Copa: 'The missing piece' for automating patching containers at scale

Mary Branscombe March 31, 2026
Source

Usually, my pieces about open source platform engineering projects are deep dives into fairly big name tools that are at an interesting point in their lifecycle, but every now and then I find a hidden gem that I'm surprised everyone isn't using because it fixes a problem almost everyone has: Copa is one of those.

It's still in the CNCF sandbox but gearing up for incubation and with the Cyber Resiliency Act looming on the horizon for anyone who sells into the EU and, frankly, the state of the world, if you have containers that have known vulnerabilities, you need a way to always be patching...

Or as Mark Russinovich said when he shared my piece on LinkedIn, "the ability to patch at scale is no longer optional; it’s a requirement for survival".

Discussion in the ATmosphere

Loading comments...