CVE
False positives and false negatives with container image scanners
An overview of the formation of false positive and false negative vulnerability results in container image scanners
Check whether a reported CVE affects your containerUse chainctl images advisories list to compare a scanner's CVE findings with Chainguard's advisories for the APK packages in an image.
Using Grype to scan software artifactsLearn to use Grype to detect CVEs in images
How to use Chainguard Security AdvisoriesArticle outlining how one can explore and use the Security Advisories found on the Chainguard Container Directory.
How end-of-life software accumulates vulnerabilitiesA conceptual article outlining the risk involved with using EOL software and how EOL images accrue vulnerabilities.
Using wolfictl to manage Security AdvisoriesGuide on how to use the wolfictl tool to create, update, and manage security advisories
Using Trivy to scan software artifactsLearn to use Trivy to analyze container images and other software artifacts for a variety of issues