Canonical has outlined its "cut bloat, not features" approach to building minimal OCI container images in a new blog post, ahead of a webinar on the subject scheduled for September 23, 2026.

Written by Lily Rivers-Klee, the post addresses a challenge commonly faced by Independent Software Vendors (ISVs) delivering containerized applications to enterprise clients: the tension between minimal image size and accurate security visibility. According to the post, conventional approaches can leave development teams either facing severe CVE noise from bloated base images or missing critical vulnerabilities entirely due to scanner blind spots in heavily stripped-down images.

The proposed approach calls for curating images to remove non-essential packages while preserving core system components required for vulnerability scanners to function accurately. Rather than choosing between full-featured base images and ultra-minimal images built "from scratch," Canonical advocates for a disciplined middle path that prioritises scanner compatibility alongside efficiency.

The post highlights Canonical's existing tooling in support of this methodology. Rockcraft is Canonical's tool for building OCI images, while Chisel enables developers to create precise Ubuntu filesystem slices. Together, these tools underpin Canonical's "Rocks" — immutable OCI base images intended to balance minimal footprint with support for security scanning tools including Snyk and OSV-Scanner.

Canonical's blog post also references Ubuntu Pro, the company's subscription offering security patching for container images, and the Ubuntu Security Research Alliance Program as elements of its broader security infrastructure.

The September 23 webinar is expected to feature a live demonstration of Chisel and Rockcraft, alongside discussion of Canonical's enterprise commitments and its partnerships with scanner vendors.


Canonical 在一篇新部落格文章中闡述了其「精簡冗餘,保留功能」的建構精簡 OCI 容器鏡像方法,相關主題研討會將於 2026 年 9 月 23 日舉行。

由 Lily Rivers-Klee 撰寫的文章,針對獨立軟件供應商(ISV)向企業客戶交付容器化應用時常面臨的挑戰:在最小鏡像體積與準確安全可見性之間取得平衡。文章指出,傳統方法可能令開發團隊面臨兩難局面——要麼因臃腫基礎鏡像產生嚴重的 CVE 噪音,要麼因過度精簡的鏡像導致掃描器盲區而完全遺漏關鍵漏洞。

提出的方法主張策劃鏡像以移除非必要套件,同時保留漏洞掃描器準確運作所需的核心系統組件。Canonical 倡導的並非在全功能基礎鏡像與「由零開始建構」的超精簡鏡像之間二選一,而是一種兼顧掃描器兼容性與效率的嚴謹中間路線。

文章強調了 Canonical 現有工具對此方法論的支持。Rockcraft 是 Canonical 用於建構 OCI 鏡像的工具,而 Chisel 讓開發者能建立精確的 Ubuntu 檔案系統切片。這些工具共同支撐着 Canonical 的「Rocks」系列——旨在兼顧最小佔用空間與 Snyk 及 OSV-Scanner 等安全掃描工具兼容性的不可變 OCI 基礎鏡像。

Canonical 的部落格文章亦提及 Ubuntu Pro——公司的訂閱服務為容器鏡像提供安全修補,並介紹了 Ubuntu Security Research Alliance Program 作為其更廣泛安全基礎設施的組成部分。

9 月 23 日的研討會預計將展示 Chisel 與 Rockcraft 的現場演示,並討論 Canonical 的企業承諾及其與掃描器供應商的合作關係。

新聞來源 / Original News Source