IT Brief UK - Technology news for CIOs & IT decision-makers
United Kingdom
Chainguard tops 1 billion container build manifests

Chainguard tops 1 billion container build manifests

Mon, 14th Sep 2026 (Today)
Sofiah Nichole Salivio
SOFIAH NICHOLE SALIVIO News Editor

Chainguard has passed 1 billion unique container build manifests after doubling its total build volume in six months.

Its catalogue now includes more than 3,000 unique container images and more than 675,000 image variants across different architectures and platforms.

The figures point to rapid expansion in a part of the software supply chain that is under closer scrutiny as companies try to reduce exposure to vulnerabilities in open source components. Container images package applications and their dependencies, and are widely used in cloud and software development environments.

A build manifest is created whenever an image in the catalogue is built, updated, or patched. The total includes initial project builds, rebuilds triggered by dependency changes and vulnerabilities, software bills of materials, signatures, and customer-produced custom images.

Attack window

Chainguard linked the latest increase in build activity to shrinking timelines between the disclosure of a vulnerability and the creation of a working exploit. It argued that automated systems are becoming more important as attackers use artificial intelligence tools to identify weaknesses in source code and dependencies more quickly.

Matt Moore, co-founder and chief technology officer at Chainguard, said organisations now need both broad coverage and fast maintenance across the software they use.

"The gap between a disclosed vulnerability and a working exploit keeps shrinking, and closing that gap takes two things most vendors can't offer together. You need a catalogue broad enough to cover virtually every artifact an organisation relies on, and the underlying speed to keep every image in that catalogue up to date," Moore said.

"Reaching 1 billion build manifests and doubling our output in just six months signals both. The only way to stay ahead of attackers is to fix vulnerabilities before they can be exploited. That's what the Chainguard Factory is built to do, at a pace we're constantly accelerating," he added.

Factory system

Chainguard attributed the higher volume to what it calls Factory 2.0, a build system designed to rebuild and patch open source software as upstream dependencies change. The system uses automation and AI-based reconciliation tools to detect drift, resolve dependency conflicts, and correct build issues.

The catalogue added 1,000 new container images in the past six months, covering widely used runtimes, frameworks, and applications including Python, Go, NGINX, PostgreSQL, and Java.

Chainguard also reported more than 32,000 unique operating system packages in its own distribution, which it uses as building blocks for customer image customisation. Alongside the image count, the 675,000-plus variants are intended to cover different architectures, preserve historical versions, and make new upstream releases available more quickly.

It said it has eliminated more than 2 million CVEs across its customers by resolving vulnerabilities before affected images are released into production. CVE, short for Common Vulnerabilities and Exposures, is the standard identifier used to track publicly disclosed software security flaws.

The company's position reflects a wider shift in software security toward reducing the number of known vulnerabilities before deployment rather than relying mainly on patching after release. That approach has gained traction as development teams face pressure to ship software quickly while keeping up with a steady flow of updates in open source projects.

Customer response

One customer highlighted the operational burden vulnerability management can place on internal engineering teams.

"The depth of what Chainguard has built - and continues to improve - would take years and a very experienced team of experts to replicate," said Maha Alsayasneh, senior engineering manager at Elastic.

"Partnering with Chainguard has let our engineers spend their time on the problems only we can solve, instead of chasing CVEs across our stack," Alsayasneh said.