How We Improved Our Docker Image Security Using Chainguard's Wolfi
Blog post from Flagsmith
Flagsmith, an open-source tool managed as a SaaS for enterprises, faced a challenge with vulnerabilities in their Docker image during an on-premise deployment for a client with stringent security standards. Initial analysis with the Clair tool revealed numerous vulnerabilities from outdated binary packages in the base layer, prompting a need for a more secure foundation. While considering alternatives, including Alpine Linux and changing the build toolchain, Flagsmith found a solution in Chainguard's Wolfi, which uses the familiar glibc C backend and offers necessary binary dependencies. Opting to pin the base layer version to the latest to ensure up-to-date binaries, they successfully tested and deployed the new Docker image, integrating Trivy security scanning and Docker Scout reporting for ongoing security monitoring. Future adjustments to their Docker build process will depend on evolving customer demands and potentially include moving to alternative build systems like Chainguard if required by enterprise security practices.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.