Listing Thumbnail

    Chainguard Images

     Info
    Sold by: Chainguard 
    Chainguard Images are a collection of minimal, hardened container images that are patched and rebuilt daily, and come with low-to-zero known CVEs, SLSA 2 compliance, signatures, and SBOMs.
    Listing Thumbnail

    Chainguard Images

     Info
    Sold by: Chainguard 

    Overview

    Chainguard Images are a collection of minimal, hardened container images. They only contain what is required to build or run your application, delivering on average a 97.6% reduction in CVEs. Each Chainguard Image is patched and rebuilt daily from source with the latest security fixes and CVE remediations, resulting in low-to-zero known CVEs, verifiable image signatures and attestations, high-quality SBOMs, and SLSA Level 2 - Build compliance. The Chainguard Images inventory contains images for the most popular base images, including Go, Python, Ruby, PHP, Node, and more; and a selection of common developer tools, applications, data products, and servers. Chainguard Production Images are available for FIPS compliance, major and minor versions, enterprise SLAs, and customer support. Chainguard offers custom pricing through AWS Marketplace Private Offers. Contact AWS-marketplace@chainguard.dev  for more information on our enterprise pricing. Pricing displayed is per Image.

    Highlights

    • Low-to-zero known CVEs with daily patches and rebuilds
    • Full SLSA Build Level 2 provenance, signatures, and SBOMs
    • Images with FIPS validation available upon request

    Details

    Delivery method

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Chainguard Images

     Info
    Pricing is based on contract duration. You pay upfront or in installments according to your contract terms with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.

    12-month contract (6)

     Info
    Dimension
    Description
    Cost/12 months
    Developer Images
    :latest version of OSS packages
    $0.00
    Application Images
    Servers, developer tools, databases, (e.g. nginx, mariadb, kubernetes)
    $29,000.00
    Base Images
    Languages, frameworks (e.g. java, go, .NET)
    $39,000.00
    FIPS Images
    FIPS versions of any image, Includes STIG
    $59,000.00
    Standard CSM
    Onboarding and Go-Live Tracking Shared Slack channel Best Practices and Education Reviews Change Management and Escalations
    $25,000.00
    AI Images
    Images for CPU and GPU Machine Learning workloads. (ex: Spark, Kubeflow, PyTorch, CUDA)
    $69,000.00

    Vendor refund policy

    Contact us for refund information

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 AWS reviews
    |
    24 external reviews
    External reviews are sourced from G2  and are not included in the star rating for this product.
    Leonardo Z.

    Simplifying security

    Reviewed on Nov 07, 2024
    Review provided by G2
    What do you like best about the product?
    Security is hard on its own, and while many vendors focus on selling detection products, Chainguard does the opposite and solve a painful problem with little effort from users.
    What do you dislike about the product?
    Chainguard offers some free to use images, but only "latest" version and not stable versions. This makes impossible to use as an individual or for open source projects.
    What problems is the product solving and how is that benefiting you?
    Zero security vulnerability containers.
    Emmanuel F.

    My experiences using Chainguard Nodejs base image was amazing!

    Reviewed on Sep 12, 2024
    Review provided by G2
    What do you like best about the product?
    - Very small image size,
    - Very small to none CVEs from my experiences.
    - Very large repo supporting many languages and technologies,
    - Ease to use,
    - Ease of implementation.
    What do you dislike about the product?
    A great part of it, is free, but for some custom implementation or features , you may pay.
    What problems is the product solving and how is that benefiting you?
    CVEs, better quality software.
    Brad M.

    Chainguard makes securing applications much easier

    Reviewed on Sep 06, 2024
    Review provided by G2
    What do you like best about the product?
    It's simplicity. Changing from a regular Image to use a Chainguard image as the base helps mitigate a lot of vulnerabilities, and it's a change any developer would be able to easily implement.

    This is something that I would recommand to any developer or business that is looking to harden their applications. Securing the base image is the first step everyone should take.
    What do you dislike about the product?
    I have some uncertaincies about what the support will look like for users using the Developer Free tier in the future. Would like them to sllow all image versions and not just latest/stable for Free Tier.
    What problems is the product solving and how is that benefiting you?
    Bring simplicity to security. It hardens the application image that our containers use to run.
    Karl H.

    Game-Changer

    Reviewed on Aug 28, 2024
    Review provided by G2
    What do you like best about the product?
    Since implementing Chainguard's hardened base images, we've seen a dramatic reduction in vulnerabilities—over 70%. This reduction not only enhances our security posture but also saves our engineering teams an enormous amount of time that would otherwise be spent on vulnerability management and patching. Chainguard's approach introduces excellent security practices out of the box, meaning our engineers no longer have to worry about critical security concerns like rootless containers, proper permissions, and secure registries.

    Chainguard sets itself apart by providing supply chain security through purpose-built packages in their registry, making it clear that while competitors might still be playing catch-up in the minor leagues, Chainguard is clearly in a league of its own, setting the standard for supply chain security. We've maximized the value of these images by ensuring reuse across our organization, categorizing images into language-based and application-based groups. This strategy allows us to gain the most value through frequent reuse of language-based images, while our centralized platform engineering teams benefit from using application-specific images at a different scale.

    To drive adoption, we've integrated Chainguard images into our centralized internal developer portal, which our developers are already familiar with and use regularly. This seamless integration has significantly boosted adoption rates, further supported by our vulnerability management reduction program. Through this program, we've been able to recommend Chainguard images, reassuring teams that transitioning will save time and energy.

    The service level agreements (SLAs) provided by Chainguard are also very attractive. The high speed of image updates ensures that we are always protected with the latest security enhancements. We've even integrated Chainguard into our automatic update tools, so our developers are always confident that they're working with the most up-to-date versions.

    Overall, Chainguard's hardened base images have been a game-changer for our organization, providing unparalleled security, efficiency, and peace of mind.
    What do you dislike about the product?
    The documentation at times fall a little behind and the modern authentication mechanisms at times can create difficulties in integrating with other existing platforms that are not yet supportive of technologies like OIDC. Quite a few of the images require rework to convert from a standard Dockerhub image however, I believe that's expected.
    What problems is the product solving and how is that benefiting you?
    Reducing container, image, vulnerabilities and creating a solid secure base to build upon
    Matheus G.

    Time-Saving, Secure Containers Solutions!

    Reviewed on Aug 23, 2024
    Review provided by G2
    What do you like best about the product?
    Chainguard allows developers to save a lot of time and effort by providing ready-to-use container images that are secure. In addition, the images provided are very lightweight.
    What do you dislike about the product?
    The custom linux distribution may be harder to work with, but wolfi-base is still quite similar to Alpine and hence not too complex.
    What problems is the product solving and how is that benefiting you?
    They provide off the shelf image solutions to secure you deployment/release containers. In other words, Chainguard allows you to secure the environment in which you deploy your applications to.
    View all reviews