TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Wolfi – Linux (Un)distro a secure software supply chain

2 点作者 zeptonaut22超过 2 年前

1 comment

zeptonaut22超过 2 年前
I&#x27;m not affiliated with this company at all, but I&#x27;m curious what others think.<p>My understanding is that Chainguard offers Docker base images (Chainguard Images) that contain just what&#x27;s necessary to run the binary (commonly referred to as distroless images). This is in contrast to &quot;regular&quot; Docker images that contain an entire Linux distro baked into the image.<p>By reducing what&#x27;s included in the image, it becomes far easier to basically generate an SBOM (software bill of materials, i.e. list of all the software in the image) and &quot;prove&quot; that there are no known vulnerabilities in the stack. (I think this &quot;proving&quot; is what the Chainguard Enforce product does.)<p>- Is this overkill for startups, and something that companies will only consider if it&#x27;s required for something like SOC2? - Is this a role that a company should fill, or should these distroless images be more community driven?