md>), [fips](<https://devfeed.tech/tags/fips.md>), [nist](<https://devfeed.tech/tags/nist.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [stig](<https://devfeed.tech/tags/stig.md>), [stigs](<https://devfeed.tech/tags/stigs.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [u-s-dod](<https://devfeed.tech/tags/u-s-dod.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

This article explains the requirements, deadlines, and scope of CMMC Phase 2. It describes the CMMC Level 2 certification requirements for organizations handling Controlled Unclassified Information or supporting Department of Defense and certain civilian agency contracts, including MFA, encryption, vulnerability scanning, supported systems, independent assessments, and compliance documentation.

### Source excerpt

CMMC Phase 2 and NIST 800-171 are here. Learn how Chainguard helps teams meet compliance with FIPS, STIGs, and zero-CVE containers.

## Introducing Our Newest Ecosystem Integration: Anchore Enterprise

DevFeed: [Introducing Our Newest Ecosystem Integration: Anchore Enterprise](<https://devfeed.tech/articles/introducing-our-newest-ecosystem-integration-anchore-enterprise-13119.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-our-newest-ecosystem-integration-anchore-enterprise>)

Published: 2025-09-23T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [anchore](<https://devfeed.tech/topics/anchore.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>)

Tags: [anchore](<https://devfeed.tech/tags/anchore.md>), [anchore-enterprise](<https://devfeed.tech/tags/anchore-enterprise.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-partners](<https://devfeed.tech/tags/chainguard-partners.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [integration](<https://devfeed.tech/tags/integration.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

Chainguard announces a new integration with Anchore Enterprise. The integration combines Chainguard's secure-by-default container images with Anchore's SBOM management, vulnerability scanning, and automated compliance policy enforcement to support continuous software security and compliance.

### Source excerpt

Discover more about Chainguard's new integration with Anchore Enterprise.

## Introducing Scanfrog: Dodge Container Vulnerabilities

DevFeed: [Introducing Scanfrog: Dodge Container Vulnerabilities](<https://devfeed.tech/articles/introducing-scanfrog-dodge-container-vulnerabilities-13120.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-scanfrog-dodge-container-vulnerabilities>)

Published: 2025-07-30T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Containers](<https://devfeed.tech/topics/containers.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [grype](<https://devfeed.tech/topics/grype.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Security](<https://devfeed.tech/topics/security.md>), [Terminal](<https://devfeed.tech/topics/terminal.md>), [arcade](<https://devfeed.tech/topics/arcade.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [anchore](<https://devfeed.tech/tags/anchore.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [container](<https://devfeed.tech/tags/container.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [container-image-vulnerabilities](<https://devfeed.tech/tags/container-image-vulnerabilities.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [free](<https://devfeed.tech/tags/free.md>), [games](<https://devfeed.tech/tags/games.md>), [grype](<https://devfeed.tech/tags/grype.md>), [management](<https://devfeed.tech/tags/management.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [scanfrog](<https://devfeed.tech/tags/scanfrog.md>), [security](<https://devfeed.tech/tags/security.md>), [terminal](<https://devfeed.tech/tags/terminal.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-scanner](<https://devfeed.tech/tags/vulnerability-scanner.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

Scanfrog is a Frogger-style terminal game that turns vulnerabilities found in a container image into game obstacles. It uses Grype, a free and open-source vulnerability scanner, to create levels based on vulnerability-scanning results and illustrates why reducing vulnerabilities improves software security.

### Source excerpt

Scanfrog is a Frogger-style game created by one of Chainguard's engineers to showcase how difficult it can be to dodge vulnerabilities in containers.

## Chainguard Now Available on Microsoft Azure Marketplace; Scan Chainguard Container Images with Microsoft Defender for Cloud

DevFeed: [Chainguard Now Available on Microsoft Azure Marketplace; Scan Chainguard Container Images with Microsoft Defender for Cloud](<https://devfeed.tech/articles/chainguard-now-available-on-microsoft-azure-marketplace-scan-chainguard-container-images-with-microsoft-defender-for-cloud-12973.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-now-available-on-microsoft-azure-marketplace>)

Published: 2025-07-16T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Azure](<https://devfeed.tech/topics/azure.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [azure](<https://devfeed.tech/tags/azure.md>), [azure-marketplace](<https://devfeed.tech/tags/azure-marketplace.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [defender](<https://devfeed.tech/tags/defender.md>), [microsoft-defender](<https://devfeed.tech/tags/microsoft-defender.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

Chainguard Containers is now available through the Microsoft Azure Marketplace, enabling Azure customers to adopt it within existing procurement, billing, deployment, and CI/CD workflows. Microsoft Defender for Cloud can also scan Chainguard container images for vulnerabilities, improving visibility and security across container environments.

### Source excerpt

Chainguard is now listed on the Microsoft Azure Marketplace. In addition, Microsoft Defender for Cloud can now scan Chainguard container images.

## FedRAMP vulnerability scanning requirements explained

DevFeed: [FedRAMP vulnerability scanning requirements explained](<https://devfeed.tech/articles/fedramp-vulnerability-scanning-requirements-explained-13042.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/fedramp-vulnerability-scanning-requirements-explained>)

Author: Can secure-by-default container images or VMs speed up FedRAMP authorization

Published: 2024-11-21T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [Containers](<https://devfeed.tech/topics/containers.md>)

Tags: [audits](<https://devfeed.tech/tags/audits.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [automated](<https://devfeed.tech/tags/automated.md>), [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cve](<https://devfeed.tech/tags/cve.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fips](<https://devfeed.tech/tags/fips.md>), [requirements](<https://devfeed.tech/tags/requirements.md>), [security](<https://devfeed.tech/tags/security.md>), [stigs](<https://devfeed.tech/tags/stigs.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

This article explains FedRAMP vulnerability scanning requirements, including the required scan scope, recurring authenticated scans, reporting expectations, remediation timelines, and the role of scan data in continuous monitoring, authorization evidence, POA&Ms, and risk reviews.

### Source excerpt

Understand FedRAMP vulnerability scanning rules, scope, and SLAs. Get compliance clarity and learn how to simplify audits.

## Snyk Code now secures AI builds with support for LLM sources

DevFeed: [Snyk Code now secures AI builds with support for LLM sources](<https://devfeed.tech/articles/snyk-code-now-secures-ai-builds-with-support-for-llm-sources-8119.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-code-secures-ai-builds/>)

Author: Liqian Lim (林利蒨); Ranko Cupovic

Published: 2024-06-25T13:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk](<https://devfeed.tech/topics/snyk.md>), [snyk-code](<https://devfeed.tech/topics/snyk-code.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [Code](<https://devfeed.tech/topics/code.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [ai](<https://devfeed.tech/tags/ai.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [coding](<https://devfeed.tech/tags/coding.md>), [convert-paid](<https://devfeed.tech/tags/convert-paid.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [executive](<https://devfeed.tech/tags/executive.md>), [interest](<https://devfeed.tech/tags/interest.md>), [llms](<https://devfeed.tech/tags/llms.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

Snyk Code has been updated to treat data returned by supported LLM libraries as untrusted sources. It performs taint analysis across data flows, detects unsanitized data reaching sensitive functions or stores, and alerts developers to potential security issues in AI-enabled applications.

### Source excerpt

Snyk Code can now protect the use of supported LLM libraries in source code to detect any security issues and promptly alert users. Book a live demo.

## Unlocking Chainguard's container security solutions

DevFeed: [Unlocking Chainguard's container security solutions](<https://devfeed.tech/articles/unlocking-chainguard-s-container-security-solutions-13304.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/unlocking-chainguards-container-security-solutions>)

Published: 2024-03-05T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Docker Hardened Images](<https://devfeed.tech/topics/docker-hardened-images.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-fatigue](<https://devfeed.tech/tags/cve-fatigue.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

This article discusses Chainguard's approach to container security, focusing on minimal hardened container images, SBOMs, signatures, vulnerability scanning, continuous monitoring, and updates. It also considers the operational trade-offs between building container images internally and using managed solutions.

### Source excerpt

Uncover insights on whether to build or buy in container lifecycle management with tips from Chainguard, balancing security and operational needs.

## Streamline dependency updates with Mergify and Snyk

DevFeed: [Streamline dependency updates with Mergify and Snyk](<https://devfeed.tech/articles/streamline-dependency-updates-with-mergify-and-snyk-7887.md>)

Original publisher: [Read original article](<https://snyk.io/blog/dependency-updates-mergify-snyk/>)

Author: Liran Tal

Published: 2023-08-23T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Dependency management](<https://devfeed.tech/topics/dependency-management.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [pull-requests](<https://devfeed.tech/topics/pull-requests.md>), [ci](<https://devfeed.tech/topics/ci.md>), [Code review](<https://devfeed.tech/topics/code-review.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [snyk-open-source](<https://devfeed.tech/topics/snyk-open-source.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [automation](<https://devfeed.tech/tags/automation.md>), [blog](<https://devfeed.tech/tags/blog.md>), [ci](<https://devfeed.tech/tags/ci.md>), [code-review](<https://devfeed.tech/tags/code-review.md>), [dependabot](<https://devfeed.tech/tags/dependabot.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [github](<https://devfeed.tech/tags/github.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

This article explains how Mergify and Snyk can automate dependency update workflows. Snyk identifies dependency updates and creates GitHub pull requests, while Mergify can automate pull request review and merging based on defined conditions, helping teams keep dependencies current and address security fixes with less manual work.

### Source excerpt

Automate dependency updates with Mergify and Snyk.

## Fortify, comply and conquer FedRAMP with Chainguard Images

DevFeed: [Fortify, comply and conquer FedRAMP with Chainguard Images](<https://devfeed.tech/articles/fortify-comply-and-conquer-fedramp-with-chainguard-images-13052.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/fortify-comply-and-conquer-fedramp-with-chainguard-images>)

Published: 2023-05-25T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Linux](<https://devfeed.tech/topics/linux.md>)

Tags: [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cve](<https://devfeed.tech/tags/cve.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fips](<https://devfeed.tech/tags/fips.md>), [hardened-image](<https://devfeed.tech/tags/hardened-image.md>), [linux](<https://devfeed.tech/tags/linux.md>), [nist](<https://devfeed.tech/tags/nist.md>), [secure-container-image](<https://devfeed.tech/tags/secure-container-image.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

This article explains how Chainguard Images can help cloud service providers and federal agencies achieve or maintain FedRAMP authorization. It describes FedRAMP requirements for hardened container images, recurring vulnerability scanning, NVD identifiers, CVSSv3 scores, and vulnerability remediation tracking. It presents Chainguard Images as secure, continuously updated base images built from source on the hardened Wolfi Linux un-distribution.

### Source excerpt

Learn how Chainguard Images can you achieve or maintain your FedRAMP compliance authorization with secure-by-default base images.

## Chainguard Image now available for prometheus

DevFeed: [Chainguard Image now available for prometheus](<https://devfeed.tech/articles/chainguard-image-now-available-for-prometheus-12950.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-image-now-available-for-prometheus>)

Published: 2023-04-14T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Prometheus](<https://devfeed.tech/topics/prometheus.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Go](<https://devfeed.tech/topics/go.md>), [Documentation](<https://devfeed.tech/topics/documentation.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [cosign](<https://devfeed.tech/tags/cosign.md>), [cves](<https://devfeed.tech/tags/cves.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [documentation](<https://devfeed.tech/tags/documentation.md>), [go](<https://devfeed.tech/tags/go.md>), [image](<https://devfeed.tech/tags/image.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [prometheus](<https://devfeed.tech/tags/prometheus.md>), [prometheus-image](<https://devfeed.tech/tags/prometheus-image.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [security](<https://devfeed.tech/tags/security.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [toolchain](<https://devfeed.tech/tags/toolchain.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard announces a Prometheus container image built on Wolfi with a minimal, distroless-style base, hardened toolchain, continuous patching, and fewer reported CVEs. The image includes a default configuration, source-built binaries, SBOMs, signatures, and provenance support.

### Source excerpt

Check out the new Chainguard Image for Prometheus that is minimal in size and contains fewer CVEs than other alternatives.

## Chainguard Image now available for NATS

DevFeed: [Chainguard Image now available for NATS](<https://devfeed.tech/articles/chainguard-image-now-available-for-nats-12948.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-image-now-available-for-nats>)

Published: 2023-03-27T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Messaging](<https://devfeed.tech/topics/messaging.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cli](<https://devfeed.tech/tags/cli.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cosign](<https://devfeed.tech/tags/cosign.md>), [documentation](<https://devfeed.tech/tags/documentation.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [messaging](<https://devfeed.tech/tags/messaging.md>), [minimal-image](<https://devfeed.tech/tags/minimal-image.md>), [nats-image](<https://devfeed.tech/tags/nats-image.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [secure-images](<https://devfeed.tech/tags/secure-images.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard announces a hardened Chainguard Image for NATS, built on Wolfi for containerized workloads. The image includes a development variant with the nats CLI and nsc tool, is reported to be over 50% smaller than comparable options, targets zero known CVEs, and includes source-built binaries, SBOMs, signatures, and provenance information.

### Source excerpt

Learn about our hardened Chainguard Image for NATS, which is built on Wolfi, our secure by default operating system for containerized workloads.

## Chainguard Image now available for Apache Zookeeper

DevFeed: [Chainguard Image now available for Apache Zookeeper](<https://devfeed.tech/articles/chainguard-image-now-available-for-apache-zookeeper-12945.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-image-now-available-for-apache-zookeeper>)

Published: 2023-03-20T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [apache-zookeeper](<https://devfeed.tech/tags/apache-zookeeper.md>), [built-from-source](<https://devfeed.tech/tags/built-from-source.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cosign](<https://devfeed.tech/tags/cosign.md>), [docker-zookeeper](<https://devfeed.tech/tags/docker-zookeeper.md>), [jdk](<https://devfeed.tech/tags/jdk.md>), [kafka-zookeeper](<https://devfeed.tech/tags/kafka-zookeeper.md>), [minimal-image](<https://devfeed.tech/tags/minimal-image.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [secure-images](<https://devfeed.tech/tags/secure-images.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>), [zookeeper-container](<https://devfeed.tech/tags/zookeeper-container.md>), [zookeeper-image](<https://devfeed.tech/tags/zookeeper-image.md>)

### AI overview

Chainguard announces a new Chainguard Image for Apache Zookeeper. Built from source with Wolfi and Chainguard's OpenJDK JRE, the minimal image is hardened for non-root operation and a locked-down filesystem, and is presented as more than 50% smaller than alternatives.

### Source excerpt

New Chainguard Image for Apache Zookeeper is over 50% smaller in size compared to alternatives. Powered by Wolfi, comes with our own JDK, and built from source.

## Chainguard Image now available for Postgres

DevFeed: [Chainguard Image now available for Postgres](<https://devfeed.tech/articles/chainguard-image-now-available-for-postgres-12949.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-image-now-available-for-postgres>)

Published: 2023-03-06T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Databases](<https://devfeed.tech/topics/databases.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [compiler-hardening](<https://devfeed.tech/tags/compiler-hardening.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [cosign](<https://devfeed.tech/tags/cosign.md>), [cves](<https://devfeed.tech/tags/cves.md>), [database-hardened-image](<https://devfeed.tech/tags/database-hardened-image.md>), [hardened-container-image](<https://devfeed.tech/tags/hardened-container-image.md>), [memory](<https://devfeed.tech/tags/memory.md>), [memory-safety](<https://devfeed.tech/tags/memory-safety.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [postgres](<https://devfeed.tech/tags/postgres.md>), [postgres-image](<https://devfeed.tech/tags/postgres-image.md>), [relational-database-image](<https://devfeed.tech/tags/relational-database-image.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-database-image](<https://devfeed.tech/tags/secure-database-image.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [sql-database-image](<https://devfeed.tech/tags/sql-database-image.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard announces a hardened Postgres container image built on Wolfi. The image runs as a non-root user, is built from source with compiler hardening and memory safety features, is 43MB in size, and aims to reduce known CVEs. It also includes SBOMs and provenance information to support vulnerability scanning and license compliance.

### Source excerpt

Run Postgres, now available as a Chainguard Image, as a hardened container image built on Wolfi. Secure Postgres images by default and reduce their size by 90%.

## Hopping into spring with Chainguard's RabbitMQ Image

DevFeed: [Hopping into spring with Chainguard's RabbitMQ Image](<https://devfeed.tech/articles/hopping-into-spring-with-chainguard-s-rabbitmq-image-13082.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/hopping-into-spring-with-chainguards-rabbitmq-image>)

Published: 2023-02-24T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Messaging](<https://devfeed.tech/topics/messaging.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [Erlang](<https://devfeed.tech/topics/erlang.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [base-images](<https://devfeed.tech/tags/base-images.md>), [bazel](<https://devfeed.tech/tags/bazel.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cosign](<https://devfeed.tech/tags/cosign.md>), [cves](<https://devfeed.tech/tags/cves.md>), [documentation](<https://devfeed.tech/tags/documentation.md>), [image](<https://devfeed.tech/tags/image.md>), [messaging](<https://devfeed.tech/tags/messaging.md>), [minimal-image](<https://devfeed.tech/tags/minimal-image.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [rabbitmq](<https://devfeed.tech/tags/rabbitmq.md>), [rabbitmq-image](<https://devfeed.tech/tags/rabbitmq-image.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-images](<https://devfeed.tech/tags/secure-images.md>), [security](<https://devfeed.tech/tags/security.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>)

### AI overview

Chainguard announces a Chainguard Image for RabbitMQ, an open-source message broker used in cloud-native applications. The image is built from source on Wolfi, with custom Erlang and OTP components, continuous patching, minimal CVEs, SBOMs, signatures, and SLSA Build Level 2 provenance.

### Source excerpt

Unlock advanced messaging capabilities with Chainguard's RabbitMQ image, designed for robustness and security.

## Chainguard Image now available for HAProxy

DevFeed: [Chainguard Image now available for HAProxy](<https://devfeed.tech/articles/chainguard-image-now-available-for-haproxy-12946.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-image-now-available-for-haproxy>)

Published: 2023-02-09T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cosign](<https://devfeed.tech/tags/cosign.md>), [cves](<https://devfeed.tech/tags/cves.md>), [haproxy](<https://devfeed.tech/tags/haproxy.md>), [haproxy-images](<https://devfeed.tech/tags/haproxy-images.md>), [image](<https://devfeed.tech/tags/image.md>), [load-balancer](<https://devfeed.tech/tags/load-balancer.md>), [minimal-image](<https://devfeed.tech/tags/minimal-image.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [secure-images](<https://devfeed.tech/tags/secure-images.md>), [toolchain](<https://devfeed.tech/tags/toolchain.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard announces a Chainguard Image for HAProxy. Built on Wolfi with a hardened toolchain, the image is designed to reduce image size and known vulnerabilities while providing binaries built from source, SBOMs, signatures, and SLSA Build Level 2 provenance.

### Source excerpt

HAProxy Chainguard Image now available: Built on Wolfi, up to 90% smaller, aims for 0-known CVEs, and is built with hardened toolchain, making it memory safe.

## Chainguard Image now available for Kubectl

DevFeed: [Chainguard Image now available for Kubectl](<https://devfeed.tech/articles/chainguard-image-now-available-for-kubectl-12947.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-image-now-available-for-kubectl>)

Published: 2023-02-07T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [ci](<https://devfeed.tech/topics/ci.md>), [GitOps](<https://devfeed.tech/topics/gitops.md>)

Tags: [base-images](<https://devfeed.tech/tags/base-images.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [ci](<https://devfeed.tech/tags/ci.md>), [containers](<https://devfeed.tech/tags/containers.md>), [gitops](<https://devfeed.tech/tags/gitops.md>), [kubectl](<https://devfeed.tech/tags/kubectl.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

Chainguard announces a kubectl image in the Chainguard Images catalog. The image supports multiple architectures, including arm64, is 75% smaller than a commonly used alternative, includes SBOMs, and is signed with Sigstore. Chainguard reports zero known CVEs at publication time.

### Source excerpt

Kubectl added to Chainguard Images catalog. Chainguard kubectl build is 75% smaller than the usual image used & is the only supported image with arm64 support.