<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[BIMP]]></title><description><![CDATA[The Base Image Management Platform. Secure your container base images today. Be zero-day ready tomorrow. ]]></description><link>https://blog.bimp.ai</link><image><url>https://substackcdn.com/image/fetch/$s_!YTMB!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2845e186-89a3-48d8-828b-8c6c6543d90c_1280x1280.png</url><title>BIMP</title><link>https://blog.bimp.ai</link></image><generator>Substack</generator><lastBuildDate>Wed, 06 May 2026 03:45:43 GMT</lastBuildDate><atom:link href="https://blog.bimp.ai/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Kortensia Ltd]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[bimp@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[bimp@substack.com]]></itunes:email><itunes:name><![CDATA[Hannah Foxwell]]></itunes:name></itunes:owner><itunes:author><![CDATA[Hannah Foxwell]]></itunes:author><googleplay:owner><![CDATA[bimp@substack.com]]></googleplay:owner><googleplay:email><![CDATA[bimp@substack.com]]></googleplay:email><googleplay:author><![CDATA[Hannah Foxwell]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[How We Built BIMP]]></title><description><![CDATA[What did we learn building at the speed of AI?]]></description><link>https://blog.bimp.ai/p/how-we-built-bimp</link><guid isPermaLink="false">https://blog.bimp.ai/p/how-we-built-bimp</guid><dc:creator><![CDATA[Hannah Foxwell]]></dc:creator><pubDate>Sat, 21 Mar 2026 18:15:14 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!xSQD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F069984b9-915c-481f-b865-f84c34d521e9_2816x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>This blog post will disappoint some of you. Hopefully it will also inspire some of you.</p><p>BIMP was not vibe coded.</p><p>BIMP was not built by a swarm of autonomous agents.</p><p>BIMP was built by us, Hannah Foxwell and Stuart Preston. Two smart people and some AI tools.</p><p>This post aims to condense some of the things we learned through this process.</p><h1>Reimagining Product Development</h1><p>We started this project with two goals:</p><ul><li><p>Build something worth building</p></li><li><p>Build at the speed of AI</p></li></ul><p>We wanted to move quickly but even we were surprised by the speed we were able to build.</p><p>Over morning coffee we chat about what we have planned for the day, then we do those things. We introduced as little process as possible.</p><p>There was no roadmap, no backlog, no stories, no tickets. We aligned on our plans for the day, made decisions about scope and discussed implementation options. Our discussion was transcribed and documented for us by our custom AI tools.</p><p>On the first day of the BIMP build we smashed through our goals for the day in a couple of hours. We were able to authenticate using google, we&#8217;d built a GitHub app, connected BIMP to a GitHub organisation, selected a repo, scanned a repo for Dockerfiles and opened a pull request on the Dockerfile in that repo.</p><p>The same happened on day two. We wanted to create a policy file that dictated what the <code>FROM</code>: line in the Dockerfile should say and open a Pull Request to replace the current base image with an updated base image.</p><p><em>If you want to learn more about what BIMP actually does you can read more in the post &#8220;What is BIMP?&#8221;</em></p><p>Hannah received a video demo from Stuart at 12pm while standing on the train station platform in York. Job done by lunchtime. Is this&#8230; is this&#8230; an MVP?!</p><p>On days like that you start to dream about a future where you can log off at lunchtime every day. What would life look like if we made a choice to organise ourselves in that way? What if we set a goal for the day, deliver it, and logged off?</p><h2>What we learned</h2><ul><li><p>A two week sprint is insanity in 2026, a day of work for one developer was hard enough to scope</p></li><li><p>Many of the practices we use to manage priorities are redundant - tickets, backlogs, user story maps etc. It&#8217;s more important to identify dependencies and work through the tasks in a logical order</p></li><li><p>We learned to be ambitious and aim higher. We might have delivered an MVP in 2 days but we didn&#8217;t stop at an MVP, we wanted to deliver a MEP &#8220;Minimal Enterprise Product&#8221;</p></li></ul><h1>User Empathy Is Everything</h1><p>Building is only fast if you know what you need to build. Luckily both Hannah and Stuart have spent their careers building enterprise platforms and driving technology transformation.</p><p>It is what we do. We are very good at it.</p><p>The difference this makes to velocity can&#8217;t be underestimated. Instead of waiting for user research or beta testers both of us understood the users&#8217; needs instinctively.</p><blockquote><p>&#8220;No, this will piss off everyone involved, we need to make this invisible.&#8221; - Hannah</p></blockquote><p>Despite this we didn&#8217;t want to blindly trust our assumptions. Hannah conducted user interviews with real people with real problems (I&#8217;m sorry you&#8217;re stuck on Node 8 dude). This revealed our blind spots and immediately made the product better.</p><p>Based on our user research we added two new personas to our product. The Engineering Director who wants to know how their team is doing and the AI Agent who wants to deliver work reliably but doesn&#8217;t know the organisation policy.</p><h2>What can you do</h2><ul><li><p>Consider moving your engineers closer to users, whether that be in partnership with product or with support teams. Forward Deployed Engineers and Product Engineers are becoming popular for a reason!</p></li><li><p>Forget the &#8220;ship and switch&#8221;. This is the practice where teams ship v1 of a feature and move to the next. Feedback and iteration with real users is gold dust and turns a product from a nice idea to something that people love.</p></li><li><p>Prioritise visibility and distribution before you need it. On day 2 of the project Hannah started outreach, uncomfortably early for Stuart. We launch the product today with a healthy waitlist of potential customers - talking to them will help us improve and we&#8217;ll get better faster regardless of whether they decide to buy.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xSQD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F069984b9-915c-481f-b865-f84c34d521e9_2816x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xSQD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F069984b9-915c-481f-b865-f84c34d521e9_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!xSQD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F069984b9-915c-481f-b865-f84c34d521e9_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!xSQD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F069984b9-915c-481f-b865-f84c34d521e9_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!xSQD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F069984b9-915c-481f-b865-f84c34d521e9_2816x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xSQD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F069984b9-915c-481f-b865-f84c34d521e9_2816x1536.png" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/069984b9-915c-481f-b865-f84c34d521e9_2816x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:8247653,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://blog.bimp.ai/i/191694682?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F069984b9-915c-481f-b865-f84c34d521e9_2816x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xSQD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F069984b9-915c-481f-b865-f84c34d521e9_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!xSQD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F069984b9-915c-481f-b865-f84c34d521e9_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!xSQD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F069984b9-915c-481f-b865-f84c34d521e9_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!xSQD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F069984b9-915c-481f-b865-f84c34d521e9_2816x1536.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>Create The Tools You Need As You Need Them</h1><p>We are bootstrapping. That means we don&#8217;t want to splurge on tools before we&#8217;ve tested our ideas.</p><p>Keeping things lean we have started to build the tools we need as we need them. We built an assistant called Otis who listens to our meetings, provides summaries and learns about our company over time - offering insights and reminding us about tasks.</p><p>Otis is our wise owl. We love him.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hKDO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb8cae95-f586-4718-b9ca-d118f096ca4c_8192x4104.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hKDO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb8cae95-f586-4718-b9ca-d118f096ca4c_8192x4104.png 424w, https://substackcdn.com/image/fetch/$s_!hKDO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb8cae95-f586-4718-b9ca-d118f096ca4c_8192x4104.png 848w, https://substackcdn.com/image/fetch/$s_!hKDO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb8cae95-f586-4718-b9ca-d118f096ca4c_8192x4104.png 1272w, https://substackcdn.com/image/fetch/$s_!hKDO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb8cae95-f586-4718-b9ca-d118f096ca4c_8192x4104.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hKDO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb8cae95-f586-4718-b9ca-d118f096ca4c_8192x4104.png" width="1456" height="729" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/db8cae95-f586-4718-b9ca-d118f096ca4c_8192x4104.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:729,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3538096,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://bimpai.substack.com/i/191694682?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb8cae95-f586-4718-b9ca-d118f096ca4c_8192x4104.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hKDO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb8cae95-f586-4718-b9ca-d118f096ca4c_8192x4104.png 424w, https://substackcdn.com/image/fetch/$s_!hKDO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb8cae95-f586-4718-b9ca-d118f096ca4c_8192x4104.png 848w, https://substackcdn.com/image/fetch/$s_!hKDO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb8cae95-f586-4718-b9ca-d118f096ca4c_8192x4104.png 1272w, https://substackcdn.com/image/fetch/$s_!hKDO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb8cae95-f586-4718-b9ca-d118f096ca4c_8192x4104.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>His insights include:</p><ul><li><p>&#8220;The Hoot&#8221; - The headlines of the day</p></li><li><p>&#8220;The Perch&#8221; - Key topics covered</p></li><li><p>&#8220;The Hunt&#8221; - Action Items</p></li><li><p>&#8220;Otis&#8217;s Insights&#8221; - A reflection on how things are going</p></li><li><p>&#8220;The Screech&#8221; - Otis reminding us to do things</p></li></ul><p>Our assistant Otis has so much potential to help us streamline our operation. We will continue to evolve our internal toolkit with personality, flare and fun.</p><blockquote><p>&#8220;My head is exploding with ideas and things I want to build. It&#8217;s like every project leads to more ideas and more projects &#8230; and I can try them out in just a couple of hours on the sofa. I can&#8217;t stop!&#8221; - Stuart</p></blockquote><p>Work should be joyful and we have an opportunity to create a work life that is whimsical and fun.</p><p>A whimsical and fun cyber security company. What a thing that would be.</p><h1>Building Has Never Been More Fun</h1><p>We have had so much fun building BIMP. Building has never been so much fun.</p><p>Sure, it would be nice if we found some users, it would be even nicer if BIMP made the world more secure. What a thing that would be. But we&#8217;re not interested if it&#8217;s not fun. We&#8217;re not interested if it&#8217;s not joyful.</p><p>Our home page has a 3D model of a blimp souring in a 3D space. This was not required but it was bloody fun.</p><p>What a time to be alive. Get building. That&#8217;s it.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.bimp.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">We&#8217;ll be sharing our journey here as we build BIMP. Subscribe to stay up to date!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[What is BIMP?]]></title><description><![CDATA[The Base Image Management Platform]]></description><link>https://blog.bimp.ai/p/what-is-bimp</link><guid isPermaLink="false">https://blog.bimp.ai/p/what-is-bimp</guid><dc:creator><![CDATA[Hannah Foxwell]]></dc:creator><pubDate>Sat, 21 Mar 2026 18:03:03 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!5FEK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9177635c-faac-45a4-8d2a-cb0b8feeb3dd_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h1>Introducing BIMP</h1><p>Say hello to BIMP!</p><p>BIMP is a Base Image Management Platform. It&#8217;s a platform that you can use to manage your base images. Simple right? So why hasn&#8217;t anyone built this before?</p><p>If you&#8217;re building your applications as containers then you will no doubt be familiar with the Dockerfile. Imperfect as they are, they are the default format for building container images. The Dockerfile includes the configuration for the containers base image - the base layer on top of which you add your application and its dependencies.</p><p>The <code>FROM:</code> line in your Dockerfile is one of the most important interfaces of your software supply chain. The base image you select in that <code>FROM: </code>line is the gateway through which reams of Open Source Software enters your organisation. If any one of those packages is vulnerable your container is vulnerable.</p><p>Most companies have a policy here, they want developers to build their containers from a secure base image, a base image procured from a reputable supplier who provides SLAs and commitments on vulnerability patches.</p><p>All you need to do is select the right base image provider for you, and then make sure every  <code>FROM:</code> line in every Dockerfile in every repo is kept up to date continuously. It&#8217;s not enough to select a secure base image today, you must keep that base image up to date constantly to ensure all new CVEs are fixed in a timely way.</p><p>BIMP automates this process end to end, putting base image CVE remediation on auto-pilot.</p><p>BIMP does this by ingesting your approved base image catalogue and then opening a pull request on every Dockerfile in every repo automatically.</p><h1>The Gap</h1><p>Most teams we&#8217;ve spoken to simply don&#8217;t update their base images, leaving them more and more vulnerable over time.</p><p>The problem is not technical. Updating a single line in a single file is not difficult. A single action could remediate tens, if not hundreds, of vulnerabilities. The problem is an organisational one.</p><p>The <strong>Development Team</strong> creates a Dockerfile, selects a base image and hooks it up to their build process. That is how it remains until someone (usually security) asks them to update it.</p><p>The <strong>Security Team </strong>is overwhelmed by risk signals, including vulnerability data from their chosen container scanner. They have to triage and prioritise those risks. They know what the fix is, but to make the fix they need to track down the right team and update the right file.</p><p>And this needs to happen continuously. There were over 48k new CVEs discovered in 2025 alone.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!acRY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb799b601-af21-4126-8cd3-42915143fea8_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!acRY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb799b601-af21-4126-8cd3-42915143fea8_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!acRY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb799b601-af21-4126-8cd3-42915143fea8_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!acRY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb799b601-af21-4126-8cd3-42915143fea8_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!acRY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb799b601-af21-4126-8cd3-42915143fea8_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!acRY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb799b601-af21-4126-8cd3-42915143fea8_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b799b601-af21-4126-8cd3-42915143fea8_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1181740,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://bimpai.substack.com/i/191693093?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb799b601-af21-4126-8cd3-42915143fea8_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!acRY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb799b601-af21-4126-8cd3-42915143fea8_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!acRY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb799b601-af21-4126-8cd3-42915143fea8_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!acRY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb799b601-af21-4126-8cd3-42915143fea8_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!acRY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb799b601-af21-4126-8cd3-42915143fea8_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>The <strong>Platform Team</strong> is curating a Golden Image catalogue of approved base images. They have worked with Security to select the right supplier and then they may have customised those purchased images ready to be used. They have told all of the Development Teams they support where to get the images, but they don&#8217;t know if every team has complied (and they suspect that many of the images have become insecure over time).</p><p>The solution is BIMP. A Base Image Management Platform. A Platform that makes Base Image Management completely automatic.</p><h1>How Does BIMP Work?</h1><h3>Platform</h3><p>The Platform Team curates their approved base image catalog once. They set the policy in BIMP and let our platform cascade updates to every Dockerfile in every repo with a ready-to-merge pull request.</p><h3>Developers</h3><p>When it&#8217;s time to update their base image BIMP creates a PR on the Dockerfile. The Dev Team can simply merge and move on, never leaving their workflow.</p><h3>Security</h3><p>BIMP eliminates friction and puts base image remediation on autopilot. Security can be confident that all vulnerabilities discovered in the base image layer will be remediated automatically without them having to do any chasing at all. They are free to focus on other risks.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5FEK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9177635c-faac-45a4-8d2a-cb0b8feeb3dd_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5FEK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9177635c-faac-45a4-8d2a-cb0b8feeb3dd_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!5FEK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9177635c-faac-45a4-8d2a-cb0b8feeb3dd_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!5FEK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9177635c-faac-45a4-8d2a-cb0b8feeb3dd_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!5FEK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9177635c-faac-45a4-8d2a-cb0b8feeb3dd_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5FEK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9177635c-faac-45a4-8d2a-cb0b8feeb3dd_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9177635c-faac-45a4-8d2a-cb0b8feeb3dd_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:825815,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://bimpai.substack.com/i/191693093?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9177635c-faac-45a4-8d2a-cb0b8feeb3dd_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5FEK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9177635c-faac-45a4-8d2a-cb0b8feeb3dd_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!5FEK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9177635c-faac-45a4-8d2a-cb0b8feeb3dd_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!5FEK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9177635c-faac-45a4-8d2a-cb0b8feeb3dd_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!5FEK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9177635c-faac-45a4-8d2a-cb0b8feeb3dd_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Isn&#8217;t this incredibly noisy?</h2><p>There are two types of updates in BIMP - Routines and Incidents.</p><h3>Routine Updates</h3><p>The most popular is the routine update - as an organisation you decide how often you want teams to process routine updates. That might be every 2 weeks or every 12 weeks, it&#8217;s up to you. The point is that there is always an update coming, no one gets left behind indefinitely and no-one needs to remember anything!</p><h3>Security Incidents</h3><p>However, sometimes you need to patch a vulnerability with more urgency than that. BIMP has an override feature that allows Security to push immediate updates to any repo that is impacted by a newly discovered vulnerability. These are tagged as <code>BIMP-Security-Incidents</code>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Nwfo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf416062-a731-4aaf-8f94-f92d8c1eca32_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Nwfo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf416062-a731-4aaf-8f94-f92d8c1eca32_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!Nwfo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf416062-a731-4aaf-8f94-f92d8c1eca32_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!Nwfo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf416062-a731-4aaf-8f94-f92d8c1eca32_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!Nwfo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf416062-a731-4aaf-8f94-f92d8c1eca32_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Nwfo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf416062-a731-4aaf-8f94-f92d8c1eca32_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/df416062-a731-4aaf-8f94-f92d8c1eca32_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:997268,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://bimpai.substack.com/i/191693093?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf416062-a731-4aaf-8f94-f92d8c1eca32_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Nwfo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf416062-a731-4aaf-8f94-f92d8c1eca32_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!Nwfo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf416062-a731-4aaf-8f94-f92d8c1eca32_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!Nwfo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf416062-a731-4aaf-8f94-f92d8c1eca32_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!Nwfo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf416062-a731-4aaf-8f94-f92d8c1eca32_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>BIMP also gives the Development Team the opportunity to plan work on a schedule that works for them. If they can&#8217;t action a base image update immediately they can request a snooze. The snooze request is their commitment that they will do the work eventually, and security have the organisational context they need about the vulnerable base image. </p><p>BIMP reopens the pull request when the snooze expires so if ownership of the repo changes, the update isn&#8217;t forgotten.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!A0sh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea9ecb0f-4a88-4816-abc7-52dbcf4e8e41_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!A0sh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea9ecb0f-4a88-4816-abc7-52dbcf4e8e41_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!A0sh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea9ecb0f-4a88-4816-abc7-52dbcf4e8e41_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!A0sh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea9ecb0f-4a88-4816-abc7-52dbcf4e8e41_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!A0sh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea9ecb0f-4a88-4816-abc7-52dbcf4e8e41_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!A0sh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea9ecb0f-4a88-4816-abc7-52dbcf4e8e41_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ea9ecb0f-4a88-4816-abc7-52dbcf4e8e41_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:924920,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://bimpai.substack.com/i/191693093?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea9ecb0f-4a88-4816-abc7-52dbcf4e8e41_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!A0sh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea9ecb0f-4a88-4816-abc7-52dbcf4e8e41_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!A0sh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea9ecb0f-4a88-4816-abc7-52dbcf4e8e41_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!A0sh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea9ecb0f-4a88-4816-abc7-52dbcf4e8e41_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!A0sh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea9ecb0f-4a88-4816-abc7-52dbcf4e8e41_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>Supply Chain Security in 2026</h1><p>Agentic Hackers have arrived. Every day we see another newsworthy story of a supply chain attack or embarrassing compromise. Couple this with the tsunami of new vulnerabilities being discovered and the battle maintainers are fighting with code-slop contributions and we find most security teams in a pressure cooker.</p><p>Reviewing, triaging and prioritising risks worked when the volume of risks was small (well, smaller) and when most hackers needed years of experience to figure out novel ways to exploit vulnerabilities.</p><p>There&#8217;s a growing discomfort in security teams that ignoring the lower risks may not be a solid strategy in an age of Agentic Hackers. If there is a chink in your cyber-armor an agent will find it, and they won&#8217;t get tired of trying. Luckily, the same technology that helped create this pressure cooker can help us solve this problem.</p><p>Automation is the answer and AI unlocks huge opportunities for automation in our software development processes. Prioritisation is still important but we believe that you should fix the foundations by default. No triage, no prioritisation, no chasing - just fucking fix it.</p><h1>Our Vision</h1><p>We believe that action oriented security is the future. We aren&#8217;t another bad news dashboard full of risks. We start with the question &#8220;what needs to happen?&#8221; and then we automate that action end to end, so neither security or developers need to think about it.</p><p>Our vision is to secure the foundation of the software supply chain for everyone, by changing how the work gets done. Zero-CVE base images need to become the default and BIMP is going to get us there faster. Migrate in minutes not months.</p><p>Secure your container base images today. Be zero-day ready tomorrow.</p><p><em>Watch the demo on <a href="https://www.youtube.com/@bimp-ai">youtube</a> or <a href="https://bimp.ai/">join the waitlist</a>.</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PY8q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f35e41b-c38a-480d-bbb9-97c580effc57_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PY8q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f35e41b-c38a-480d-bbb9-97c580effc57_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!PY8q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f35e41b-c38a-480d-bbb9-97c580effc57_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!PY8q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f35e41b-c38a-480d-bbb9-97c580effc57_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!PY8q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f35e41b-c38a-480d-bbb9-97c580effc57_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PY8q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f35e41b-c38a-480d-bbb9-97c580effc57_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5f35e41b-c38a-480d-bbb9-97c580effc57_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1620403,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://bimpai.substack.com/i/191693093?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f35e41b-c38a-480d-bbb9-97c580effc57_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PY8q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f35e41b-c38a-480d-bbb9-97c580effc57_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!PY8q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f35e41b-c38a-480d-bbb9-97c580effc57_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!PY8q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f35e41b-c38a-480d-bbb9-97c580effc57_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!PY8q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f35e41b-c38a-480d-bbb9-97c580effc57_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.bimp.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">We&#8217;ll be sharing our story here on the BIMP blog. Subscribe to stay up to date!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>