惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - Franky
T
Tailwind CSS Blog
Microsoft Azure Blog
Microsoft Azure Blog
The Cloudflare Blog
博客园 - 叶小钗
N
Netflix TechBlog - Medium
罗磊的独立博客
量子位
MyScale Blog
MyScale Blog
A
About on SuperTechFans
Blog — PlanetScale
Blog — PlanetScale
V
Visual Studio Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
GbyAI
GbyAI
B
Blog
腾讯CDC
爱范儿
爱范儿
Recent Announcements
Recent Announcements
有赞技术团队
有赞技术团队
F
Fortinet All Blogs
雷峰网
雷峰网
G
Google Developers Blog
Google DeepMind News
Google DeepMind News

Ubuntu blog

Beyond the 10-year mark: Extending Ubuntu Pro 16.04 LTS security coverage | Ubuntu Android™ development shouldn’t start with a physical device | Ubuntu Bring Zenoh to ROS 2 with snaps | Ubuntu Evolution of the RISC-V ISA. What next after RVA23? | Ubuntu Ubuntu now certified on Qualcomm Dragonwing™ IQ-8275 | Ubuntu Grace on the currents: Stonking Stingray | Ubuntu How we create a Canonical Academy exam | Ubuntu Surviving the uncharted: when dedicated OpenStack expertise is your best ally in disaster recovery  | Ubuntu Canonical joins the Open Secure AI Alliance | Ubuntu AI harnesses for telco autonomous networks | Ubuntu Arduino® VENTUNO™ Q is available for pre-order with Ubuntu pre-installed | Ubuntu Advantech AOM-2721 is now Ubuntu Certified | Ubuntu Canonical integrates NVIDIA Nemotron 3.5 Lightning with Ubuntu for always-on AI agents | Ubuntu Ubuntu’s virtualization hardware enablement (HWE) stack: a new model for confidential computing enablement | Ubuntu Confidential computing and the new regulatory focus on data in use | Ubuntu A day in the life of an Android developer with Anbox Cloud | Ubuntu Canonical announces the Enterprise Store as part of Ubuntu Pro | Ubuntu Tracing a memory leak bug in PID 1 and contributing an upstream fix: a Linux support story | Ubuntu MAAS installation: bare metal provisioning is easier than ever | Ubuntu Januscape vulnerability CVE-2026-53359 mitigations available | Ubuntu Managing Ubuntu on bare metal at scale | Ubuntu Ubuntu Server: a platform made for enterprise scale | Ubuntu Building an open source chain of trust: new research uncovers key blockers and ways forward | Ubuntu Beyond safety and security: Why automotive open source demands dependability  | Ubuntu DirtyClone Linux kernel local privilege escalation vulnerability fixes available | Ubuntu pedit COW kernel local privilege escalation vulnerability mitigations | Ubuntu Canonical becomes Gold Sponsor of Trifecta Tech Foundation | Ubuntu Challenges designers face in open source (and how to fix them) | Ubuntu Hunting a 16-year-old SQLite bug with TLA+: is dqlite affected? | Ubuntu Anbox Cloud on C4A metal: Android, at scale, without friction | Ubuntu
Cut bloat, not features | Ubuntu
Lily Rivers-Klee · 2026-09-11 · via Ubuntu blog

Accelerating software delivery with minimal OCI images

For Independent Software Vendors (ISVs), delivering containerized applications to enterprise clients often means navigating a difficult trade-off between minimal image size and accurate security visibility. Traditional approaches can leave development teams battling severe CVE noise or, conversely, missing critical vulnerabilities entirely due to scanner blind spots. What’s more, off-the-shelf images require clients to fit their needs into what’s available, rather than being able to build and use container images that meet their exact specifications.

To help ISVs overcome this compromise, Canonical is hosting a technical webinar on September 23, 2026. In the session, you’ll learn how to deliver lightweight, secure, and scannable container images without the operational overhead.

Addressing the distroless security gap

Typical distroless images use a “top-down” approach, inflating a base image and then cherry-picking to trim it down. Unfortunately, this often strips out essential package metadata, causing security scanners to miss critical vulnerabilities and report false negatives. 

In this webinar, you’ll learn how rocks, Canonical’s OCI-compliant, minimal container images, solve this by using a “bottom-up” approach. Powered by Chisel, our novel package manager, rocks are built by slicing packages directly from the Ubuntu archives, staying ultra-small while retaining the exact metadata required for highly accurate CVE scanning. 

Live demo: building a rock with Rockcraft

Creating a minimal, secure, and maintainable container shouldn’t be a hurdle. Our engineers will provide a hands-on demonstration of building a rock using Chisel and Rockcraft. You will see how to:

  • Move away from ungoverned, imperative Dockerfiles that cause inconsistencies.
  • Use Rockcraft’s declarative YAML format for a standardized, reproducible developer experience.
  • Build and pack OCI-compliant images effortlessly.

Enterprise-ready commitments

Enterprises trust their operating systems for their most critical systems. With rocks, ISVs can draw upon the trusted Ubuntu ecosystem, but for their container dependencies. We will cover the enterprise commitments behind rocks, including:

  • Non-root default execution to enforce the principle of least privilege and contain blast radiuses.
  • Hardened designs built from trusted, heavily audited Ubuntu sources.
  • Timely CVE fixes, backporting, and up to 15 years of Long-Term Support (LTS) through Ubuntu Pro.

Empowered by security scanner partnerships

Because rocks solve the distroless visibility problem, the wider cybersecurity industry is taking notice. We will highlight how major security vendors are partnering with Canonical through the Ubuntu Security Research Alliance Program. You will learn how industry-leading tools, including Snyk and Google’s OSV-Scanner, now provide native support for scanning chiseled Ubuntu images, allowing you to confidently deliver precise, noise-free vulnerability data to your customers.

Stop letting container bloat and scanning inaccuracies slow down your enterprise software deployments.

Register now on BrightTALK to reserve your spot