Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2713+ Articles
165+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Chainguard Doubles Output to 1 Billion Build Manifests in Six Months
Chainguard Doubles Output to 1 Billion Build Manifests in Six Months
NEWS

Chainguard Doubles Output to 1 Billion Build Manifests in Six Months

Chainguard's container image factory doubled its rebuild output from 500 million to over 1 billion manifests, driven by a new agentic pipeline.

Dylan H.

News Desk

September 8, 2026
3 min read

Doubling Output in Half a Year

Container security company Chainguard has crossed 1 billion build manifests produced by its image factory, doubling its output from 500 million manifests just six months earlier. Over the same period, the company's catalog grew to more than 3,000 unique container images and 675,000 individual image versions.

A build manifest is Chainguard's unit of account for every verifiable artifact its factory produces — a fresh image build, a rebuild triggered by a security patch, an architecture variant, or a regenerated SBOM following a dependency change. The metric is less a vanity number than a proxy for how comprehensively the entire catalog is kept current against new vulnerabilities and dependency updates.


Growth Snapshot

MetricFigure
Build manifests (current)1,000,000,000+
Build manifests (six months prior)~500,000,000
Unique container images3,000+
Image versions in catalog675,000+

What's Behind the Numbers

Chainguard attributes the acceleration to two pieces of infrastructure:

  • Chainguard OS — a purpose-built Linux distribution for cloud-native workloads, built around rolling releases rather than a traditional six-month cadence, giving the company continuous rather than periodic control over its supply chain.
  • Factory 2.0, powered by an open-source agentic framework called DriftlessAF, which replaces the company's prior event-driven rebuild system with self-correcting automation. Rather than reacting to individual triggers, the system continuously compares desired state against actual state, assigns reconciliation work to bots, and calls on AI for judgment calls in more complex cases — while still producing verifiable, auditable outputs. Failed tasks are retried automatically rather than requiring manual intervention.

Why It Matters for Supply Chain Security

Chainguard frames the milestone around a shift in the threat model: as attackers increasingly use AI to accelerate vulnerability discovery and exploit development, defenders need to compress how quickly a patched, verified image reaches production across an entire dependency graph — not just for a handful of flagship images. A catalog of 3,000+ images and 675,000+ versions only stays meaningfully secure if all of it, not just the popular subset, can be rebuilt and reverified quickly after a new CVE drops.

That's the underlying argument for treating rebuild velocity at scale — rather than headline vulnerability counts — as the metric worth watching in the "hardened base image" space that Chainguard, and competitors, occupy.


References

  • The Hacker News — What It Took to Reach 1 Billion Build Manifests

Related Reading

  • Adobe Rushes Emergency Fix as Magento "StyleSmuggler" Zero-Day Backdoors Servers
#Chainguard#Supply Chain Security#Container Security#DevSecOps#SBOM

Related Articles

Chainguard Unveils Factory 2.0 to Automate Hardening the Software Supply Chain

The rebuilt Chainguard Factory platform adds deeper security automation designed to continuously reconcile open source artifacts across containers,...

3 min read

The State of Trusted Open Source Report: Key Findings for 2025

Chainguard's first-ever State of Trusted Open Source report reveals critical insights into open source consumption patterns across container images,...

6 min read

Container Supply Chain Security: SBOMs and Keyless Signing with Syft, Grype, and Cosign

Build a CI pipeline that generates SBOMs with Syft, scans them for vulnerabilities with Grype, and signs container images keylessly with Cosign — closing the loop between what you shipped and what you can prove you shipped.

9 min read
Back to all News