Resolve a scanner finding for a CVE Chainguard has fixed
What to check when the Chainguard Console or a security advisory says a CVE is fixed, but your vulnerability scanner …
For the complete documentation index, see llms.txt.
Note: Chainguard OS Packages is in beta. Contact your Chainguard account team to enable it for your organization.
Chainguard OS Packages expands the packages available to your private APK repository by giving you access to the full set of 30,000 enterprise-grade, zero-CVE packages built as part of Chainguard OS and Wolfi. It also includes a small set of Chainguard base images, for example, chainguard-base.
Chainguard OS Packages is designed for larger customers who already build their own images from packages using tools like Bazel, Dockerfiles, and rules_apko, and want to use a wider set of packages from Chainguard. Because you are creating custom builds, you are responsible for the image builds, the build tooling, validation, and compatibility. You still benefit from the fact that Chainguard builds the packages in the Chainguard Factory with complete SBOMs and our standard enterprise-grade, zero-CVE process.
If you need to achieve FIPS compliance, the FIPS variant of Chainguard OS Packages includes access packages with the latest versions of Chainguard’s FIPS-validated modules.
Chainguard OS Packages is not compatible with Chainguard Custom Assembly.
What to check when the Chainguard Console or a security advisory says a CVE is fixed, but your vulnerability scanner …
How to use the Chainguard Terraform provider to create overlays and bind them to specific tags of a Custom Assembly …
How to use chainctl to create overlays and bind them to specific tags of a Custom Assembly repository.
Upload an agent skill for hardening, track the job, browse results in user folders, and review the report before …
Tutorial for setting up Sonatype Nexus raw repositories as pull-through caches for apk packages from Chainguard's …
Last updated: 2026-09-28 14:00