Using Dependabot with Chainguard Containers
How to configure Dependabot to authenticate to your private cgr.dev registry and open pull requests that update …
For the complete documentation index, see llms.txt.
Note: Chainguard OS Packages is in beta. Contact your Chainguard account team to enable it for your organization.
Chainguard OS Packages expands the packages available to your private APK repository by giving you access to the full set of 30,000 enterprise-grade, zero-CVE packages built as part of Chainguard OS and Wolfi. It also includes a small set of Chainguard base images, for example, chainguard-base.
Chainguard OS Packages is designed for larger customers who already build their own images from packages using tools like Bazel, Dockerfiles, and rules_apko, and want to use a wider set of packages from Chainguard. Because you are creating custom builds, you are responsible for the image builds, the build tooling, validation, and compatibility. You still benefit from the fact that Chainguard builds the packages in the Chainguard Factory with complete SBOMs and our standard enterprise-grade, zero-CVE process.
If you need to achieve FIPS compliance, the FIPS variant of Chainguard OS Packages includes access packages with the latest versions of Chainguard’s FIPS-validated modules.
Chainguard OS Packages is not compatible with Chainguard Custom Assembly.
How to configure Dependabot to authenticate to your private cgr.dev registry and open pull requests that update …
When a container or version isn't available to you: how to identify which situation you're in, what to do about each, …
Use build pinning to keep library artifacts stable across rebuilds.
Understand the errors Chainguard Libraries returns when a package or version is blocked, and how they appear across …
An end-to-end walkthrough of Chainguard Containers: pull a free container, run a small Node.js application on it, and …
Last updated: 2026-04-01 00:48