CVE
How Chainguard issues Security Advisories
The life cycle of Chainguard-issued Security Advisories
Strategies for minimizing your CVE riskLearn strategies for minimizing CVE risk in container images, including how Chainguard's approach to minimal images and rapid patching helps reduce vulnerabilities
False positives and false negatives with container image scannersAn overview of the formation of false positive and false negative vulnerability results in container image scanners
Check whether a reported CVE affects your containerUse chainctl images advisories list to compare a scanner's CVE findings with Chainguard's advisories for the APK packages in an image.
Using Grype to scan software artifactsLearn to use Grype to detect CVEs in images
How to use Chainguard Security AdvisoriesArticle outlining how one can explore and use the Security Advisories found on the Chainguard Container Directory.
Resolve a scanner finding for a CVE Chainguard has fixedWhat to check when the Chainguard Console or a security advisory says a CVE is fixed, but your vulnerability scanner still reports it.