Quickstart for Chainguard Containers
An end-to-end walkthrough of Chainguard Containers: pull a free container, run a small Node.js application on it, and …
For the complete documentation index, see llms.txt.
This page logs Chainguard product updates week by week, newest first: product announcements, breaking changes, container images that reached end-of-life or are no longer available, and images newly added to the catalog. Each event is listed once, in the week it first appeared.
Launched August 13, 2026.
When Chainguard Libraries withholds an npm package or version — because of detected malware or greyware, a pending malware scan, or a policy block such as a cooldown — npm now returns a 403 naming the specific reason, for example MALWARE_DETECTED, instead of the unexplained 404 it returned before. The other supported package managers (pnpm, yarn, uv, poetry, Maven, and Gradle) still report a blocked version as a generic not-found error, and a 409 when an entire package is blocked for malware.
For more information, refer to Error messages.
Launched August 12, 2026.
Chainguard Guardener, the automated migration tool, now covers GitHub Actions as well as container images. The GitHub App inventories the Actions in use across your organization’s repositories, maps them to hardened Chainguard equivalents, and opens pull requests to swap them in, pinned to a specific SHA rather than a mutable tag. It runs in two modes: an upfront pass that surfaces existing Actions usage and opens migration pull requests, and ongoing standardization that watches workflow files and suggests Chainguard equivalents as new upstream Actions appear.
For more information, refer to Getting started with Chainguard Guardener.
Breaking ChangesEffective August 24, 2026.
Chainguard Repository can serve two copies of the same package version: the upstream copy mirrored from the public registry, and Chainguard’s copy rebuilt from source. The two have different checksums, and each request resolves independently, so when Chainguard publishes a rebuild of a version your organization already pulled, the next resolution moves you to the rebuild and its checksum no longer matches your lockfile — surfacing client-side as errors such as EINTEGRITY in npm. As of August 24, 2026, build pinning records which copy your organization received the first time it downloads a package version and keeps resolving that version to the same copy until you choose to move forward. Malware and policy blocks apply independently: a version that is later blocked stops being served rather than being replaced with a different copy.
chainctl libraries cache opt-out. Both opt-out and chainctl libraries cache opt-in accept --ecosystem, and pinning state is tracked per organization and ecosystem. To see which copy each held version came from, run chainctl libraries cache list.For more information, refer to chainctl libraries cache.
Chainguard offers a grace period for eligible end-of-life images: up to six months of continued rebuilds and security updates while you complete your upgrade.
The following container images reached the end of their grace period and are no longer available:
| Image | End-of-life | Grace period ended |
|---|---|---|
prometheus:3.9 | 2026-02-17 | 2026-08-17 |
The following container images reached end-of-life and entered their grace period:
| Image | End-of-life | Grace period ends |
|---|---|---|
mattermost:10.11 | 2026-08-15 | 2027-02-15 |
Chainguard built 17 new container images this week, including both standard and FIPS variants.
| Image | Tier | Added |
|---|---|---|
azurite | application | 2026-08-10 |
k0s-cni-node | application +fips | 2026-08-10 |
peerdb-ui | application +fips | 2026-08-10 |
scc | application +fips | 2026-08-10 |
zitadel-login | application | 2026-08-11 |
aws-lambda-nodejs | application +fips | 2026-08-12 |
localstack | application | 2026-08-12 |
kserve-router-fips | fips | 2026-08-13 |
jdk-openssl-fips | fips | 2026-08-14 |
jre-openssl-fips | fips | 2026-08-14 |
kube-router | application +fips | 2026-08-14 |
commercial-nginx-ingress-plus | commercial | 2026-08-17 |
Launched August 4, 2026.
AWS added a Supply Chain category to Security Hub Extended and named Chainguard one of its inaugural partners. You can now subscribe to Chainguard Libraries from the Security Hub console and pay through your existing AWS account. Libraries findings arrive normalized to the Open Cybersecurity Schema Framework (OCSF), so they appear alongside your AWS and other partner findings, and AWS Enterprise Support customers receive Level 1 support from AWS.
For more information about the catalog, refer to the Chainguard Libraries overview.
Launched August 4, 2026.
The Console now shows which malicious and suspicious packages Chainguard Libraries blocked before they reached your environment. A weekly chart tracks the malware and greyware stopped across the Python and JavaScript ecosystems, and a search tool reports why any given package was flagged unsafe. Find it under the Malware tab in the Libraries section of the Console sidebar; it is enabled by default for every organization entitled to Libraries.
For more information, refer to View malware information.
Launched August 3, 2026.
Chainguard now supports Proof Key for Code Exchange (PKCE) on the OAuth token exchange with custom OIDC identity providers, in line with OAuth 2.1. Administrators can enable it with chainctl or the Chainguard API, either alongside an existing client secret or as a secret-free public client.
For more information, including setup steps, refer to Enable PKCE for OAuth Token Exchange.
EOLChainguard offers a grace period for eligible end-of-life images: up to six months of continued rebuilds and security updates while you complete your upgrade.
The following container images reached end-of-life and entered their grace period:
| Image | End-of-life | Grace period ends |
|---|---|---|
net-kourier:1.21 | 2026-08-04 | 2027-02-04 |
tekton-pipelines:1.3 | 2026-08-04 | 2027-02-04 |
ruby3.2-rails:7.2 | 2026-08-09 | 2027-02-09 |
ruby3.3-rails:7.2 | 2026-08-09 | 2027-02-09 |
ruby3.4-rails:7.2 | 2026-08-09 | 2027-02-09 |
ruby4.0-rails:7.2 | 2026-08-09 | 2027-02-09 |
Chainguard built 23 new container images this week, including both standard and FIPS variants.
| Image | Tier | Added |
|---|---|---|
prometheus-stackdriver-exporter | application +fips | 2026-08-03 |
crossplane-azure-keyvault | application | 2026-08-04 |
crossplane-azure-kusto | application | 2026-08-04 |
influxdb-fips | fips | 2026-08-04 |
moodle-iamguarded | application | 2026-08-04 |
pypiserver-fips | fips | 2026-08-04 |
kubevirt-cdi-cloner | application +fips | 2026-08-05 |
yopass | application | 2026-08-05 |
acm-controller | application +fips | 2026-08-06 |
gremlin-server | application | 2026-08-06 |
rollouts-plugin-trafficrouter-gatewayapi | application +fips | 2026-08-06 |
claude | application | 2026-08-07 |
codex | application | 2026-08-07 |
cruise-control | application +fips | 2026-08-07 |
dotstatsuite-supercore | application | 2026-08-07 |
opencode | application | 2026-08-08 |
zalando-pgbouncer | application +fips | 2026-08-10 |
Effective July 15, 2026.
Chainguard aligned the entrypoint and command behavior of all supported ingress-nginx-controller images with the upstream image, correcting a startup configuration defect present since the image was first published in 2024. Non-iamguarded variants also changed their default runtime user from root (UID 0) to www-data (UID 101).
ingress-nginx-controller images, including FIPS and -iamguarded variants.command, args, entrypoint, or runAsUser, or that depends on admission policies or file ownership assumptions. Deployments using the upstream Helm chart defaults need no changes.Chainguard offers a grace period for eligible end-of-life images: up to six months of continued rebuilds and security updates while you complete your upgrade.
The following container images reached the end of their grace period and are no longer available:
| Image | End-of-life | Grace period ended |
|---|---|---|
cilium:1.16 | 2026-02-03 | 2026-08-03 |
neo4j:2025.12 | 2026-02-03 | 2026-08-03 |
The following container images reached end-of-life and entered their grace period:
| Image | End-of-life | Grace period ends |
|---|---|---|
eks-distro:1.33 | 2026-07-29 | 2027-07-29 |
mongo:8.2 | 2026-07-31 | 2027-01-31 |
prometheus:3.5 | 2026-07-31 | 2027-01-31 |
cockroach:26.1 | 2026-08-02 | 2027-02-02 |
cockroach-openssl:26.1 | 2026-08-02 | 2027-02-02 |
Chainguard built 18 new container images this week, including both standard and FIPS variants.
| Image | Tier | Added |
|---|---|---|
atlas | application +fips | 2026-07-29 |
azure-metrics-exporter | application +fips | 2026-07-29 |
crossplane-azure-solutions | application | 2026-07-29 |
crossplane-azure-streamanalytics | application | 2026-07-29 |
crossplane-azure-web | application | 2026-07-29 |
dns-controller-manager | application +fips | 2026-07-29 |
instrumentisto-haraka | application +fips | 2026-07-29 |
openstack-kolla-toolbox | application +fips | 2026-07-29 |
sftpgo | application | 2026-07-29 |
flink-kubernetes-operator-fips | fips | 2026-07-30 |
traccar | application +fips | 2026-07-30 |
metacontroller-fips | fips | 2026-07-31 |
Launched July 24, 2026.
SUSE’s NeuVector vulnerability scanner now natively supports Chainguard Containers and ingests Chainguard’s OSV advisory feed, which includes recent data-quality improvements. Scans of Chainguard images suppress false positives and report more accurate results.
Launched July 22, 2026.
Administrators can map identity provider groups — Okta or Microsoft Entra ID, for example — directly to Chainguard roles, instead of assigning roles one user at a time. Anyone who authenticates with a mapped group in their token receives that role for the session.
For more information, including setup steps, refer to Grant Chainguard roles from identity provider groups.
EOLChainguard offers a grace period for eligible end-of-life images: up to six months of continued rebuilds and security updates while you complete your upgrade.
The following container images reached the end of their grace period and are no longer available:
| Image | End-of-life | Grace period ended |
|---|---|---|
knative-eventing:1.19 | 2026-01-28 | 2026-07-28 |
knative-serving:1.19 | 2026-01-28 | 2026-07-28 |
net-kourier:1.19 | 2026-01-28 | 2026-07-28 |
The following container images reached end-of-life and entered their grace period:
| Image | End-of-life | Grace period ends |
|---|---|---|
dnsdist:1.9 | 2026-07-21 | 2027-01-21 |
longhorn-backing-image-manager:1.8 | 2026-07-22 | 2027-01-22 |
longhorn-instance-manager:1.8 | 2026-07-22 | 2027-01-22 |
envoy:1.35 | 2026-07-23 | 2027-01-23 |
Chainguard built 15 new container images this week, including both standard and FIPS variants.
| Image | Tier | Added |
|---|---|---|
coder | application +fips | 2026-07-22 |
flink-kubernetes-operator | application | 2026-07-22 |
pghero | application +fips | 2026-07-22 |
kargo | application | 2026-07-23 |
nuclio-controller | application +fips | 2026-07-23 |
phpmyadmin | application +fips | 2026-07-23 |
apache-exporter-iamguarded | application | 2026-07-24 |
glab | application +fips | 2026-07-27 |
metabase | application | 2026-07-27 |
crossplane-azure-relay | application | 2026-07-28 |
Last updated: 2026-08-17 00:00