Traditional STIG scanners need a shell to run their checks. Chainguard images are built without one by design. That mismatch has left DoD programs pursuing an ATO and vendors pursuing FedRAMP with a bad choice: soften a hardened image just to pass a compliance scan, or run two separate STIG workflows depending on which image variant you're using.

Anchore Enterprise now runs STIG checks on Chainguard images across both shell-based and fully distroless variants, with no shell execution required. In this session, we'll show it live: pulling a shell-less Chainguard image, running it through Anchore's policy engine, and walking through the resulting STIG audit trail, the same one your ATO or FedRAMP reviewer will ask for.

Join our experts from Chainguard and Anchore for a live demonstration and discussion on vulnerability management and compliance standards.

Featured Speakers

Philip Brooks

Senior Solutions Engineer, Chainguard

Bradley Jones

Senior Software Engineer, Anchore