
9/9/2024 · Fernando Diaz
What this post added
This post details the integration of Chainguard's hardened container images with GitLab, enabling users to leverage minimal, secure base images directly within GitLab CI jobs or Dockerfiles. It also covers container image signing using Sigstore/Cosign for authenticity, trust, and integrity, and outlines GitLab's comprehensive suite of vulnerability scanning tools (SAST, DAST, IaC, Container Scanning, Dependency Scanning, Secret Detection, API Fuzzing, Coverage-guided Fuzzing) to maintain security posture as dependencies are added to hardened images.