For the complete documentation index, see llms.txt.

CVE

How Chainguard issues Security Advisories
The life cycle of Chainguard-issued Security Advisories
Strategies for minimizing your CVE risk
Learn strategies for minimizing CVE risk in container images, including how Chainguard's approach to minimal images and rapid patching helps reduce vulnerabilities
False positives and false negatives with container image scanners
An overview of the formation of false positive and false negative vulnerability results in container image scanners
Check whether a reported CVE affects your container
Use chainctl images advisories list to compare a scanner's CVE findings with Chainguard's advisories for the APK packages in an image.
Using Grype to scan software artifacts
Learn to use Grype to detect CVEs in images
How to use Chainguard Security Advisories
Article outlining how one can explore and use the Security Advisories found on the Chainguard Container Directory.
Resolve a scanner finding for a CVE Chainguard has fixed
What to check when the Chainguard Console or a security advisory says a CVE is fixed, but your vulnerability scanner still reports it.