Build on Chainguard Registry Images in Cloudsmith

Jun 24 2024

We are happy to announce that Cloudsmith now supports the Chainguard Registry as an upstream source for container images. 🎉

Chainguard, a Docker Verified Publisher, offers Chainguard Images, which are minimal, hardened container images with impressive features:

  • (Mostly) zero CVEs 💜
  • Includes SBOMs and signatures ✏️
  • Many images are distroless, containing only the application and its runtime dependencies.

Integrating the Chainguard Registry as an upstream in your Cloudsmith account enhances security 🛡️ and boosts efficiency in your artifact management workflow. We do this by proxying and caching Chainguard images in your Cloudsmith repos.

Key benefits:

  • Reduce attack risk with no/low vulnerability base images provided by Chainguard.
  • Effortlessly deploy and distribute your packages and third-party dependencies using Cloudsmith's global content delivery network for optimal performance. 🚄
  • Ensure compliance and security by establishing and enforcing rules on dependencies with Cloudsmith’s policy manager.
  • Safeguard 🦸 your workflows from disruptions caused by the removal of dependencies or outages in public repositories.

Our blog post goes deeper into the benefits and the steps to set up the Chainguard Registry as an upstream in your Cloudsmith account.

Ready to get started? Chainguard Registry upstreams are currently in Early Access. Please reach out to us today to gain access.

Happy packaging! 🎈

Keep up to date with our monthly product bulletin

By submitting this form, you agree to our privacy policy