r/devsecops
We already use hardened images, now looking at chainguard alternatives for curated language libraries
- upvotes
- 12
- comments
- 14
Post
We spent most of last year cutting inherited CVEs out of our container images. Now the attention has moved to the application dependencies that end up inside those images. We already use hardened base images and I noticed a couple of vendors now offer curated language libraries as well. I care about package quality and malware screening and how it fits our existing build pipelines. Feature lists all look alike so I want real world experience. For teams that tried curated libraries in production how did it work out?
Extracted from these lines
[comment u/ILoveAppSec] we tried chainguard for patched oss libs and weren't thrilled with the variety of coverage, so worth asking each vendor for their eol and backport poli