Chainguard has surpassed 1 billion container construct manifests, doubling manufacturing from 500 million in six months because it expands its AI-assisted software program supply-chain safety platform.
The corporate now maintains greater than 3,000 distinctive container photographs and 675,000 picture variations. The milestone displays greater than uncooked construct quantity.
Every construct manifest represents a newly generated, verifiable container artifact, together with recent utility photographs, rebuilt packages following a libc patch, architecture-specific variants, or regenerated software program payments of supplies (SBOMs) after a dependency replace.
For tasks with a number of supported variations and architectures, equivalent to Python or Go, these rebuilds can multiply quickly. Each upstream launch, dependency repair, hardening enchancment, or safety advisory can set off new builds.
Chainguard Hits 1 Billion Construct Manifests
Chainguard mentioned the strategy is meant to make sure container photographs stay safe past the second they’re initially pulled by prospects. On the basis of the platform is Chainguard OS, a Linux distribution designed for cloud-native workloads and steady supply.
Slightly than counting on conventional long-lived distribution releases, Chainguard OS makes use of a rolling-release mannequin that allows up to date artifacts to be shipped all through the day.

Chainguard Manufacturing facility builds the corporate’s container artifacts from supply and attaches safety metadata, together with SLSA Degree 3 provenance, Sigstore signatures, and full SBOMs.
The manufacturing unit is designed to generate reproducible builds, lowering the danger of configuration drift or inconsistencies between the meant artifact and the picture finally delivered to customers.
Nevertheless, reproducibility alone couldn’t assist rebuilds at billion-manifest scale. The corporate wanted a system able to figuring out when hundreds of dependent parts required remediation and initiating builds with out counting on guide intervention.
Chainguard addressed that problem with Manufacturing facility 2.0, powered by its open-source DriftlessAF framework. The system replaces a largely event-driven mannequin with a self-correcting reconciliation course of.
Below the earlier structure, particular person occasions might generate cascading work objects, duplicate construct failures, brittle queues, and operational overhead for web site reliability engineers.
Partial failures typically required guide remediation, slowing down the response to CVEs and different package deal adjustments. Manufacturing facility 2.0 as a substitute repeatedly compares the meant software program state with the catalog’s precise state.
When a brand new vulnerability, upstream package deal launch, dependency replace, or safety requirement seems, reconciler bots establish the distinction and work towards restoring the specified state.

The system makes use of a shared work queue and redundant duties, which means failed jobs may be retried or discarded with out stopping the general platform from converging on the meant safe final result.
AI is used for duties that conventional deterministic automation struggles to deal with, together with evaluating newly launched parts, assessing package deal adjustments, and backporting vulnerability fixes to older software program variations.
Chainguard mentioned the brokers nonetheless function by structured and verifiable tooling to cut back the danger of unsafe AI-generated adjustments. The corporate argues that rebuild velocity is now central to supply-chain protection.
Attackers can more and more use AI to map dependency graphs, establish weaknesses, and speed up the event of exploits. Defenders due to this fact want to cut back the time between an upstream safety change and a newly rebuilt, signed, and verified container picture.
By increasing DriftlessAF and shifting extra of its catalog into self-healing reconciliation loops, Chainguard goals to automate safety upkeep at a scale that conventional event-driven construct techniques wrestle to realize.
Maintain your SOC updated on energetic malware & phishing inside 24h of their emergence. Attempt ANYRUN to stop incidents with early detection.








