Chainguard, based in Kirkland, Washington, United States, said on Sept. 3, 2026 that it has passed 1 billion unique container build manifests, doubling its total from 500 million in six months. The company also expanded its Chainguard Containers catalog to 3,000 unique images, adding 1,000 in the same period.
Milestones#
The build manifests are generated each time a new image in the catalog is built, updated, or patched. Chainguard said the catalog now includes 3,000 unique container images and 675,000 image variants.
- 1 billion unique container build manifests
- 3,000 unique container images
- 675,000 image variants
- 2 million Common Vulnerabilities and Exposures (CVEs) eliminated across customers
AI-accelerated attacks#
Chainguard said artificial intelligence has shortened the time attackers need to find and exploit vulnerabilities. The company stated that AI can scan source code and dependencies, chain vulnerabilities, and create exploits in hours, often before fixes are public.
“The gap between a disclosed vulnerability and a working exploit keeps shrinking, and closing that gap takes two things most vendors can’t offer together. You need a catalog broad enough to cover virtually every artifact an organization relies on, and the underlying speed to keep every image in that catalog up-to-date,” said Matt Moore, Co-founder and Chief Technology Officer, Chainguard. “Reaching 1 billion build manifests and doubling our output in just six months is a signal of both. The only way to stay ahead of attackers is to fix vulnerabilities before they can be exploited. That’s what the Chainguard Factory is built to do, at a pace we’re constantly accelerating.”
Chainguard Factory 2.0#
Chainguard attributes the acceleration to Chainguard Factory 2.0, introduced earlier this year and powered by DriftlessAF. The company describes DriftlessAF as a resilient, self-correcting build system that combines traditional automation with agentic, AI-powered reconciliation bots. Factory 2.0 detects drift, resolves dependency conflicts, and corrects itself in real time, according to Chainguard.
Chainguard said it has eliminated 2 million CVEs across its customers. These vulnerabilities were resolved before images shipped, the company said.
“The depth of what Chainguard has built, and continues to improve, would take years and a very experienced team of experts to replicate,” said Maha Alsayasneh, Senior Engineering Manager, Elastic. “Partnering with Chainguard has let our engineers spend their time on the problems only we can solve, instead of chasing CVEs across our stack.”
Chainguard provides open source software artifacts to engineers and AI agents. Its customers include Fortune 500 enterprises and global industry leaders such as Anduril, Canva, DocuSign, OpenAI, Public Storage, Snap Inc., and Snowflake. Investors include Amplify, IVP, Kleiner Perkins, Lightspeed Venture Partners, Mantis VC, Redpoint Ventures, Sequoia Capital, and Spark Capital.
