Cut bloat, not features
Ubuntu blog ·
Accelerating software delivery with minimal OCI images For Independent Software Vendors (ISVs), delivering containerized applications to enterprise clients often means navigating a difficult trade-off between minimal image size and accurate security visibility. Traditional approaches can leave development teams battling severe CVE noise or, conversely, missing critical vulnerabilities entirely due to scanner blind spots. What’s more, […]
For Independent Software Vendors (ISVs), delivering containerized applications to enterprise clients often means navigating a difficult trade-off between minimal image size and accurate security visibility. Traditional approaches can leave development teams battling severe CVE noise or, conversely, missing critical vulnerabilities entirely due to scanner blind spots. What’s more, off-the-shelf images require clients to fit their needs into what’s available, rather than being able to build and use container images that meet their exact specifications.
To help ISVs overcome this compromise, Canonical is hosting a technical webinar on September 23, 2026 . In the session, you’ll learn how to deliver lightweight, secure, and scannable container images without the operational overhead.
Typical distroless images use a “top-down” approach, inflating a base image and then cherry-picking to trim it down. Unfortunately, this often strips out essential package metadata, causing security scanners to miss critical vulnerabilities and report false negatives.
In this webinar, you’ll learn how rocks, Canonical’s OCI-compliant, minimal container images, solve this by using a “bottom-up” approach. Powered by Chisel, our novel package manager, rocks are built by slicing packages directly from the Ubuntu archives, staying ultra-small while retaining the exact metadata required for highly accurate CVE scanning.
Creating a minimal, secure, and maintainable container shouldn’t be a hurdle. Our engineers will provide a hands-on demonstration of building a rock using Chisel and Rockcraft. You will see how to:
Enterprises trust their operating systems for their most critical systems. With rocks, ISVs can draw upon the trusted Ubuntu ecosystem, but for their container dependencies. We will cover the enterprise commitments behind rocks, including:
Because rocks solve the distroless visibility problem, the wider cybersecurity industry is taking notice. We will highlight how major security vendors are partnering with Canonical through the Ubuntu Security Research Alliance Program. You will learn how industry-leading tools, including Snyk and Google’s OSV-Scanner, now provide native support for scanning chiseled Ubuntu images, allowing you to confidently deliver precise, noise-free vulnerability data to your customers.
Stop letting container bloat and scanning inaccuracies slow down your enterprise software deployments.
Register now on BrightTALK to reserve your spot