Home / Companies / Flagsmith / Blog / Post Details
Content Deep Dive

How We Improved Our Docker Image Security Using Chainguard's Wolfi

Blog post from Flagsmith

Post Details
Company
Date Published
Author
Kim Gustyr
Word Count
926
Company Posts That Month
38
Language
English
Hacker News Points
-
Post removed?
No
Summary

Flagsmith, an open-source tool managed as a SaaS for enterprises, faced a challenge with vulnerabilities in their Docker image during an on-premise deployment for a client with stringent security standards. Initial analysis with the Clair tool revealed numerous vulnerabilities from outdated binary packages in the base layer, prompting a need for a more secure foundation. While considering alternatives, including Alpine Linux and changing the build toolchain, Flagsmith found a solution in Chainguard's Wolfi, which uses the familiar glibc C backend and offers necessary binary dependencies. Opting to pin the base layer version to the latest to ensure up-to-date binaries, they successfully tested and deployed the new Docker image, integrating Trivy security scanning and Docker Scout reporting for ongoing security monitoring. Future adjustments to their Docker build process will depend on evolving customer demands and potentially include moving to alternative build systems like Chainguard if required by enterprise security practices.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.