

Chainguard: Building Secure Container Images
May 3, 2024
Dan Lorenc, from Chainguard, shares insights on creating secure container images, emphasizing the importance of minimalism to enhance security. He discusses the ramifications of the recent XZ supply chain attack and how Chainguard addresses vulnerability management. Dan highlights the benefits of their zero CVE approach, the launch of Chainguard images on Docker Hub, and the need for proactive security practices. He also elaborates on tools for reducing attack surfaces and the significance of frameworks like SLSA in bolstering software security.
Chapters
Transcript
Episode notes
1 2 3 4 5 6 7
Intro
00:00 • 5min
Navigating Software Supply Chain Security
05:28 • 19min
Understanding Hash Differences in Container Images
24:27 • 2min
Securing Container Vulnerabilities
26:51 • 17min
Minimizing SSH Usage and the Evolution of Secure Container Distros
43:43 • 2min
Understanding SLSA: Strengthening Software Security
45:53 • 11min
Exploring ChainGuard: Entry Points and Educational Resources
56:52 • 3min