#Distroless
Highly regulated industry? Your software supply chain security needs an upgrade. Learn about Distroless images, STIG Readiness, and SLSA Level 3 compliance in our new blog! #SupplyChainSecurity #DevSecOps #Cybersecurity https://brcm.tech/3MwCiNb
What Good Software Supply Chain Security Looks Like for Highly Regulated Industries
Organizations running their business on open source software are faced with a more aggressive and complicated security and compliance landscape than ever before. According to Sonatype’s 10th Annual St...
brcm.tech
February 17, 2026 at 6:13 PM
What's inside:

- Why `docker pull` is an act of faith
- Falco: runtime threat detection with eBPF
- Distroless vs Alpine: 150 CVEs/year vs 5
- cosign + Sigstore: keyless image signing
- Kyverno verify-images: the enforcement layer

That's 5 tools in one issue.
February 17, 2026 at 1:59 PM
I spoke with @charleshumble.bsky.social a few weeks back for @gotocon.com

We dived into a wide range of security and container topics, from why containers came about and how vulnerability scanners work, to SBOMs and the evolution of Distroless into @chainguard.dev images

youtu.be/9NUOiL48hbo?...
State of the Art of Container Security • Adrian Mouat & Charles Humble • GOTO 2026
This interview was recorded for GOTO State of the Art in November 2025. #GOTOcon #GOTO https://gotopia.tech Read the full transcription of this interview…
www.youtube.com
February 16, 2026 at 3:21 PM
@charleshumble.bsky.social & @adrianmouat.com discuss container security: why distroless images matter, how Chainguard builds from source for zero CVEs, and lessons from XZ Utils & Shackle-Alert attacks.
State of the Art of Container Security • Adrian Mouat & Charles Humble • GOTO 2026
This interview was recorded for GOTO State of the Art in November 2025. #GOTOcon #GOTO https://gotopia.tech Read the full transcription of this interview…
youtu.be
February 16, 2026 at 1:01 PM
Haproxy kakuttamaan ja jakamaan staattista kamaa S3:sta. Minusta paljon kivempi ratkaisu kuin epämääräinen pod jakamassa staattista kamaa epämääräisellä web-palvelimella. Tarviikin tehdä Haproxyn kontista distroless.

#nörttijuttuja #tietoturva
February 10, 2026 at 4:28 AM
Estou ensinando no vídeo, como criar uma imagem de container normal, outra com o Wolfi da Chainguard e, por fim, a Distroless do Google.

Bora lá assistir e entender qual a diferença entre elas! #VAIIII

Posso contar com o seu compartilhamento?

youtu.be/CHIQjLSfjoM
COMO TRANSFORMAR IMAGENS DOCKER EM IMAGENS COM ZERO VULNERABILIDADES E MENORES!
YouTube video by LINUXtips
youtu.be
February 9, 2026 at 7:08 PM
Good news. I figured out what I was missing. A distroless Unbound container built from source with #buildroot. The uncompressed image size is ~25MB.
February 5, 2026 at 8:38 AM
Reduce workload attack surface with distroless image [karnwong.me]

https://link.webring.in.th/2946
February 4, 2026 at 4:25 AM
Use cases:

- Check DNS from inside the pod
- Inspect files in a distroless image
- tcpdump traffic without rebuilding
- Test connectivity to other services
- strace a running process (with --share-processes)

Works on K8s 1.25+. Built-in. Free.
February 2, 2026 at 2:48 PM
Your pod runs distroless.

No shell. No curl. No tcpdump. Nothing.

How do you debug it? 🧵
February 2, 2026 at 2:48 PM
Build faster, safer Python apps with the "Python Minimal" container image by Bitnami.

Distroless-style containers with near-zero CVEs, smaller footprint, faster startup, and built-in compliance (FIPS, STIG, SBOMs).

See how to use it with Django 👇
community.broadcom.com/tanzu/blogs/...
Secure your Python deployments using Bitnami Secure Images minimal image
community.broadcom.com
January 29, 2026 at 4:19 PM
Hackaday - Article -
"The Distroless Linux Future May Be Coming"...

hackaday.com/2026/01/12/t...

==========================
#librecanada #linux #opensource
The Distroless Linux Future May Be Coming
Over the decades the number of Linux distributions has effectively exploded, from a handful in the late ’90s to quite literally hundreds today, not counting minor variations. There lately see…
hackaday.com
January 18, 2026 at 12:34 AM
[some-subscribed-rss] New Post: I wasn’t really sure what hardned images were, let alone “distroless,” so Tony and I were lucky to get William on this week’s Tanzu Catsup to sort it out. We also discuss how it fits into platform engineering., by Coté https://cote.io/2026/01/14/103819.html
January 14, 2026 at 10:12 AM
New scenario released! 🚀

Reload the configuration of a containerized app without restarting the Docker container.

Sounds easy? Not so much when the container uses a distroless image.

www.learnbyfixing.com/scenarios/16/

Happy fixing!

#LearnByFixing #DevOps #SRE #Sysadmin #Docker
January 14, 2026 at 10:08 AM
Après "l'âge d'or" et les "âges sombres", la "renaissance" du bureau Linux https://kylerank.in/blog/linux-desktop-renaissance.html Commentaires : voir le flux At...

#flatpak #immutable #proton #steamos #docker #distroless #homebrew

Origin | Interest | Match
Lien Après "l'âge d'or" et les "âges sombres", la "renaissance" du bureau Linux
* https://kylerank.in/blog/linux-desktop-renaissance.html
linuxfr.org
January 14, 2026 at 7:41 PM
The Distroless Linux Future May Be Coming

Over the decades the number of Linux distributions has effectively exploded, from a handful in the late ’90s to quite literally hundreds today, not counting minor variations. There lately seems to be a counter-movement brewing in response to this…
The Distroless Linux Future May Be Coming
Over the decades the number of Linux distributions has effectively exploded, from a handful in the late ’90s to quite literally hundreds today, not counting minor variations. There lately seems to be a counter-movement brewing in response to this fragmentation, with Project Bluefin’s Distroless project being the latest addition here. Also notable are KDE’s efforts, with KDE Linux as its own top-down KDE-based distro, but now with a switch to BuildStream from Arch likely as a distroless move.
nexttech-news.com
January 12, 2026 at 10:44 PM
The Distroless Linux Future May Be Coming

Over the decades the number of Linux distributions has effectively exploded, from a handful in the late ’90s to quite literally hundreds today, not counting minor variations. There lately seems to be a counter-movement brewing in response to this…
The Distroless Linux Future May Be Coming
Over the decades the number of Linux distributions has effectively exploded, from a handful in the late ’90s to quite literally hundreds today, not counting minor variations. There lately seems to be a counter-movement brewing in response to this fragmentation, with Project Bluefin’s Distroless project being the latest addition here. Also notable are KDE’s efforts, with KDE Linux as its own top-down KDE-based distro, but now with a switch to BuildStream from Arch likely as a distroless move.
nexttech-news.com
January 12, 2026 at 10:44 PM
The Distroless Linux Future May Be Coming
Over the decades the number of Linux distributions has effectively exploded, from a handful in the late ’90s to quite literally hundreds today, not counting minor variations. There lately seems to be a counter-movement brewing in response to this fragmentation, with Project Bluefin’s _Distroless_ project being the latest addition here. Also notable are KDE’s efforts, with KDE Linux as its own top-down KDE-based distro, but now with a switch to BuildStream from Arch likely as a distroless move. It should be clear that there is no obvious course here yet, and that opinions are very much divided. The idea of ‘Linux’ becoming a more singular OS appeals to some, while to others it’s the antithesis of what ‘Linux’ is about. This much becomes clear in [Brodie Robertson]’s exploration of this topic as well. The way to think about ‘distroless’ is that there is a common base using the Freedesktop SDK on which the customization layer is applied, such as Bluefin, KDE or Gnome’s environments. You could think of this base as the common runtime, using the Freedesktop standards for interoperability for a user-selected layer that’s installed on top. This way the idea of basing a distro on a specific distro is tossed out in favor of something that’s vaguely reminiscent of the Linux Standard Base attempt at standardization. It’ll be fascinating to see how things will move from here, as there are definite arguments to be made in favor of less fragmentation and resultingly less duplicated effort. In many ways this would bring Linux closer to for example FreeBSD, which avoids the Linux Chaos Vortex problem by having a singular codebase. FreeBSD ‘distros’ like GhostBSD and NomadBSD are therefore essentially just specialized customizations that target a sub-group of FreeBSD users. Of course, when we start talking about package managers and other base-distro specific features, we may very well risk igniting the same problems that tore apart the LSB so many years ago. Will we also standardize on RPM over DEB package files and kin, or something else?
hackaday.com
January 12, 2026 at 9:03 PM
The Distroless Linux Future May Be Coming
The Distroless Linux Future May Be Coming
Hackaday Article
hackaday.com
January 12, 2026 at 9:01 PM
**The Distroless Linux Future May Be Coming**

Over the decades the number of Linux distributions has effectively exploded, from a handful in the late ’90s to quite literally hundreds today, not counting minor variations. There lately seems to be a […]

[Original post on poliverso.org]
January 15, 2026 at 5:19 AM
I'm starting to get really interested on immutable "distroless" os, just like, systemd, the desktop environment, the kernel and flatpaks

Tried gnome os today and it was quite nice (would like to try to use it but doesn't seem ready for production stuff)
January 12, 2026 at 5:33 AM