Chainguard doubles its build output in six months as its automated software factory scales to keep pace with faster-moving software threats
Chainguard, the trusted source for open source, recently announced that it has surpassed 1 billion container build manifests – the artifacts generated when a new image in its catalogue is built, updated or patched.
The company has doubled its total build volume from 500 million to more than 1 billion in just six months, as it scales its automated software factory to rebuild and update open source software at increasing speed.
The timing is significant. AI is changing the speed at which software vulnerabilities can be found and exploited, shrinking the window in which organisations have to respond. Chainguard’s approach is to close that window by making secure software available faster: continually rebuilding, updating and patching open source software as vulnerabilities, dependencies and upstream projects change.
Chainguard has also reached 3,000 unique container images in its Chainguard Containers catalogue, adding 1,000 additional images in the same six-month period. The catalogue now includes widely used applications, runtimes and frameworks including Go, NGINX, PostgreSQL, Python and Java.
Together, these milestones demonstrate the scale of Chainguard’s engineering operation and the impact of its automated software factory, built to accelerate output over time at a moment when AI is redefining the speed of software supply chain attacks.
Keeping pace with AI-accelerated attacks
It used to take a human attacker days or weeks to find a vulnerability and build a working exploit. AI has collapsed that timeline and can scan source code and dependencies, chain vulnerabilities together, and weaponise them into new, complex exploits in just hours, often before a fix for specific vulnerabilities reaches the public.
As that window continues to collapse, the ability to identify, rebuild and patch affected software quickly becomes increasingly important.
“The gap between a disclosed vulnerability and a working exploit keeps shrinking, and closing that gap takes two things most vendors can’t offer together. You need a catalogue broad enough to cover virtually every artifact an organisation relies on, and the underlying speed to keep every image in that catalogue up-to-date,” said Matt Moore, Co-founder and Chief Technology Officer, Chainguard. “Reaching 1 billion build manifests and doubling our output in just six months is a signal of both. The only way to stay ahead of attackers is to fix vulnerabilities before they can be exploited. That’s what the Chainguard Factory is built to do, at a pace we’re constantly accelerating.”
Chainguard Factory: Building and rebuilding at scale
The increase from 500 million to 1 billion build manifests in six months reflects a fundamentally faster software factory. Earlier this year, Chainguard introduced Chainguard Factory 2.0, powered by DriftlessAF, a resilient, self-correcting build system that pairs traditional automation with agentic, AI-powered reconciliation bots.
Where the original Chainguard Factory automated the mechanics of rebuilding open source software, Factory 2.0 operates at the speed of AI attacks: detecting drift, resolving dependency conflicts, and correcting itself in real time. Through the Chainguard Factory, the company has now delivered:
- 1 billion+ build manifests: Chainguard has produced more than 500 million build manifests in the past six months alone. Build manifests reflect initial project builds, rebuilds from dependency updates and tooling changes, builds triggered by vulnerabilities, generated SBOMs and signatures, customer-produced custom images through Custom Assembly, and more.
- 3,000+ unique container images: The Chainguard Containers catalogue now features more than 3,000 images for which a minimal, low- or zero-CVE Chainguard image is available, including widely used applications, runtimes, and frameworks like Go, NGINX, PostgreSQL, Python, Java, and many more. In just the past six months, the company added 1,000 new projects to the catalogue.
- 675,000+ image variants: With hundreds of thousands of architecture-specific image variants across its catalogue, Chainguard delivers broad platform coverage and rapid availability of new versions and persistent availability of historical versions as upstream projects and architectures evolve.
- 32,000+ unique Chainguard OS packages: By providing customers with thousands of underlying OS packages and hundreds of thousands of package versions, Chainguard Factory assembles the building blocks that organisations need to customise their container images from Chainguard.
To date, Chainguard has eliminated 2 million CVEs across all of its customers. These are vulnerabilities that never had the chance to become incidents because they were resolved before the image shipped. Every new project, rebuild, and patch produced by Factory 2.0 shrinks the window an attacker has to work with. The faster Chainguard’s software factory moves, the more open source software it can secure and the more quickly customers can respond to vulnerabilities.
“The depth of what Chainguard has built – and continues to improve – would take years and a very experienced team of experts to replicate,” said Maha Alsayasneh, Senior Engineering Manager, Elastic. “Partnering with Chainguard has let our engineers spend their time on the problems only we can solve, instead of chasing CVEs across our stack.”
Find out more
Explore Chainguard’s container image catalogue and learn more about working with Chainguard.

