Echo Acquires Hardened Container Assets from Minimus
TL;DR — Key Takeaways
- Echo has acquired technology assets from Minimus following Minimus’ decision to shut down.
- Echo plans to incorporate the acquired assets into its hardened software portfolio, which includes container images, virtual machines, libraries, serverless functions, operating system packages and Helm charts.
- Echo uses AI agents to investigate vulnerabilities and help develop and validate patches, reducing the remediation burden on DevSecOps teams.
Echo today revealed it has acquired technology assets from Minimus, a provider of hardened open source container images, that earlier this week revealed it is shutting down.
Those assets will later be incorporated into a rival offering from Echo, which also provides hardened virtual machines, open source libraries, serverless functions, operating systems packages and Helm charts for Kubernetes clusters.
Echo CEO Eilon Elhadad said those assets will be used to further extend an existing portfolio of hardened software artifacts housed in a local instance of a repository that DevSecOps teams can instantly access to build and deploy more secure applications to additional distributions of Linux. Via that repository, it not only becomes possible to access hardened artifacts, but also seamlessly replace existing ones with artifacts built from source code that are 100% compatible with the artifacts they replace in an existing application, he added.
Those artifacts are continuously updated as Echo employs proprietary AI agents to investigate vulnerabilities and then develop and validate patches as needed. That approach shifts responsibility for continuously patching artifacts to Echo rather than requiring a DevSecOps team to first validate the need for an update before creating and testing it, noted Elhadad.
Mitch Ashley, vice president and practice lead for software lifecycle engineering at The Futurum Group, said the fact that Minimus is winding down says more about the changing economics of hardened open source than demand for it. The next thing to watch is whether Echo also moves to acquire scanner integrations and how that influences their product strategy from here, he added.
It’s not clear at what rate organizations are revamping their existing DevSecOps workflows, but as the volume of vulnerabilities that are being discovered in the age of AI dramatically increases, it has become all too obvious a different approach is required. The issue is how rapidly DevSecOps teams will be able to adapt before a successive wave of cyberattacks using exploits created by AI tools is launched. It’s not likely that DevSecOps teams will be able to fix every application before those attacks arrive, so in most cases there will be a need to prioritize the applications that are most critical to the business.
On the plus side, however, that need to continuously remediate applications may spur further adoption of containers that are simpler to rip and replace by design. In theory, any time a new vulnerability is discovered, AI coding tools could be used to rapidly create a patch that would then be delivered via an update to a specific set of containers versus having to patch an entire monolithic application.
Hopefully, after what will clearly be some trying times, the overall state of application security will improve. After all, there can only be so much technical debt in existing legacy applications. The challenge then becomes ensuring that the next generation of applications are truly secure by design from the moment they are constructed through deployment and subsequent updates.
Frequently Asked Questions
What did Echo acquire from Minimus?
Echo acquired technology assets from Minimus, a provider of hardened open source container images that recently announced it was shutting down.
How will Echo use the Minimus assets?
Echo plans to incorporate them into its existing portfolio of hardened software artifacts and make them available through its repository platform.
How does Echo use AI for vulnerability remediation?
Echo uses proprietary AI agents to investigate vulnerabilities and help develop and validate patches that can then be distributed through updated hardened artifacts.


