🧵 CLI tool for directly patching container images!
See the code
copa is a CLI tool written in Go and based on buildkit that can be used to directly patch container images without full rebuilds. copa can also patch container images using the vulnerability scanning results from popular tools like Trivy.
For more details and how to get started, please refer to full documentation.
Copa supports both apt-less Ubuntu images that retain a full
/var/lib/dpkg/status file and native Chisel images that contain
/var/lib/chisel/manifest.wall. Full-status images support report-driven and
comprehensive updates. Native-manifest images support comprehensive updates
only; omit --report so Copa can re-cut every installed slice.
For native manifest.wall images, use --chisel-release to select a named
release such as ubuntu-24.04, a local release directory, or a public HTTPS Git
URL with a mandatory pinned commit or tag fragment. Without an override, Copa
infers
ubuntu-<VERSION_ID> from the target's /etc/os-release. Initial support uses
public archives only. As verified on July 31, 2026 with Copa's pinned Trivy
version (v0.69.3), Trivy does not extract OS package inventory from native
manifest.wall files.
See Ubuntu Chiseled image
patching for behavior and limitations.

We needed the ability to patch containers quickly without going upstream for a full rebuild. As the window between vulnerability disclosure and active exploitation continues to narrow, there is a growing operational need to patch critical security vulnerabilities in container images so they can be quickly redeployed into production. The need is especially acute when those vulnerabilities are:

In addition to filling the operational gap not met by left-shift security practices and tools, the ability of copa to patch a container without requiring a rebuild of the container image provides other benefits:
The copa tool is an extensible engine that:

This approach is motivated by the core principles of making direct container patching broadly applicable and accessible:
There are several ways to get involved:
#copacetic channel on the CNCF Slack.The project welcomes contributions and suggestions that abide by the CNCF Code of Conduct.
(top 24 of 34)
1,772 followers · starred Nov 2023
742 followers · starred Sep 2025
557 followers · starred Nov 2023
63 followers · starred Mar 2023
🧵 CLI tool for directly patching container images!
See the code
copa is a CLI tool written in Go and based on buildkit that can be used to directly patch container images without full rebuilds. copa can also patch container images using the vulnerability scanning results from popular tools like Trivy.
For more details and how to get started, please refer to full documentation.
Copa supports both apt-less Ubuntu images that retain a full
/var/lib/dpkg/status file and native Chisel images that contain
/var/lib/chisel/manifest.wall. Full-status images support report-driven and
comprehensive updates. Native-manifest images support comprehensive updates
only; omit --report so Copa can re-cut every installed slice.
For native manifest.wall images, use --chisel-release to select a named
release such as ubuntu-24.04, a local release directory, or a public HTTPS Git
URL with a mandatory pinned commit or tag fragment. Without an override, Copa
infers
ubuntu-<VERSION_ID> from the target's /etc/os-release. Initial support uses
public archives only. As verified on July 31, 2026 with Copa's pinned Trivy
version (v0.69.3), Trivy does not extract OS package inventory from native
manifest.wall files.
See Ubuntu Chiseled image
patching for behavior and limitations.

We needed the ability to patch containers quickly without going upstream for a full rebuild. As the window between vulnerability disclosure and active exploitation continues to narrow, there is a growing operational need to patch critical security vulnerabilities in container images so they can be quickly redeployed into production. The need is especially acute when those vulnerabilities are:

In addition to filling the operational gap not met by left-shift security practices and tools, the ability of copa to patch a container without requiring a rebuild of the container image provides other benefits:
The copa tool is an extensible engine that:

This approach is motivated by the core principles of making direct container patching broadly applicable and accessible:
There are several ways to get involved:
#copacetic channel on the CNCF Slack.The project welcomes contributions and suggestions that abide by the CNCF Code of Conduct.
(top 24 of 34)
1,772 followers · starred Nov 2023
742 followers · starred Sep 2025
557 followers · starred Nov 2023
63 followers · starred Mar 2023