SAN JOSE, Calif., July 21, 2026 (GLOBE NEWSWIRE) — BellSoft, a leadi g Ope JDK ve do , a ou ces the ge e al availability of a ew ha de ed builde image fo Paketo Buildpacks
Paketo Buildpacks
At the ce te of the p ocess is a builde , a cu ated co tai e image that packages the buildpacks, a build e vi o me t (the “build stack”), a d a u time e vi o me t (the “ u stack”) togethe . The builde is the secu ity fou datio of eve y image p oduced: the OS packages, lib a ies a d u time bi a ies it co tai s become the base of eve y applicatio co tai e that uses it. BellSoft’s co t ibutio is a ha de ed builde that eplaces both stacks with Ha de ed Images, based o Alpaquita, BellSoft’s ow secu e a d lightweight OS, so eve y co tai e p oduced automatically i he its BellSoft’s full secu ity a d complia ce postu e.
Docke files a e w itte by develope s, o e pe se vice, updated ma ually, a d a e p o e to d ift. Acco di g to a ece t BellSoft su vey, ove 60% of develope s a e u awa e that a poo ly w itte Docke file ca itself become a secu ity vul e ability. At e te p ise scale, with hu d eds of se vices a d doze s of teams, Docke file sp awl becomes a complia ce a d mai te a ce liability. Base image updates must be p opagated ma ually ac oss eve y eposito y. Secu ity patches a e o ly as fast as the slowest team.
Paketo Buildpacks
With BellSoft’s ha de ed builde , that adva tage compou ds. Whe a vul e ability is patched i BellSoft Ha de ed Images, eve y applicatio built o the builde picks up the fix o the ext build, ac oss eve y se vice a d eve y team, simulta eously.
The th eat la dscape has cha ged. Ze o-t ust secu ity models, softwa e supply chai attacks, a d tighte i g egulato y equi eme ts, f om FedRAMP a d DISA STIG to the EU Cybe Resilie ce Act (CRA) a d DORA, have made ha de ed co tai e bases a p actical ecessity fo a y o ga izatio u i g p oductio wo kloads. The questio is o lo ge whethe to ha de , but how to do it without addi g f ictio fo developme t teams.
BellSoft Ha de ed Images a e built o Alpaquita, BellSoft’s secu e, lightweight OS, a d ship with a sig ifica tly educed package footp i t, o -mutable compo e t set, u i g as o – oot, a d othe secu ity co figu atio s e abled by default. They a e mai tai ed by BellSoft’s secu ity team with a commitme t to a ze o-CVE wi dow: whe a vul e ability is disclosed, a patched image is published typically withi 24 hou s.
“Vul e ability ma ageme t is a busi ess p oblem, ot a e gi ee i g o e,” said Alex Belok ylov, CEO of BellSoft. “It dese ves a busi ess a swe , ot the sile t accumulatio of toil o al eady-st etched i te al teams. Sca e fatigue is eal, a d so is the cost of ig o i g it. Rathe tha t acki g CVE feeds, t iagi g which vul e abilities affect which base images, a d coo di ati g patches ac oss teams, secu ity a d platfo m e gi ee i g teams ca ely o BellSoft to mai tai a clea image baseli e. Each published image comes with a full Softwa e Bill of Mate ials a d a ve ifiable p ove a ce eco d, maki g complia ce audits st aightfo wa d a d t a spa e t, a d p ovidi g the docume ted evide ce that egulato s a d e te p ise p ocu eme t teams i c easi gly dema d.”
BellSoft’s ha de ed builde fo Paketo Buildpacks
Teams al eady usi g Paketo Buildpacks
Buildpacks, the Buildpacks.io logo, a d Paketo Buildpacks a e t adema ks of The Li ux Fou datio . Please see buildpacks.io a d paketo.io fo mo e i fo matio .
BellSoft delive s the most complete Java expe ie ce with a mo e secu e, eliable, a d cost-effective app oach to applicatio developme t o a y platfo m a d i a y e vi o me t. BellSoft is o e of the leadi g co t ibuto s to the Ope JDK, a d the o ly ve do that suppo ts cu e t LTS Java ve sio s, legacy JDK 6 & 7 a d Libe ica NIK. Libe ica JDK is the u time of choice fo VMwa e, Sp i g F amewo k, JetB ai s, a d millio s of use s wo ldwide. Fo mo e i fo matio , visit www.bell-sw.com.
Co tact:Kevi WolfTGPR fo BellSoftkevi @tgp llc.com







 