Chainguard

The category incumbent: the largest catalog of zero-CVE minimal images built on its own Wolfi distro, plus hardened language libraries and VMs.

https://www.chainguard.dev
best_for

Enterprises that need the broadest catalog, published SLAs, and FIPS/STIG evidence, and have the budget to pay per image for it.

strengths

  • Largest catalog in the category (1,500+ images) with the deepest public documentation
  • Published CVE remediation SLA and a long public track record of zero-CVE scans
  • FIPS and STIG-hardened variants with real compliance program adoption
  • Expanded surface: container images, language libraries (Java, Python, JavaScript), and VM images

weaknesses

  • Premium per-image enterprise pricing is the most common objection in the category
  • Wolfi is its own distro: package availability and behavior differences can add migration work
  • Free tier limited to latest tags on a subset of images; version pinning requires paid plans

Attribute detail

Company
Founded
Headquarters
Funding / backing
Approach
Core approach
Base OS / distro
libc
Shell / package manager in runtime images
Catalog
Catalog size
Coverage scope
Custom / BYO image support
End-of-life version support
Security posture
Zero-CVE posture
CVE remediation SLA
Rebuild cadence
SBOM
VEX statements
Signing & provenance
Compliance
FIPS 140-3 variants
STIG hardening
Compliance fit (FedRAMP / PCI / HIPAA)
Operations
Migration effort
Private registry / air-gap delivery
Commercial
Pricing model
Free tier