Canonical has partnered with Snyk to bring native scanning support for chiseled Ubuntu containers to Snyk Container. Chiseled Ubuntu images are minimal, distroless containers built bottom-up using the Chisel package manager, retaining package metadata needed for accurate CVE scanning. Unlike typical distroless images that often omit metadata and cause false negatives, chiseled Ubuntu images allow Snyk to correctly identify slices and report vulnerabilities accurately. The integration requires no extra configuration, works with existing Snyk commands, and results in reduced vulnerability noise and faster CI/CD pipelines.

4m read timeFrom ubuntu.com
Post cover image
Table of contents
Distro-aware, without the distroBridging the distroless security gapGet production-ready, securely-maintained container imagesLearn more
494 Impressions