
Propio trusts Chainguard to prevent AI-driven supply chain attacks
The challenge
Like almost every company using open source today, Propio Language Services struggled to keep pace with an ever-growing wave of AI-driven supply chain attacks. According to Kevin Fuller, CISO at Propio, the team was constantly identifying and responding to new threats, which made proactive security nearly impossible and took time away from planned product work.
“CVEs were out of control,” said Donnie Dooley, CTO. “They were running rampant. They weren't being managed to the SLAs that we had stated.” At one point, roughly 20% of engineering capacity was dedicated solely to CVE management rather than building the product.
For the Propio team, the risk and subsequent security-oriented work started with containers, but didn’t end there. Kevin explained, “Containers and libraries have both kept me up at night trying to identify what we need to deal with.”
Kyle Vanderbilt, Director of Platform Engineering, described the sharpening urgency around libraries: “The Axios supply chain attack is what prompted our interest in Chainguard Libraries. It was surprising to us that a library that's used by millions of developers around the world was attacked and had such a broad impact.”
The team considered managing remediation in-house, but the effort was overwhelming. They needed to look to the market to bring on a vendor that would reduce CVE volume without new operational burdens.
The solution
The Propio team was looking for a few key capabilities: a drastic reduction in CVEs out of the box, protection against malware and supply chain attacks, and a way to reduce the manual security burden for internal teams.
While the team started with Chainguard Containers for the immediate reduction in CVEs, CVE remediation alone wasn’t enough. Propio then turned its attention to the open source dependencies powering its applications, adopting Chainguard Libraries for JavaScript, with plans to extend coverage to additional languages over time. For Donnie, having the two products working in tandem was essential for addressing the exposure across the platform.
The rollout moved quickly, with Propio’s platform engineering team getting two services running in their dev environment within days, and the first services in production within a few weeks. Because Chainguard integrated directly into Propio’s existing GitLab registry and CI/CD pipelines, the switch required minimal disruption to development teams, who simply needed to update their base images. As Donnie shared, "Propio's implementation with Chainguard Containers has been the best integration that we've done as a technology company."
The results
Container security that fuels development velocity
Since implementing Chainguard Containers, Propio has seen its CVEs drop from thousands to near zero almost overnight, a reduction that has translated directly into product feature enhancements rather than time spent on CVE remediation.
Extended prevention to the dependencies layer
Chainguard Libraries gives Propio’s team the ability to code in JavaScript without bringing on the malware risk that’s plagued npm. "With Chainguard Libraries, I'm looking forward to being able to sleep at night and not have to worry about the ongoing malware supply chain attacks," Kyle said.
Kevin sees Chainguard as driving the shift from reactive detection to proactive prevention across containers and libraries. "We have immediate visibility to that now, but more important than that, it's a preventative capability. So it's not just detection, it's prevention. And that has given us a world of peace."