<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Vulnerability management on</title><link>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/chainguard/containers/security-and-compliance/vulnerability-management/</link><description>Recent content in Vulnerability management on</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><copyright>Copyright (c) 2023 Chainguard</copyright><lastBuildDate>Fri, 04 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/chainguard/containers/security-and-compliance/vulnerability-management/index.xml" rel="self" type="application/rss+xml"/><item><title>Strategies for minimizing your CVE risk</title><link>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/chainguard/containers/security-and-compliance/vulnerability-management/cve-risk/</link><pubDate>Thu, 16 Nov 2023 11:07:52 +0200</pubDate><guid>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/chainguard/containers/security-and-compliance/vulnerability-management/cve-risk/</guid><description>&lt;p&gt;&lt;a href="https://www.chainguard.dev/supply-chain-security-101/what-is-a-cve#what-is-a-cve"&gt;Common vulnerabilities and exposures&lt;/a&gt; (CVEs) are an increasing concern for developers and organizations, which is why Chainguard developed its minimal container images that reduce the attack surface. A new CVE in a widely-used application or a vulnerability scan with numerous positive results can significantly impact security posture, compliance requirements, and development timelines.&lt;/p&gt;
&lt;p&gt;Chances are, your software has already been impacted by a CVE. It&amp;rsquo;s likely there are active CVEs in software you are using. After all, there are software vulnerabilities currently in existence that haven&amp;rsquo;t even been discovered (known as zero-day vulnerabilities). With that said, this conceptual article aims to highlight a few practices and strategies you and your team can use to reduce the risk of CVEs on your software. It also includes a section on &lt;a href="https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/chainguard/containers/security-and-compliance/vulnerability-management/cve-risk/#recommended-tools"&gt;tools recommended by Chainguard&lt;/a&gt; that can help to reduce your attack surface area and minimize your risk of CVEs.&lt;/p&gt;</description></item><item><title>Check whether a reported CVE affects your container</title><link>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/chainguard/containers/security-and-compliance/vulnerability-management/cve-status/</link><pubDate>Thu, 10 Sep 2026 00:00:00 +0000</pubDate><guid>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/chainguard/containers/security-and-compliance/vulnerability-management/cve-status/</guid><description>&lt;p&gt;Use &lt;code&gt;chainctl images advisories list&lt;/code&gt; to compare the advisories for the APK packages in an image with the CVEs reported by your scanner.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; This command looks up advisories by APK package. Chainguard records a vulnerability in a Go module, Java archive, or other language component against the APK package that ships it, so the results cover those components too. They don&amp;rsquo;t cover dependencies that your own build adds to the image. For details, see &lt;a href="https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/chainguard/containers/security-and-compliance/vulnerability-management/cve-status/#when-the-finding-is-a-go-module-or-java-dependency"&gt;When the finding is a Go module or Java dependency&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Resolve a scanner finding for a CVE Chainguard has fixed</title><link>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/chainguard/containers/security-and-compliance/vulnerability-management/scanner-flags-fixed-cve/</link><pubDate>Thu, 01 Oct 2026 14:31:17 +0000</pubDate><guid>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/chainguard/containers/security-and-compliance/vulnerability-management/scanner-flags-fixed-cve/</guid><description>&lt;p&gt;Sometimes the Chainguard Console or a Chainguard security advisory reports a CVE as fixed, but your vulnerability scanner still reports it in the same image. When this blocks a CI security gate, the cause is usually a mismatch between the image you scanned, the data your scanner uses, and Chainguard&amp;rsquo;s advisory data. Work through the checks on this page in order; they&amp;rsquo;re arranged so that the most common causes come first.&lt;/p&gt;</description></item><item><title>Using CVE visualizations</title><link>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/chainguard/containers/security-and-compliance/vulnerability-management/cve-visualizations/</link><pubDate>Thu, 19 Dec 2024 11:07:52 +0200</pubDate><guid>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/chainguard/containers/security-and-compliance/vulnerability-management/cve-visualizations/</guid><description>&lt;p&gt;Chainguard provides CVE Visualizations for all of its container images. This feature creates reports with CVE comparisons between Chainguard Containers and popular alternatives, as well as historical CVE remediation metrics. CVE Visualizations provide insight into image health and can help teams measure the engineering, security, and economic benefits gained from using Chainguard Containers.&lt;/p&gt;
&lt;p&gt;This guide outlines how you can access a container image&amp;rsquo;s CVE Visualization in both the Chainguard Console and in the Containers Directory.&lt;/p&gt;</description></item></channel></rss>