Canonical has partnered with Snyk to bring native scanning support for chiseled Ubuntu containers to Snyk Container. Chiseled Ubuntu images are minimal, distroless containers built bottom-up using the Chisel package manager, retaining package metadata needed for accurate CVE scanning. Unlike typical distroless images that often omit metadata and cause false negatives, chiseled Ubuntu images allow Snyk to correctly identify slices and report vulnerabilities accurately. The integration requires no extra configuration, works with existing Snyk commands, and results in reduced vulnerability noise and faster CI/CD pipelines.
Table of contents
Distro-aware, without the distroBridging the distroless security gapGet production-ready, securely-maintained container imagesLearn more494 Impressions