Container Virtual Registry
Secure open source container infrastructure with GitLab and Chainguard

Secure open source container infrastructure with GitLab and Chainguard

9/9/2024 · Fernando Diaz

What this post added

This post details the integration of Chainguard's hardened container images with GitLab, enabling users to leverage minimal, secure base images directly within GitLab CI jobs or Dockerfiles. It also covers container image signing using Sigstore/Cosign for authenticity, trust, and integrity, and outlines GitLab's comprehensive suite of vulnerability scanning tools (SAST, DAST, IaC, Container Scanning, Dependency Scanning, Secret Detection, API Fuzzing, Coverage-guided Fuzzing) to maintain security posture as dependencies are added to hardened images.

Read the original post ↗