Case Study: Sublime Security cuts base image CVEs to near zero and reclaims triage capacity with Chainguard
Key results
The challenge
Sublime Security ran weekly CVE triage through rotating engineers, and container base-image vulnerabilities consumed a disproportionate share of every rotation as volume grew. As a security company, Sublime held itself to a high internal standard, and enterprise customers were pushing for SBOMs and evidence of active remediation beyond a SOC 2 attestation.
The solution
Sublime adopted Chainguard Containers, integrating them via OpenID Connect and GitHub Actions so engineers could pick hardened base images from the catalog without routing through security for approval. The distroless images carry a smaller software surface, reducing the vulnerabilities inherited from upstream base layers.
“The most measurable outcome has been a near 100% reduction in base image CVEs for teams that have adopted Chainguard internally.”
ABAndrew BechererAdvisor, Sublime Security
The results, in context
Sublime reported a near 100% reduction in base image CVEs for teams that adopted Chainguard internally. Eliminating that workload freed at least 50% of the affected engineer's triage time for higher-value work, and the smaller software surface reduced false-positive scan alerts.