Skip to main content
ChainguardCustomer feedback

A user who previously tried Chainguard for patched open-source libraries reported being unsatisfied with the variety of its package coverage.

What happened

Post: "We already use hardened images, now looking at chainguard alternatives for curated language libraries"

Source

Post

We spent most of last year cutting inherited CVEs out of our container images. Now the attention has moved to the application dependencies that end up inside those images. We already use hardened base images and I noticed a couple of vendors now offer curated language libraries as well. I care about package quality and malware screening and how it fits our existing build pipelines. Feature lists all look alike so I want real world experience. For teams that tried curated libraries in production how did it work out?

Extracted from these lines

  • [comment u/ILoveAppSec] we tried chainguard for patched oss libs and weren't thrilled with the variety of coverage, so worth asking each vendor for their eol and backport poli

reddit.com/r/devsecops/comments/1wn7qz0/we_already_use_hardened_image...Read the full source

Comments on the post

5 of 14 comments
  • “Biggest headache is coverage. Your top 200 packages will be there, then some random transitive dep or a version pinned three minors back isn't, and the build breaks at 4pm on a Friday. Put it behind your existing Artifactory/Nexus as a remote, with fallback to public first, so you can see the actual miss rate before you go strict. Also ask each vendor if they rebuild from source or just scan w”

    u/Cubeless-Developers2 points · Sep 22, 2026View

  • “Full disclosure, I work at Seal Security. We backport the CVE fix into the version you're already on (lodash 4.17.15 -> 4.17.15-sp1, zero code changes) instead of pushing you to the next major. Biased take, but nobody covers more ecosystems and old versions than we do, and anything missing gets sealed on demand.”

    u/Shot-Addendum27992 points · Sep 23, 2026View

  • “exploring alternatives sounds smart, keeping libraries curated helps maintain security and stability in the project”

    u/_MistyBloomelle1 points · Sep 22, 2026View

  • “I think it would be a bit of both. We already have enough point solutions, so platform consolidation is definitely a factor. But we also want confidence that developers aren't accidentally pulling questionable packages into new services.”

    u/Adderall_Hurricane1 points · Sep 22, 2026View

  • “We had good results with curated libraries, but the maintenance overhead was real. The biggest win was fewer dependency surprises during builds.”

    u/Dyldough_Night1 points · Sep 22, 2026View

Extracted by Autobound

From the Signal API record
Signal
Customer feedback

What this signalsUser posts often show product pain before it reaches reviews or churn.

Subreddit
r/devsecops

The full record

From the Signal API record

Numbers

Mentions
1

Details

Timing
Completed
Category
Features
Virality
Somewhat high
Post kind
Text
Prominence
Aside
Company's role
Vendor

Topics and mentions

Topics

  • software supply chain security
  • package management
  • feature coverage

Extraction

Sentiment
Negative
Detected
Sep 22, 2026
signal_type
reddit-company
signal_subtype
customerFeedback

Use this data

Get every Reddit signal for Chainguard and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Chainguard this week?”

  2. Send it to your own tools

    The Signal API returns Reddit signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full reddit-company record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/3a8f243a-16e0-5c33-a129-0a9cccff2f79 returns this record as JSON. POST /v1/companies/enrich returns every signal for chainguard.dev.

{
  "signal_id": "3a8f243a-16e0-5c33-a129-0a9cccff2f79",
  "signal_type": "reddit-company",
  "signal_subtype": "customerFeedback",
  "detected_at": "2026-09-22T12:10:56+00:00",
  "company": {
    "name": "Chainguard",
    "domain": "chainguard.dev"
  },
  "data": {
    "nsfw": false,
    "stage": "none",
    "awards": 0,
    "timing": "completed",
    "topics": [
      "software supply chain security",
      "package management",
      "feature coverage"
    ],
    "post_id": "1wn7qz0",
    "summary": "A user who previously tried Chainguard for patched open-source libraries reported being unsatisfied with the variety of its package coverage.",
    "category": "features",
    "comments": [
      {
        "url": "https://www.reddit.com/r/devsecops/comments/1wn7qz0/comment/pbfly8b/",
        "depth": 0,
        "score": 2,
        "author": "Cubeless-Developers",
        "excerpt": "Biggest headache is coverage. Your top 200 packages will be there, then some random transitive dep or a version pinned three minors back isn't, and the build breaks at 4pm on a Friday.\n\n Put it behind your existing Artifactory/Nexus as a remote, with fallback to public first, so you can see the actual miss rate before you go strict.\n\n Also ask each vendor if they rebuild from source or just scan w",
        "posted_at": "2026-09-22T20:05:32.000Z",
        "author_url": "https://www.reddit.com/user/Cubeless-Developers/"
      },
      {
        "url": "https://www.reddit.com/r/devsecops/comments/1wn7qz0/comment/pbjf3at/",
        "depth": 0,
        "score": 2,
        "author": "Shot-Addendum2799",
        "excerpt": "Full disclosure, I work at Seal Security.\nWe backport the CVE fix into the version you're already on (lodash 4.17.15 -> 4.17.15-sp1, zero code changes) instead of pushing you to the next major. Biased take, but nobody covers more ecosystems and old versions than we do, and anything missing gets sealed on demand.",
        "posted_at": "2026-09-23T10:31:56.000Z",
        "author_url": "https://www.reddit.com/user/Shot-Addendum2799/"
      },
      {
        "url": "https://www.reddit.com/r/devsecops/comments/1wn7qz0/comment/pbeudvy/",
        "depth": 0,
        "score": 1,
        "author": "_MistyBloomelle",
        "excerpt": "exploring alternatives sounds smart, keeping libraries curated helps maintain security and stability in the project",
        "posted_at": "2026-09-22T18:08:00.000Z",
        "author_url": "https://www.reddit.com/user/_MistyBloomelle/"
      },
      {
        "url": "https://www.reddit.com/r/devsecops/comments/1wn7qz0/comment/pbfq2qm/",
        "depth": 0,
        "score": 1,
        "author": "Adderall_Hurricane",
        "excerpt": "I think it would be a bit of both. We already have enough point solutions, so platform consolidation is definitely a factor. But we also want confidence that developers aren't accidentally pulling questionable packages into new services.",
        "posted_at": "2026-09-22T20:23:30.000Z",
        "author_url": "https://www.reddit.com/user/Adderall_Hurricane/"
      },
      {
        "url": "https://www.reddit.com/r/devsecops/comments/1wn7qz0/comment/pbgj3me/",
        "depth": 0,
        "score": 1,
        "author": "Dyldough_Night",
        "excerpt": "We had good results with curated libraries, but the maintenance overhead was real. The biggest win was fewer dependency surprises during builds.",
        "posted_at": "2026-09-22T22:41:58.000Z",
        "author_url": "https://www.reddit.com/user/Dyldough_Night/"
      },
      {
        "url": "https://www.reddit.com/r/devsecops/comments/1wn7qz0/comment/pbh6mzp/",
        "depth": 0,
        "score": 1,
        "author": "theJacofalltrades",
        "excerpt": "Hi. I’m a staff platform engineer, and we've been testing both internally. Chainguard has a strong reputation, but RapidFort caught our attention because it combines Curated Libraries with the curated image side of the platform. Managing both dependencies and container images in one place is something we're finding worth evaluating rather than stitching together multiple tools.",
        "posted_at": "2026-09-23T00:49:43.000Z",
        "author_url": "https://www.reddit.com/user/theJacofalltrades/"
      },
      {
        "url": "https://www.reddit.com/r/devsecops/comments/1wn7qz0/comment/pbk4i62/",
        "depth": 0,
        "score": 1,
        "author": "Odd_Salt4155",
        "excerpt": "Curious how you handled updates once the curated libraries were in place did patch cadence feel smoother than pulling straight from upstream, or did it add friction when a CVE fix lagged behind?",
        "posted_at": "2026-09-23T13:04:13.000Z",
        "author_url": "https://www.reddit.com/user/Odd_Salt4155/"
      },
      {
        "url": "https://www.reddit.com/r/devsecops/comments/1wn7qz0/comment/pbwde0x/",
        "depth": 0,
        "score": 1,
        "author": "Prestigious-Flan-931",
        "excerpt": "Hardened base images are great, but application dependencies introduce a different risk model.\n\n They execute inside your application process and often handle some of the most sensitive operations in the app - parsing input, deserialization, file access, network calls, process execution, etc.\n\n And just look at some of the recent incidents. OpenAI was impacted through a compromised TanStack npm de",
        "posted_at": "2026-09-25T03:03:09.000Z",
        "author_url": "https://www.reddit.com/user/Prestigious-Flan-931/"
      }
    ],
    "evidence": [
      "[comment u/ILoveAppSec] we tried chainguard for patched oss libs and weren't thrilled with the variety of coverage, so worth asking each vendor for their eol and backport poli"
    ],
    "virality": "somewhat_high",
    "post_date": "2026-09-22T12:10:56.000Z",
    "post_kind": "text",
    "post_text": "We spent most of last year cutting inherited CVEs out of our container images. Now the attention has moved to the application dependencies that end up inside those images. We already use hardened base images and I noticed a couple of vendors now offer curated language libraries as well. I care about package quality and malware screening and how it fits our existing build pipelines. Feature lists all look alike so I want real world experience. For teams that tried curated libraries in production how did it work out?",
    "sentiment": "negative",
    "subreddit": "devsecops",
    "post_title": "We already use hardened images, now looking at chainguard alternatives for curated language libraries",
    "prominence": "aside",
    "source_url": "https://www.reddit.com/r/devsecops/comments/1wn7qz0/we_already_use_hardened_images_now_looking_at/",
    "entity_role": "vendor",
    "post_author": "Emily-onesg",
    "upvote_ratio": 1,
    "mention_count": 1,
    "mention_surge": false,
    "subreddit_url": "https://www.reddit.com/r/devsecops/",
    "total_upvotes": 12,
    "comments_total": 14,
    "total_comments": 14,
    "post_author_url": "https://www.reddit.com/user/Emily-onesg/",
    "signal_category": "feedback",
    "comments_included": 10
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.