# Chainguard Products Changelog

URL: https://deploy-preview-3613--ornate-narwhal-088216.netlify.app/chainguard/changelog.md
Last Modified: July 28, 2026
Tags: Chainguard Containers, Changelog

Weekly changelog of Chainguard product updates — product announcements, breaking changes, container images reaching end-of-life or leaving the catalog, and images newly added to it.

This page logs Chainguard product updates week by week, newest first: product announcements, breaking changes, container images that reached end-of-life or are no longer available, and images newly added to the catalog. Each event is listed once, in the week it first appeared.
Week of 2026-08-03 Breaking Changes ingress-nginx-controller entrypoint, command, and default user changes Effective July 15, 2026.
Chainguard aligned the entrypoint and command behavior of all supported ingress-nginx-controller images with the upstream image, correcting a startup configuration defect present since the image was first published in 2024. Non-iamguarded variants also changed their default runtime user from root (UID 0) to www-data (UID 101).
Affected: all supported ingress-nginx-controller images, including FIPS and -iamguarded variants. Action: review any configuration that overrides command, args, entrypoint, or runAsUser, or that depends on admission policies or file ownership assumptions. Deployments using the upstream Helm chart defaults need no changes. EOL Chainguard offers a grace period for eligible end-of-life images: up to six months of continued rebuilds and security updates while you complete your upgrade.
Images that are no longer available The following container images reached the end of their grace period and are no longer available:
Image End-of-life Grace period ended cilium:1.16 2026-02-03 2026-08-03 neo4j:2025.12 2026-02-03 2026-08-03 Images that have reached end-of-life The following container images reached end-of-life and entered their grace period:
Image End-of-life Grace period ends eks-distro:1.33 2026-07-29 2027-07-29 mongo:8.2 2026-07-31 2027-01-31 prometheus:3.5 2026-07-31 2027-01-31 cockroach:26.1 2026-08-02 2027-02-02 cockroach-openssl:26.1 2026-08-02 2027-02-02 New Images Chainguard built 22 new container images this week, including both standard and FIPS variants.
ImageTierAdded glabapplication +fips2026-07-27 metabaseapplication2026-07-27 atlasapplication +fips2026-07-29 azure-metrics-exporterapplication +fips2026-07-29 crossplane-azure-solutionsapplication2026-07-29 crossplane-azure-streamanalyticsapplication2026-07-29 crossplane-azure-webapplication2026-07-29 dns-controller-managerapplication +fips2026-07-29 instrumentisto-harakaapplication +fips2026-07-29 openstack-kolla-toolboxapplication +fips2026-07-29 sftpgoapplication2026-07-29 flink-kubernetes-operator-fipsfips2026-07-30 traccarapplication +fips2026-07-30 metacontroller-fipsfips2026-07-31 chainguard-desktop-workstation-rpibase2026-08-01 Week of 2026-07-28 Product Announcements SUSE NeuVector now natively supports Chainguard Containers Launched July 24, 2026.
SUSE&rsquo;s NeuVector vulnerability scanner now natively supports Chainguard Containers and ingests Chainguard&rsquo;s OSV advisory feed, which includes recent data-quality improvements. Scans of Chainguard images suppress false positives and report more accurate results.
Group-based role mapping is now generally available Launched July 22, 2026.
Administrators can map identity provider groups — Okta or Microsoft Entra ID, for example — directly to Chainguard roles, instead of assigning roles one user at a time. Anyone who authenticates with a mapped group in their token receives that role for the session.
For more information, including setup steps, refer to Grant Chainguard Roles from Identity Provider Groups.
EOL Chainguard offers a grace period for eligible end-of-life images: up to six months of continued rebuilds and security updates while you complete your upgrade.
Images that are no longer available The following container images reached the end of their grace period and are no longer available:
Image End-of-life Grace period ended knative-eventing:1.19 2026-01-28 2026-07-28 knative-serving:1.19 2026-01-28 2026-07-28 net-kourier:1.19 2026-01-28 2026-07-28 Images that have reached end-of-life The following container images reached end-of-life and entered their grace period:
Image End-of-life Grace period ends dnsdist:1.9 2026-07-21 2027-01-21 longhorn-backing-image-manager:1.8 2026-07-22 2027-01-22 longhorn-instance-manager:1.8 2026-07-22 2027-01-22 envoy:1.35 2026-07-23 2027-01-23 New Images Chainguard built 16 new container images this week, including both standard and FIPS variants.
ImageTierAdded coderapplication +fips2026-07-22 flink-kubernetes-operatorapplication2026-07-22 pgheroapplication +fips2026-07-22 kargoapplication2026-07-23 nuclio-controllerapplication +fips2026-07-23 phpmyadminapplication +fips2026-07-23 apache-exporter-iamguardedapplication2026-07-24 rpi-server-bootcbase2026-07-25 glabapplication +fips2026-07-27 metabaseapplication2026-07-27 crossplane-azure-relayapplication2026-07-28 
