Chainguard Joins Docker Verified Publisher Program |
Written by Alex Denham |
Friday, 15 March 2024 |
Chainguard has joined the Docker Verified Publisher (DVP) program, meaning its Chainguard Developer Images are now officially available on Docker's container image registry. Docker Hub has more than 10 million accounts and nearly 500 billion pulls from the Docker community. The Chainguard Developer Images are secure, minimal container images for cloud-native and open source projects, including Python, Node and Java. Chainguard Developer Images offer a low-to-zero CVE (common vulnerabilities and exposures) commitment so developers can focus on building secure applications, knowing vulnerabilities will be remediated and fixed quickly across the software development lifecycle. The company also provides Chainguard Production Images that meet enterprise requirements for patching Service Level Agreements (SLAs), FIPs-validated images for FedRAMP, and secure AI images. Chainguard says its images have helped organizations see a 97.6% reduction in CVEs and eliminate entire classes of vulnerabilities within their software supply chain. The Image Registry provides passwordless, short-lived token-based authentication and help meet critical software supply chain security requirements by providing Software Bill of Materials (SBOMs) and verified software signatures by Sigstore. Announcing the availability of Chainguard Images on the Docker Hub, Dan Lorenc, CEO and Co-founder of Chainguard said: "Chainguard has built the largest library of open source software that is secure by default. With this partnership, Docker users can now access a trusted resource for secure, hardened, high-quality images." Welcoming Chainguard to the DVP program, Justin Cormack, CTO, Docker said: "Development teams are increasingly prioritizing high quality base images as the key starting point for improving their supply chain. The Docker Verified Publisher program is a key part of Docker’s mission to provide a broad range of trusted, high quality content." To access Chainguard Developer Images on Docker Hub, visit Chainguard's DVP page. More InformationRelated ArticlesChainguard's Enforce Platform Boosted With New Capabilities Chainguard Announces AI Images Bundle Sigstore Java - Sign And Verify Your Java Builds Wolfi Linux (Un)Distribution Secures The Software Supply Chain |
Last Updated ( Friday, 15 March 2024 ) |