Echo eliminates 1,400 CVEs in NanoClaw's container images
We eliminated 1,400 CVEs in NanoClaw's container images

Echo's partnership with NanoClaw aims to harden the open-source project's container images. By using multiple scanners, they identified over 1,400 CVEs, then systematically bumped safe upgrades, backported critical fixes, and leveraged Echo OS to patch OS-level vulnerabilities. The result: a 99% reduction in CVEs, with remaining ones continuously monitored. This post details the process, including a complex backport of CVE-2025-59375 in expat, showcasing Echo's AI-driven patching agents and commitment to upstream compatibility.
The final patch is 9 files, 64 hunks, +786/-112, with the complete upstream test suite passing.