Joint Customers Can Now Utilize RapidFort Leading Set of Curated Hardened Container Images, Enriching CVE Findings from Wiz with RapidFort Evidence-Backed Advisories and Direct Path to Near-Zero CVE Remediation
RapidFort, the leader in Software Supply Chain Security (SSCS) with the largest distribution of curated truly open-source software, today announced interoperability with Wiz, a leading cloud and AI security platform that’s now part of Google Cloud. With this integration, joint customers can now scan and identify RapidFort industry-largest set of curated and hardened images for the presence of CVEs, and leverage RapidFort advisory-backed remediation status alongside those findings – without leaving the Wiz platform or changing how they scan today.
“We’re happy to welcome RapidFort to the Wiz Integration Network,” said Oron Noah, VP of Product, Extensibility and Partnerships at Wiz. “Managing cloud vulnerabilities isn’t just about identifying risk, it’s about making remediation as seamless as possible. By surfacing RapidFort advisory feed directly within the Wiz platform, we’re helping joint customers clear out false positives and fix CVEs quickly.”
While Wiz identifies CVEs across cloud and container estates, this integration provides joint customers with a streamlined remediation path. When a CVE finding touches a RapidFort-curated or -hardened image, Wiz surfaces RapidFort advisory context, and the near-zero CVE curated equivalent is available as a direct, typically one-line, remediation. RapidFort curated images retain the same OS, language stack, size, and version tags Wiz customers already use. Its advisory determinations are backed by primary sources and applied consistently across scanners, which gives Wiz customers a documented reason for each false-positive determination rather than a black-box suppression.
“This important integration extends the stated scanner-agnostic strategy of RapidFort into a named, directory-listed partnership with one of the most prominent players in the category,” said George Manuelian, Chief Strategy Officer at RapidFort. “Joint Wiz customers can now spend fewer hours triaging CVEs that were never exploitable in the first place, and have a documented remediation path the moment a real CVE is found, all inside the scanning tool they already run. Now they do not have to choose between their existing scanner investment and adopting a near-zero CVE image supply chain – these two solutions now work together natively.”
Joint customers can now leverage RapidFort industry-leading vulnerability remediation.
- RapidFort is the only curated-image distributor that supports all major LTS OS releases in one catalog (Ubuntu, Debian, Red Hat/UBI, and Alpine) rather than standardizing customers onto a single distribution.
- RapidFort Curated Images retain the joint customer existing OS, size, and version tags, as a drop-in replacement for CVE remediation not a migration; customers change a FROM line rather than re-platforming. This lowers total cost of ownership and removes the main adoption barrier for both developers (no re-testing a new base) and security teams (no new tooling to learn).
- RapidFort Advisory determinations are evidence-backed (NVD, distro trackers, upstream commits) and apply consistently regardless of which scanner reported the finding.
- RapidFort publishes a patch-time SLA once an upstream fix exists: Seven calendar days for Critical/High, 21 for Medium, 28 for Low.
- RapidFort images are DISA STIG-verified and support full FIPS 140-3 requirements.
For partners building on or alongside RapidFort, this latest integration is a proof point that RapidFort advisory feeds and RapidFort curated catalogs are designed to plug into the tools partners already provide, rather than requiring a closed, single-vendor stack.
Availability
The RapidFort and Wiz integration is currently available and listed live today in the Wiz Integrations directory. For more information visit https://www.wiz.io/integrations?q=rapidfort.
About RapidFort
RapidFort leads the Software Supply Chain Security market with the largest distribution of curated, genuinely open-source software. Its platform enables organizations to eliminate risk at scale through hardened near-zero CVE container images, runtime profiling, attack surface management, and the industry’s first independently malware-scanned open-source images – cutting CVE exposure by up to 99.9% without code changes or platform migration. RapidFort is recognized in the inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security, named a Gartner® Cool Vendor™, and honored as a Nutanix .Next Partner of the Year. The company is backed by Blue Cloud Ventures and Forgepoint Capital and headquartered in Sunnyvale, Calif. Visit www.RapidFort.com.
RapidFort, RAPIDFORT, and RBOM are registered trademarks of RapidFort, Inc. All other marks and names mentioned herein may be trademarks of their respective companies.
View source version on businesswire.com: https://www.businesswire.com/news/home/20261001673190/en/
Joint RapidFort and Wiz customers can now utilize RapidFort leading set of curated hardened container images, enriching CVE findings from Wiz with RapidFort evidence-backed advisories and direct path to near-zero CVE remediation.
Contacts
Dan Spalding
dan.spalding@rapidfort.com
(408) 960-9297