Silent Rebuilds: Keeping Container CVE Counts Near-Zero

chainguard docker github Dec 08, 2025

Starting with a slim/distroless container image is necessary today, but it isn't enough. You need daily automation to trigger rebuilds for dependencies and base image digest updates.


I used to think of it this way, but I don’t anymore. I think it’s a false choice. We can have both, and I see it as a path. I start at full control and safety, and automate my way to fast. The moment something goes wrong because I went too fast (likely due to not enough testing, linting, or automated “checks”), I slow down, improve my automation, and keep pushing faster.

Bret's container, AI, and DevOps learnings, in your inbox!

Join my newsletter for weekly-ish updates on content I'm creating: videos, articles, events, courses and more.