Case Study Deskcasestudydesk.com
CybersecuritySourced

Case Study: Sublime Security cuts base image CVEs to near zero and reclaims triage capacity with Chainguard

Sublime Security Case StudySourced & dated by Case Study Desk
Key facts · TL;DR
Company
Sublime Security
Industry
Cybersecurity
Challenge
Container base-image CVEs consumed a large share of every weekly triage rotation.
Headline result
Sublime Security reported a near 100% reduction in base image CVEs for teams that adopted Chainguard, freeing at least 50% of the affected engineer's triage time.

Key results

~100%
Reduction in base image CVEs
teams that adopted Chainguard internally
50%
Triage time freed
task that used to consume most of a triage shift

The challenge

Sublime Security ran weekly CVE triage through rotating engineers, and container base-image vulnerabilities consumed a disproportionate share of every rotation as volume grew. As a security company, Sublime held itself to a high internal standard, and enterprise customers were pushing for SBOMs and evidence of active remediation beyond a SOC 2 attestation.

The solution

Sublime adopted Chainguard Containers, integrating them via OpenID Connect and GitHub Actions so engineers could pick hardened base images from the catalog without routing through security for approval. The distroless images carry a smaller software surface, reducing the vulnerabilities inherited from upstream base layers.

The most measurable outcome has been a near 100% reduction in base image CVEs for teams that have adopted Chainguard internally.

AB
Andrew Becherer
Advisor, Sublime Security

The results, in context

Sublime reported a near 100% reduction in base image CVEs for teams that adopted Chainguard internally. Eliminating that workload freed at least 50% of the affected engineer's triage time for higher-value work, and the smaller software surface reduced false-positive scan alerts.

Products used

Chainguard Chainguard Containers