container security

RapidFort + Wiz: Closing the Gap in Software Supply Chain Security

RapidFort + Wiz: Closing the Gap in Software Supply Chain Security

RapidFort has listed a native integration with Wiz, surfacing its curated hardened container images and evidence-backed CVE advisories directly inside the Wiz platform. The drop-in replacement model eliminates the re-testing burden that typically blocks hardened image adoption. For ITDMs and developers alike, the integration is as much a developer velocity story as it is a security one.

RapidFort + Wiz: Closing the Gap in Software Supply Chain Security Read More »

RapidFort and Trivy Cut CVE Noise in Software Supply Chain Security

RapidFort and Trivy Cut CVE Noise in Software Supply Chain Security

RapidFort and Aqua Security have partnered to integrate RapidFort’s remediation advisories into the Trivy open-source scanner, enabling accurate reporting of near-zero CVE container images. The integration reduces scanner noise and false positives without requiring developers to own the remediation work themselves. For security and engineering teams, it means scan results that actually reflect reality at the build gate.

RapidFort and Trivy Cut CVE Noise in Software Supply Chain Security Read More »

RapidFort Eyes Federal Market With Q4 Supply Chain Security Push

RapidFort Eyes Federal Market With Q4 Supply Chain Security Push

RapidFort is sponsoring four major Q4 events including KubeCon and OWASP AppSec USA, while hosting a defense technology panel tied to the SpaceWERX Transition Program. The move signals a focused push into federal and air-gapped environments where software supply chain security is an acute, underserved need. ECI Research data on open-source validation and disconnected environments helps explain why the timing makes sense.

RapidFort Eyes Federal Market With Q4 Supply Chain Security Push Read More »

Docker Cloud Sandboxes Extend AI Agent Isolation to the Cloud

Docker Cloud Sandboxes Extend AI Agent Isolation to the Cloud

Docker has launched Cloud Sandboxes, extending its local microVM isolation model to managed cloud infrastructure so agentic workflows can run unattended at scale. The company also published a next-generation Kits specification built on OCI images and committed to CNCF governance. ECI Research analyst coverage examines what this means for developer productivity, compliance, and the emerging agentic infrastructure market.

Docker Cloud Sandboxes Extend AI Agent Isolation to the Cloud Read More »

RapidFort + CrowdStrike: Closing the Container Vulnerability Gap

RapidFort + CrowdStrike: Closing the Container Vulnerability Gap

RapidFort’s new integration with CrowdStrike Falcon Cloud Security targets the gap between vulnerability detection and remediation in Kubernetes environments. By ingesting SBOM and CVE data from Falcon and automating container image hardening, the two vendors aim to close a loop that has historically required significant manual intervention. The integration has particular relevance for federal and defense organizations operating in air-gapped environments.

RapidFort + CrowdStrike: Closing the Container Vulnerability Gap Read More »

Echo Acquires Minimus: Secure-by-Default Market Consolidates

Echo Acquires Minimus: Secure-by-Default Market Consolidates

Echo has acquired key technology assets from Minimus, positioning itself as the first distro-agnostic, secure-by-default software platform. The deal signals market consolidation around two players: Echo and Chainguard. ECI Research data on open source validation and AI compliance friction reveals why this category matters now.

Echo Acquires Minimus: Secure-by-Default Market Consolidates Read More »

Docker Bets on Agentic AI With CPO and CFO Hires | ECI Research

Docker Bets on Agentic AI With CPO and CFO Hires | ECI Research

Docker has appointed Mat Velloso as CPO and Vinh Le as CFO, both hired explicitly to advance the company’s agentic AI platform strategy. ECI Research examines why Docker’s container runtime heritage gives it credible standing in the emerging agentic governance market. The appointments signal a deliberate push to own the execution layer where AI agents operate at enterprise scale.

Docker Bets on Agentic AI With CPO and CFO Hires | ECI Research Read More »

Traefik's Distroless Zero Targets Container Attack Surface

Traefik’s Distroless Zero Targets Container Attack Surface

Traefik Labs has announced Distroless Zero, a hardened container model that removes C libraries and system dependencies to eliminate attack surface rather than scan for it. With FIPS 140-3 and EU CRA deadlines arriving this fall, the timing is deliberate. ECI Research data shows software supply chain security is a top investment priority for nearly half of engineering organizations surveyed.

Traefik’s Distroless Zero Targets Container Attack Surface Read More »

Traefik Distro Zero: Memory-Safe, FIPS 140-3 Gateway Security

Traefik Distro Zero: Memory-Safe, FIPS 140-3 Gateway Security

Traefik Labs has introduced Distro Zero, a hardened container image that ships a single static Go binary with FIPS 140-3 validated cryptography and no C library substrate. The announcement targets regulated enterprises facing the FIPS 140-2 sunset deadline and EU Cyber Resilience Act reporting obligations. Advanced gateway capabilities are unlocked by license on the same binary, eliminating re-validation when requirements grow.

Traefik Distro Zero: Memory-Safe, FIPS 140-3 Gateway Security Read More »

Minimus Opens Free Secure Container Image Catalog | ECI Research

Minimus Opens Free Secure Container Image Catalog | ECI Research

Minimus is opening its entire catalog of near-zero CVE container images for free, with no registration required. ECI Research examines why the move targets the growing asymmetry between AI-accelerated vulnerability discovery and slow remediation, and what it means for enterprise DevSecOps strategy. Signed SBOMs and an agent-ready CLI make this more than a freemium play.

Minimus Opens Free Secure Container Image Catalog | ECI Research Read More »