news and updates

The Minimus Blog

Security research, technical walk-throughs, news articles, commentary on application and cloud native security. Updated regularly by the Minimus team.

Guides

Article 21 Compliance: NIS2 Requirements for Container-Based Workloads

Understand NIS2 requirements for container workloads, from supply chain security to CVE management and audit-ready compliance controls.
Debra Hopper
April 20, 2026
Opinions

Turning Back the Tide: Defenders in the Age of AI Vulnerability Research

AI is changing how vulnerabilities are found, not how they’re fixed. Defenders need a new approach: shrinking the attack surface before vulnerabilities exist.
Neil Carpenter
April 17, 2026
Guides

DORA Compliance for Container-Based Workloads: What Financial Sector Engineers Need to Know

DORA compliance for container workloads explained, with practical implementation guidance for platform engineers and ICT vendors.
Debra Hopper
April 17, 2026
Guides

Implementing CIS Hardening Across Container Pipelines

Learn how to scale CIS hardening with automation, SBOMs, and minimal images across container environments.
Debra Hopper
April 16, 2026
Guides

CIS Hardened Images: What They Are and How CIS Applies to Containers

A guide to CIS hardened images, how CIS benchmarks translate to containers, and what changes in a containerized environment.
Debra Hopper
April 15, 2026
Guides

Distroless vs hardened container images

Distroless images remove shells & package managers. Hardened images add patching, SBOMs & compliance. Learn when to use each with Minimus.
Liron Prizner
April 13, 2026
Guides

How to Reduce Container Image Attack Surface

Learn how to reduce container attack surfaces: build minimal bases, harden Dockerfiles, scan in CI/CD, enforce Kubernetes controls, and use SBOMs.
Ori Ron
April 11, 2026
Guides

Chainguard Alternatives: Best Hardened Image Providers [2026]

Chainguard alternatives for hardened container images: minimal bases, continuous rebuilds, SBOMs, CVE reduction, and compliance-ready images
Yael Nardi
April 9, 2026
Guides

Near zero CVE container images explained | Minimus

What near zero CVE images are and are not, why they matter for security and compliance, and how to get there with multi-stage builds, scanning, SBOMs, and VEXs.
Pini Karuchi
April 7, 2026
Guides

How to Build Zero-CVE Container Images (Without Slowing Your Pipeline)

Learn how to build zero-CVE container images using minimal bases, automated rebuilds, SBOMs, and VEX while keeping pipelines fast and secure.
Yael Nardi
April 5, 2026
Guides

How to prevent software supply chain attacks

Learn how to prevent software supply chain attacks. Covers SBOMs, SLSA levels, Sigstore signing, KEV-based CVE prioritization, and hardening CI/CD pipelines.
Liron Prizner
April 3, 2026
Security Research

Trivy v0.69.4 Software Supply Chain Attack: What You Need To Know

Trivy v0.69.4 supply chain attack explained. Learn what happened, how to tell if you're impacted, and what steps to take to protect your data.
Artur Oleyarsh
March 23, 2026
Guides

Understanding Container Runtimes: Static vs Dynamic and Runtime Isolation

Learn how container runtimes work, why static vs dynamic binaries matter, and how runtime isolation affects container security and reliability.
Yevgeni Bulichev
March 13, 2026
Minimus Product

Minimus Package Comparison: Understanding What’s Inside Your Container Image

Understand what’s inside your container image. Minimus images start without unnecessary packages to reduce image size and eliminate vulnerabilities.
Yakir Zagron
March 12, 2026
Guides

Hardened Container Images: The Foundation of Container Security

What are hardened container images? Learn how they reduce vulnerabilities, minimize attack surface, and strengthen container security.
Minimus
March 6, 2026

Minimus Activity Log: Operational Visibility for Hardened Minimal Images

Monitor platform access, token changes, and custom image activity with the Minimus Activity Log. Built-in visibility and auditability for hardened images.
Neil Carpenter
March 4, 2026
Minimus Product

Fast Go CVE Remediation: Reducing CVE Risk With Hardened Container Images

Go CVEs are inevitable. Slow remediation isn’t. Minimus' minimal, source-built images reduce risk and fix critical vulnerabilities in hours.
Amit Kaplan
February 25, 2026
Guides

Minimal Distroless Images: Benefits Beyond Security

Minimal distroless images offer more than security benefits. Smaller images cut infrastructure costs, speed CI/CD, and improve performance across environments.
Adam Clark
February 25, 2026
Security Research

Stop Running OpenClaw With 2,000+ CVEs: Why the Minimus OpenClaw Image Has 99% Fewer CVEs

Running OpenClaw? Your container image might be insecure. Learn how Minimus reduces OpenClaw CVEs by 99% while keeping the same functionality.
Assaf Shapira
February 19, 2026
Guides

Zero Trust with Minimus: Hardened Images for a Secure Foundation

Build Zero Trust from the image up. Minimus hardened containers deliver verifiable builds, minimal attack surface, and signed artifacts for a secure foundation.
Patrick Maddox
February 18, 2026
Minimus Product

Minimus RBAC: Granular Access Control for Container Security

Minimus RBAC replaces manual permissions with Viewer, Operator, and Admin roles, improving security, auditability, and operational efficiency.
Gabriele Falchini
February 13, 2026
Minimus Product

Application Compliance: Taking Container Image Hardening to the Next Level

Go beyond base image compliance with application-level hardening. Minimus delivers pre-hardened images and audit-ready validation.
Adam Clark
February 11, 2026
Security Research

CVE-2026-22039: How Kyverno’s Critical Authorization Bypass Breaks Kubernetes Namespace Isolation

This post breaks down CVE-2026-22039, a Kyverno authorization bypass that allows cross-namespace resource access in Kubernetes clusters.
Artur Oleyarsh
February 4, 2026
Minimus Product

Beyond Version Tags: Detailed Changelogs for Container Images

Go beyond version tags. See exactly what changed in container images, compare digests, and decide when to update using Minimus detailed changelogs.
Ashley Ward
January 29, 2026
Minimus Product

Add File Bundles to Private Images: More Flexibility and Control

See how file bundling in Minimus Image Creator lets teams include certificates and config files in private images without managing separate builds.
Adam Clark
January 27, 2026
Guides

How to Use CBOMs in Containerized Environments: Data Formats, Tools, and Use Cases

A practical guide to using CBOMs in containerized environments, covering data formats, tools, and cryptographic risk management.
Murugiah Souppaya
January 16, 2026
Guides

From SBOM to CBOM: Why Container Security Needs Cryptographic Visibility

Learn what a Cryptographic Bill of Materials (CBOM) is, how it complements SBOMs, and why cryptographic visibility matters for container image security.
Murugiah Souppaya
January 15, 2026
Guides

How to Move From Distribution-Based Images to Distroless With Minimus

Learn why distroless images are more secure and how to migrate from distro-based images to distroless with Minimus, without breaking existing workflows.
Patrick Maddox
December 12, 2025
Guides

Sha1-Hulud 2.0 - The Second Coming: What You Need To Know

What happened and how Sha1-Hulud 2.0 works: a second-gen supply chain worm infecting npm packages, harvesting credentials, and replicating across GitHub.
Artur Oleyarsh
December 1, 2025
Guides

3 Ways to Achieve FIPS 140-3 Validation in Container Images

Understand the three paths to FIPS 140-3 validation for container images and how each impacts security, compliance, maintenance, and audit readiness.
Minimus
November 24, 2025
Guides

Understanding FIPS 140-3: How It Strengthens Security and Compliance in Container Images

Understand FIPS 140-3, how validation works, and why it’s essential for securing container images and meeting modern compliance standards.
Minimus
November 21, 2025
Security Research

New Vulnerabilities in runC Allow Container Escape

Read this for a breakdown of new runC CVEs, their exploitability, affected versions, and how to patch and mitigate.
Artur Oleyarsh
November 20, 2025
Minimus News

Image Creator: A New Chapter in Container Security

Build and customize your own hardened container images with Minimus' Image Creator, now generally available.
Minimus
November 19, 2025
Guides

MinIO Docker Image Changes: What Happened and How to Find a Secure Alternative

MinIO announced they will no longer publish free Docker images to Docker Hub. For teams affected by these changes, Minimus provides a secure MinIO alternative.
Minimus
October 23, 2025
Guides

Using the Kyverno Admission Controller to Enforce Hardened Base Images

Secure Kubernetes deployments with Kyverno by enforcing Minimus hardened base images, reducing vulnerabilities and improving compliance.
Neil Carpenter
September 25, 2025
Minimus Product

Introducing Minimus Image Creator: Create Custom Minimal Images

Build custom minimal container images from hardened base images and 20k+ packages - with the security, updates, and compliance benefits of all Minimus images.
Patrick Maddox
September 10, 2025
Guides

FIPS Compliance for Containers: What Developers Need to Know

Learn what FIPS is, why FIPS compliance matters for developers, and tips for building and maintaining FIPS-compliant containers.
Kat Cosgrove
September 5, 2025
Security Research

Introducing Mean Time to CVE as a Security Metric for Container Images

Mean Time to CVE reframes container security metrics by focusing on the frequency of new vulnerabilities, instead of just amount, to better predict future risk.
Jackson Parker
September 4, 2025
Guides

Navigating the Bitnami Pricing Changes: What You Need to Know

Bitnami has moved most images and Helm charts behind a paywall. Learn what’s changing, how to navigate it, and explore Minimus as a drop-in alternative.
Minimus
August 28, 2025
Guides

Using Open Source Vulnerability Scanners With Hardened Container Images

Learn about popular open source vulnerability scanners, and how using them alongside secure base images like Minimus simplifies vulnerability management.
Kat Cosgrove
August 27, 2025
Minimus Product

Compliance Dashboards: Detailed Visibility for CIS, FIPS, and STIG

Minimus customers can now view at an image level, or across their environment, the specific compliance regimes and controls image configurations are mapped to. 
Patrick Maddox
August 22, 2025
Minimus Product

Introducing Hardened Helm Charts for Minimus Images

Minimus hardened Helm charts are already configured to use Minimus images, making it easy to deploy secure application stacks.
Ashley Ward
August 21, 2025
Minimus Product

Minimus VEX Support: Filter Out Non-Exploitable Vulnerabilities Automatically

VEX in Minimus gives teams a clear picture of which vulnerabilities impact them and helps reduce time and manual work required to confirm vulnerability status.
Neil Carpenter
August 19, 2025
Minimus News

What’s New in Minimus: Compliance Dashboards, Helm Charts, and VEX

New from Minimus: Compliance dashboards, VEX, hardened helm charts, and Microsoft SSO. Secure container deployment just got easier for teams at scale.
Josh Thorngren
August 5, 2025
Guides

Enabling Secure, Compliant Software Delivery with Minimus Container Images

Minimus container images avoid 95% of CVEs and support secure, compliant delivery in regulated, air-gapped, and fast-moving environments.
Minimus
August 1, 2025
Guides

Securing Retail Containerized Environments with Minimus Hardened Images

Minimus container images help retailers secure cloud and edge workloads, reduce vulnerabilities by 95%, and simplify PCI DSS compliance at scale.
Minimus
July 24, 2025
Minimus News

Minimus Container Images Now Available on Iron Bank: Accelerating FedRAMP Compliance

Minimus container images are now publicly available on Iron Bank, the U.S. Department of Defense's repository of digitally signed, hardened container images.
Minimus
July 22, 2025
Guides

Supporting HIPAA Compliance with Minimus Secure Container Images

Minimus images simplify HIPAA compliance with secure-by-default containers, real-time risk management, and full supply chain transparency.
Minimus
July 16, 2025
Guides

The Cyber Resilience Act: What Open Source Users Need to Know

The Cyber Resilience Act shifts security responsibility to vendors. Learn how it impacts open source software use and how to reduce your risk.
Kat Cosgrove
July 15, 2025
Minimus News

Announcing the Minimus × Wiz Partnership

We’re excited to announce a new partnership with Wiz. Combine Wiz’s comprehensive visibility with Minimus’s secure-by-default images for end-to-end security.
Minimus
July 9, 2025
Minimus Product

Minimus Platform Overview: Container Security That Just Works

Secure your software supply chain with Minimus: trusted container images, real-time threat intelligence, and full visibility for developers and security teams.
Minimus
July 8, 2025
Minimus Product

Track and Prioritize CVEs with Minimus' Vulnerability Intelligence

Minimus' vulnerability intelligence helps you assess risk, prioritize action, and maintain visibility with detailed advisories and per-image CVE tracking.
Neil Carpenter
June 30, 2025
Guides

Strengthening Cloud-Native Security for Financial Services with Minimus

Learn how Minimus helps financial institutions reduce CVEs by 95% and simplify compliance—even in air-gapped and highly regulated deployments.
Minimus
June 25, 2025
Minimus Product

Automating Workflows with Minimus Action Providers: Slack, Webhooks, and More

Automate workflows and stay informed with Minimus Action Providers. Trigger alerts, scans, and updates across your tools when container changes happen.
Ashley Ward
June 24, 2025
Minimus News

What’s New in Minimus: June 2025

In this week’s release, we’ve focused on improvements to our actions, advisories, integrations, as well as updating the frontend of the Minimus web console.
Josh Thorngren
June 23, 2025
Guides

Using Minimus to Achieve NIST SP 800-190 Container Security Compliance

Learn how Minimus hardened container images align with NIST SP 800-190, reducing vulnerabilities and simplifying compliance.
Minimus
June 9, 2025
Minimus Team

Meet the Team: Sean Reardon, Account Executive

Meet Sean Reardon—learn what brought Sean to Minimus and what he thinks the key is to building strong relationships with customers.
Debra Hopper
June 5, 2025
Guides

Supporting FedRAMP Compliance with Minimus Secure Container Images

Simplify FedRAMP compliance with Minimus: secure, minimal container images, automated remediation, and full compatibility with air-gapped environments.
Minimus
June 3, 2025
Minimus Team

Meet the Team: Maya Even-Shani, Director of Product Management

Maya Even-Shani shares her journey to Minimus, insights on product leadership, and what makes Minimus images an easy win for security teams.
Minimus
May 29, 2025
Minimus Product

Why Minimus? Ben Bernstein on Building Better Security

Ben Bernstein shares why Minimus was built, how it simplifies security, and how it helps developers reclaim time by reducing vulnerabilities by 95%.
Ben Bernstein
May 28, 2025
Minimus Team

Meet the Team: Neil Carpenter

In this “Meet the Team” Q&A, we talked with Neil Carpenter, who joined the solutions architecture team at Minimus at the beginning of April.
Minimus
May 23, 2025
Minimus News

Minimus' Vision, Team, and Trajectory: A Conversation with Yoav Leitersdorf & Ben Bernstein

Yoav Leitersdorf and Ben Bernstein discuss the story behind Minimus, their vision for security, and key insights from their journeys as founders and leaders.
Minimus
May 19, 2025
Security Research

What’s in Your Nginx Image? A Deep Dive into Container Security

Standard Nginx images often include unused packages that introduce hidden vulnerabilities. Learn how using a minimal nginx image can reduce your attack surface.
Patrick Maddox
May 15, 2025
Minimus Product

Minimus Has 95% Fewer CVEs—Here’s How We Back That Up (and More)

Curious where our 95% CVE reduction claim comes from? Here's the data and stats behind that and more.
Josh Thorngren
May 13, 2025
Minimus News

Minimus Launches at RSAC 2025; Reducing Application Security Vulnerabilities by over 95%

Read the press release announcing Minimus' exit from stealth.
Minimus
April 28, 2025
Minimus News

Introducing Minimus: Maximum Security, Minimum Effort

Minimus is now generally available. Avoid 95% of CVEs with our secure, minimal container images. Get started today.
Minimus
April 28, 2025
Guides

What is Software Composition Analysis (SCA)?

Software composition analysis (SCA) finds CVEs and license risk in open source dependencies. How SCA works, tools, SDLC integration, best practices.
Minimus
Guides

What is CVE remediation? Prioritization and response guide

CVE remediation combines CVSS, EPSS, and CISA KEV signals to prioritize fixes. Learn the lifecycle, container-specific workflows, and tools that work in 2026.
Minimus

What is Software Supply Chain Security

SBOMs signing and hardened images show how to reduce dependency risk and secure your software supply chain from source to production
Minimus
Guides

How Minimal Base Images Reduce Real Risk

Minimal base images cut attack surface, reduce CVEs, improve SBOM clarity, and strengthen container security using multi-stage builds and automation.
Minimus
Sign up for minimus

Avoid over 97% of container CVEs

Access hundreds of hardened images, secure Helm charts, the Minimus custom image builder, and more.