"Of course, Chainguard is THE goto for base images, high quality software and a strong chain of custody. I can’t imagine people are still using alpine, there should be some more awareness towards image security! Sure you’ve got scratch, ko for Go images and Google’s distroless for various other runtimes, but for truly streamlining it across polyglot repos is only possible with something like Wolfi if you want to achieve enterprise grade production, FedRamp FIPS compliance and with good SLAs. This can only be achieved with Chainguard at least these days."
“In May 2023, in our KOTS repo, we bumped versions of third party software 568 times due to vulnerabilities. I'm certain there were lower severity vulnerabilities that just didn't get addressed because it wasn't worth the effort to go after every vulnerability. This morning, I saw our latest KOTS Chainguard Image and found zero vulnerabilities.”