Software security teams can face an overwhelming influx of vulnerability alerts, often stemming from non-essential packages bundled inside traditional container base images. When developers inherit base images packed with unneeded tools, shells, and package managers, security teams end up triaging noise, and developers end up burdened with Common Vulnerabilities and Exposures (CVE) remediations. To ease this friction and help organizations move toward a zero-CVE strategy, container infrastructure requires a purpose-built starting point that cuts away unnecessary attack surface from day one.

To address this challenge and strengthen defense-in-depth across the hybrid cloud, support for Red Hat Hardened Images is live in the AWS InspectorScan API and ECR Basic scanning. By further expanding Red Hat’s collaboration with AWS, we’re delivering a smoother way to verify software supply chain integrity and maintain cleaner security profiles directly within native AWS workflows. Red Hat Hardened Images and AWS scanning gives security and developer teams the flexibility to choose the technology that best fits their project's needs, while strengthening security standards.

Red Hat Hardened Images is a catalog of essential container images built for deployment across vendor-agnostic infrastructure, containing only the specific files required for an application to run. Built using Red Hat’s trusted software pipeline, these pre-hardened images are rigorously tested for operational functionality and optimized to mitigate as many known security vulnerabilities as possible at release. By removing unnecessary software that increases attack surface and security noise, this minimalist approach provides a purpose-built path toward a zero-CVE environment.

Red Hat’s collaboration with AWS addresses the unique needs of both security engineers and developers. Security engineers benefit from a secure-by-default posture, cleaner security scans, faster CVE remediations, and standardized security profiles that support compliance certifications like CIS, STIG, and OpenSCAP. Developers gain freedom of choice across components and versions, easier adoption through drop-in compatibility, and comprehensive documentation. Amazon ECR Basic scanning is built-in vulnerability detection for container images stored in Amazon Elastic Container Registry (ECR).