logo
Azul & Chainguard partner on zero-CVE Java containers

Azul & Chainguard partner on zero-CVE Java containers

Techday NZ19-06-2025

Azul and Chainguard have announced a partnership focused on strengthening container security for Java workloads through combined commercial Java support and secure container images.
The collaboration will see Chainguard create Java container images built from source, incorporating Azul's commercially supported build of OpenJDK from the Azul Platform Core. This approach is designed to allow enterprises to deliver production workloads more efficiently while addressing the complexities of securing the full software stack for Java applications.
Complexity in Java security
Java remains integral to a wide range of enterprise applications, with growing challenges around ensuring timely access to secure builds. Securing Java workloads requires reliable updates and consistent patching, traditionally necessitating expertise and timely intervention by vendors. Azul aims to fulfil this role by delivering fully supported OpenJDK builds intended as a direct replacement for Oracle Java, enabling organisations to maintain compliance and security while reducing expenditure and freeing development teams from remediation tasks.
Chainguard Containers supports customers by securing operating systems and application runtime environments. The combination targets gaps in current protection practices that too often see engineering and security teams handle numerous vulnerability disclosures, deal with inconsistent patching, and attempt to harden containers without slowing developer productivity. For Java workloads, which require both rapid security response and commercial support, these difficulties are particularly pressing.
Recent research from NetRise indicates that the average container carries 604 known vulnerabilities in underlying software components. Notably, over 45% of these CVEs are two to ten years old. This accumulation of unaddressed vulnerabilities increases risks for organisations that depend on containerised apps.
Findings from Azul's 2025 State of Java Survey & Report further highlight the impact of security issues. According to the report, 33% of respondents stated their DevOps teams spend more than half their time addressing false positives from Java-related vulnerabilities. Additionally, 49% of surveyed companies reported they are still encountering vulnerabilities from Log4j in production environments, nearly three years after the initial disclosure. The need to secure all layers, from operating systems to toolchains, forms a critical part of the software development lifecycle.
Hardened, zero-CVE Java containers
The partnership between Azul and Chainguard is positioned as a direct response to challenges identified by industry research. The joint offering will deliver zero-CVE containers for Java versions 21 and above, built from Azul's source code and supported commercially through Azul's Java expertise. Customers are expected to benefit from a streamlined way to secure Java application foundations, reducing overall risk exposure and enabling more consistent, reliable deployments.
The new container images will be constructed entirely from source and tested in accordance with the Java Compatibility Kit, providing assurance of compatibility and feature parity. Azul's approach to stabilised, security-only Critical Patch Updates gives engineering teams the opportunity to deploy updated Java images more efficiently, minimising manual patching and testing efforts. This is intended to help organisations redirect development resources away from platform maintenance and towards application delivery. "Our customers need solutions that reduce risk and build trust at every layer of their modern software deployment stack," said Dan Lorenc, co-founder and CEO at Chainguard. "Today, we're bringing Chainguard's expertise in building minimal, zero-CVE images and Azul's expertise in Java together to create the most secure, commercial-grade containers for cloud-native workloads."
Scott Sellers, co-founder and CEO at Azul, added: "Choosing a hardened container shouldn't mean sacrificing timely security-only updates and commercial support services for your Java runtimes. Today, we're excited to offer enterprises best-in-breed hardened Java containers from Chainguard while leveraging world-class commercial support from Azul."
Customers adopting Azul Java container images through Chainguard Containers will have access to commercial Java support within the Azul Platform Core portfolio. This ensures ongoing access to patches and direct assistance for Java runtime issues in critical enterprise environments.

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Java Independence is now a board-level priority - Driving cost savings, cloud efficiency and strategic agility
Java Independence is now a board-level priority - Driving cost savings, cloud efficiency and strategic agility

Techday NZ

time2 days ago

  • Techday NZ

Java Independence is now a board-level priority - Driving cost savings, cloud efficiency and strategic agility

Chances are every time you stream content, buy something online or check your bank balance, you're interacting with Java-based systems. Java powers mission-critical systems across industries. Netflix runs its entire streaming infrastructure on Java-based microservices, processing millions of concurrent viewers. Global payment networks validate credit card transactions in milliseconds across hundreds of countries using Java applications. While the Java community has expanded to over 10 million developers worldwide, enterprises face mounting cost pressures from multiple directions. For the enterprises powering these essential services, 2025 represents a critical decision point: continue paying escalating costs for Oracle Java, potentially impacting profit margins or customer pricing as well as the potential for future price hikes, or seek alternatives. Java independence gives businesses control, choice, and confidence in how they build and run Java applications. Azul's recent 2025 State of Java Survey & Report reveals an enterprise Java ecosystem in transition, driven by mounting cost concerns, market preference for open-source solutions, and ongoing uncertainty around Oracle's licensing policies. This watershed moment stems from Oracle's shift to employee-based pricing in January 2023, which fundamentally disrupted enterprise Java strategy. Oracle's licensing practices have significantly increased Java-related expenditures, with the company generating billions annually from Java licensing and support. This shift isn't just about cost savings, it's about mitigating risk and enhancing agility. Java independence has become a board-level priority in an era where digital transformation drives market leadership. The oracle Java challenge The new Oracle pricing model detaches Java costs from actual usage, creating an unsustainable scenario: a 10,000-employee company running a handful of Java applications pays the same as a similarly sized organisation running thousands of Java-based services. For global businesses, this represents both a financial challenge and a strategic imperative to maintain competitive advantage. Our research reveals that two-thirds of organisations found Oracle's licensing model more expensive than alternatives, and an overwhelming majority reported successful migrations away from Oracle Java. With 25% of companies citing audit risk as a key migration driver, the urgency to transition has become a business priority rather than just an IT concern. The OpenJDK success story The success of OpenJDK adoption has shattered Oracle Java migration concerns. The data tells a compelling story: 84% of companies found the transition easier than expected or as planned, with three-quarters completing migrations within 12 months. This rapid timeline reflects both the maturity of available solutions and the robust support ecosystem around OpenJDK migrations. OpenJDK distributions have emerged as preferred alternatives to Oracle Java. These enterprise-ready solutions match Oracle Java SE's core capabilities while offering enhanced support and performance options. Successful migration hinges on three key components: Organisational momentum - Technical expertise, discovery & inventory tools and project planning assistance from a commercial OpenJDK provider can significantly help secure and maintain executive support, ultimately impacting a successful transition. Comprehensive Java mapping - Identifying all Java deployments across an organisation is essential. With 83% of organisations requiring commercially supported Java in production, this mapping phase is critical. Governance and compliance - Maintaining independence from Oracle Java licensing requires robust governance. Success means partnering with OpenJDK providers offering comprehensive protection, from IP safeguards to indemnification. The immediate financial benefits are substantial — most organisations report a 50-70% reduction in Oracle Java-related costs. Perhaps even more compelling, additional value lies in regaining control over Java technology strategy. Cloud cost optimisation Organisations are grappling with rapidly escalating cloud infrastructure costs, as annual global cloud spending is nearing a trillion dollars and continues to grow at double-digit rates. Our research reveals that 71% of organisations overpay for cloud compute capacity, highlighting an opportunity to reduce costs while improving application performance. Companies that select non-Oracle optimised Java platforms can save 20%+ on cloud computing costs. This is because high-performance Java runtimes deliver more stable Java applications and infrastructure while consuming fewer computing resources, creating compelling advantages beyond just licensing considerations. Powering AI innovation with Java Emerging technology demands amplify the need for change, particularly in AI and cloud computing. Half of the surveyed companies from our State of Java report already build AI functionality using Java — from financial institutions developing fraud detection systems to retailers leveraging machine learning for customer personalisation and inventory management. As computational demands grow, organisations require Java platforms that can deliver both performance and efficiency. These advanced workloads highlight the need for solutions that provide more scalable and stable applications while consuming fewer computing resources, enabling AI initiatives to be deployed successfully without excessive infrastructure investments. Oracle Java independence is not just a technical evolution — it's a strategic imperative that gives organisations the freedom to innovate, control costs, and build their technology future on their own terms.

Azul & Chainguard partner on zero-CVE Java containers
Azul & Chainguard partner on zero-CVE Java containers

Techday NZ

time19-06-2025

  • Techday NZ

Azul & Chainguard partner on zero-CVE Java containers

Azul and Chainguard have announced a partnership focused on strengthening container security for Java workloads through combined commercial Java support and secure container images. The collaboration will see Chainguard create Java container images built from source, incorporating Azul's commercially supported build of OpenJDK from the Azul Platform Core. This approach is designed to allow enterprises to deliver production workloads more efficiently while addressing the complexities of securing the full software stack for Java applications. Complexity in Java security Java remains integral to a wide range of enterprise applications, with growing challenges around ensuring timely access to secure builds. Securing Java workloads requires reliable updates and consistent patching, traditionally necessitating expertise and timely intervention by vendors. Azul aims to fulfil this role by delivering fully supported OpenJDK builds intended as a direct replacement for Oracle Java, enabling organisations to maintain compliance and security while reducing expenditure and freeing development teams from remediation tasks. Chainguard Containers supports customers by securing operating systems and application runtime environments. The combination targets gaps in current protection practices that too often see engineering and security teams handle numerous vulnerability disclosures, deal with inconsistent patching, and attempt to harden containers without slowing developer productivity. For Java workloads, which require both rapid security response and commercial support, these difficulties are particularly pressing. Recent research from NetRise indicates that the average container carries 604 known vulnerabilities in underlying software components. Notably, over 45% of these CVEs are two to ten years old. This accumulation of unaddressed vulnerabilities increases risks for organisations that depend on containerised apps. Findings from Azul's 2025 State of Java Survey & Report further highlight the impact of security issues. According to the report, 33% of respondents stated their DevOps teams spend more than half their time addressing false positives from Java-related vulnerabilities. Additionally, 49% of surveyed companies reported they are still encountering vulnerabilities from Log4j in production environments, nearly three years after the initial disclosure. The need to secure all layers, from operating systems to toolchains, forms a critical part of the software development lifecycle. Hardened, zero-CVE Java containers The partnership between Azul and Chainguard is positioned as a direct response to challenges identified by industry research. The joint offering will deliver zero-CVE containers for Java versions 21 and above, built from Azul's source code and supported commercially through Azul's Java expertise. Customers are expected to benefit from a streamlined way to secure Java application foundations, reducing overall risk exposure and enabling more consistent, reliable deployments. The new container images will be constructed entirely from source and tested in accordance with the Java Compatibility Kit, providing assurance of compatibility and feature parity. Azul's approach to stabilised, security-only Critical Patch Updates gives engineering teams the opportunity to deploy updated Java images more efficiently, minimising manual patching and testing efforts. This is intended to help organisations redirect development resources away from platform maintenance and towards application delivery. "Our customers need solutions that reduce risk and build trust at every layer of their modern software deployment stack," said Dan Lorenc, co-founder and CEO at Chainguard. "Today, we're bringing Chainguard's expertise in building minimal, zero-CVE images and Azul's expertise in Java together to create the most secure, commercial-grade containers for cloud-native workloads." Scott Sellers, co-founder and CEO at Azul, added: "Choosing a hardened container shouldn't mean sacrificing timely security-only updates and commercial support services for your Java runtimes. Today, we're excited to offer enterprises best-in-breed hardened Java containers from Chainguard while leveraging world-class commercial support from Azul." Customers adopting Azul Java container images through Chainguard Containers will have access to commercial Java support within the Azul Platform Core portfolio. This ensures ongoing access to patches and direct assistance for Java runtime issues in critical enterprise environments.

Azul boosts Java security with improved runtime vulnerability detection
Azul boosts Java security with improved runtime vulnerability detection

Techday NZ

time13-06-2025

  • Techday NZ

Azul boosts Java security with improved runtime vulnerability detection

Azul has introduced enhanced vulnerability detection capabilities to its Intelligence Cloud that aim to reduce false positives and improve the accuracy of identifying Java application security risks. The company's updated solution, called Azul Vulnerability Detection, now uses class-level production runtime data to detect known vulnerabilities within Java applications. This approach contrasts with conventional application security (AppSec) and application performance monitoring (APM) tools, which often flag vulnerabilities based on component file names or software bill of materials (SBOM) data. Such traditional practices can generate a large volume of false positives, which the company asserts unnecessarily divert DevOps teams' time and effort. Based on findings from the Azul 2025 State of Java Survey & Report, a significant proportion of organisations are affected by this problem, with 33% indicating that more than half of their DevOps teams' time is spent addressing false positives related to Java Common Vulnerabilities and Exposures (CVEs) alerts. The broad-brush flagging approach, which does not distinguish between components actually used in production and those simply present, can result in alerts for unused or non-critical vulnerabilities. Azul's approach leverages data from Java application production environments to establish whether vulnerable classes in a component are executed, rather than simply existing as part of a packaged file. The company claims this refinement enables the solution to eliminate up to 99% of false positives, translating to a potential 100 to 1,000 times reduction compared to earlier detection methods. The technical approach The solution operates by applying a curated knowledge base that maps CVEs to individual Java classes used at runtime. By examining actual code paths executed in live environments, the system can determine whether a flagged vulnerability is relevant and warrants example cited is CVE-2024-1597, which affects specific versions of the PostgreSQL Java Database Connectivity (JDBC) driver. This high-severity vulnerability, which scores 9.8 out of 10 on the Common Vulnerability Scoring System (CVSS), can only be exploited when the driver is used in a particular non-default configuration. Conventional tools issue alerts if the driver is present in the application package, regardless of how it is used, contributing to unnecessary remediation efforts. Azul's detection mechanism discerns whether any of the 11 susceptible classes out of 470 in the component are used, thereby reducing irrelevant alerts. Key benefits According to Azul, the Intelliigence Cloud's Vulnerability Detection capability provides several benefits to enterprises managing extensive Java estates. These include continuous, real-time detection of vulnerabilities in production environments, which helps teams rapidly triage and prioritise critical issues in high-stakes scenarios like the Log4j vulnerability event. The platform retains both real-time and historical data on component and code use, using AI methods to focus forensic investigations on vulnerabilities actively exploited prior to their discovery. Azul's vulnerability team updates the system's knowledge base with newly identified CVEs, using AI to monitor sources such as the National Vulnerabilities Database (NVD) and other repositories. The runtime data collection works across Oracle JDK as well as any OpenJDK-based Java Virtual Machine (JVM), providing flexibility for organisations using a range of Java distributions, including those from Amazon, Temurin, Microsoft, and Red Hat. Azul states that this data-gathering incurs no impact on production system performance, as it leverages information already generated by the JVM during application execution. "The improved Vulnerability Detection features strengthen the proposition of Azul's Intelligence Cloud analytics SaaS offering as a way to increase DevOps productivity and recover developer capacity by reducing the need for full-time employee time spent wasted on security false positives and inefficient triage," said William Fellows, research director at 451 Research, part of S&P Global Market Intelligence. Company statement "Our mission is to help enterprises focus their security efforts on what matters - real risk, not noise," said Scott Sellers, co-founder and CEO of Azul. "By eliminating up to 99% of false positives and pinpointing vulnerabilities in Java applications with 100x – 1000x greater accuracy than traditional tools, Azul Intelligence Cloud enables capacity recovery across DevOps and security teams. As a result, teams can dramatically reduce noise, prioritise real risk and accelerate remediation - all with zero impact to performance and without slowing innovation." Azul's enhancements to its Intelligence Cloud are positioned to address long-standing productivity challenges faced by DevOps teams handling Java application security, particularly the time lost to managing irrelevant or inaccurate alerts.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store