
Hardened, continuously rebuilt open source containers, libraries, and VMs with no known CVEs
Chainguard was founded in 2021 by Dan Lorenc, Kim Lewandowski, Ville Aikas, Matt Moore, and Scott Nichols, several of whom built container and supply chain tooling at Google and created the original distroless images along with the Sigstore signing project and the SLSA framework. The company's premise is that patching vulnerabilities downstream is the wrong end of the problem: rather than scanning an image and chasing what a scanner reports, it rebuilds the software itself. That work runs on Wolfi, a Linux distribution the company built specifically for supply chain security, with fine-grained packaging and rapid upstream tracking so fixes land in hours rather than on a distribution's release cadence.
The catalog covers containers, language libraries, virtual machines, OS packages, and CI actions, rebuilt daily from source with build provenance and an SBOM attached to each artifact. Images are stripped to what an application actually needs, which removes both attack surface and most of the noise a scanner would otherwise raise. Adoption is typically a base image or dependency swap rather than a new tool in the pipeline, and the attestations become the evidence trail for FedRAMP, PCI DSS, SOC 2, and CMMC audits. Chainguard says its catalog now spans more than 3,000 projects and 520,000 images. The company has raised roughly $892M, including a $356M Series D in April 2025 co-led by Kleiner Perkins and IVP and a $280M growth round in October 2025, at a $3.5B valuation.



