Home / Companies / Elastic / Blog / Post Details
Content Deep Dive

Reducing CVEs in Elastic container images

Blog post from Elastic

Post Details
Company
Date Published
Author
-
Word Count
1,409
Company Posts That Month
21
Language
-
Hacker News Points
-
Post removed?
No
Summary

Elastic has embarked on a mission to reduce Common Vulnerabilities and Exposures (CVEs) in their container images by leveraging minimal base images from the Chainguard project, which emphasizes a secure software supply chain. This initiative, beginning with Elastic Stack version 8.16, has led to a significant reduction in vulnerabilities, as seen with the recent release of Elasticsearch 8.16 and the ongoing development of version 8.17. The effort is supported by a comprehensive vulnerability management strategy that includes predefined service level objectives, continuous monitoring, and the use of tools like Renovate to automate updates. Additionally, Elastic employs best practices such as using Docker multistage builds and distroless images to minimize the attack surface of their containers. The project is underpinned by the use of Chainguard images, which are synchronized with the Elastic container registry, ensuring secure and efficient deployment for both developers and production environments.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Kubernetes 4 1,736 172 73 +13%
Developer Experience 2 292 156 81 +38%
Serverless 1 778 155 73 +74%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.