Listing Thumbnail

    Chainguard Images

     Info
    Deployed on AWS
    Chainguard Images are a collection of minimal, hardened container images that are patched and rebuilt daily, and come with low-to-zero known CVEs, SLSA 2 compliance, signatures, and SBOMs.

    Overview

    Chainguard Images are a collection of minimal, hardened container images. They only contain what is required to build or run your application, delivering on average a 97.6% reduction in CVEs. Each Chainguard Image is patched and rebuilt daily from source with the latest security fixes and CVE remediations, resulting in low-to-zero known CVEs, verifiable image signatures and attestations, high-quality SBOMs, and SLSA Level 2 - Build compliance.
    The Chainguard Images inventory contains images for the most popular base images, including Go, Python, Ruby, PHP, Node, and more; and a selection of common developer tools, applications, data products, and servers.
    Chainguard Production Images are available for FIPS compliance, major and minor versions, enterprise SLAs, and customer support. Chainguard offers custom pricing through AWS Marketplace Private Offers.

    Chainguard provides custom pricing for customers via Private Offer. Please contact AWS-marketplace@chainguard.dev  for more information on our pricing model. Pricing displayed is per Image.

    Highlights

    • Low-to-zero known CVEs with daily patches and rebuilds
    • Full SLSA Build Level 2 provenance, signatures, and SBOMs
    • Images with FIPS validation available upon request

    Details

    Delivery method

    Deployed on AWS

    Unlock automation with AI agent solutions

    Fast-track AI initiatives with agents, tools, and solutions from AWS Partners.
    AI Agents

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Chainguard Images

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (6)

     Info
    Dimension
    Description
    Cost/12 months
    Starter Images
    :latest version of OSS packages
    $0.00
    Application Image
    The listed pricing is for illustrative purposes only and does not reflect actual pricing, which will be provided upon request, exclusively as part of a private offer from Chainguard
    $0.01
    Base Image
    The listed pricing is for illustrative purposes only and does not reflect actual pricing, which will be provided upon request, exclusively as part of a private offer from Chainguard
    $0.01
    FIPS Image
    The listed pricing is for illustrative purposes only and does not reflect actual pricing, which will be provided upon request, exclusively as part of a private offer from Chainguard
    $0.01
    AI Image
    The listed pricing is for illustrative purposes only and does not reflect actual pricing, which will be provided upon request, exclusively as part of a private offer from Chainguard
    $0.01
    Standard CSM
    The listed pricing is for illustrative purposes only and does not reflect actual pricing, which will be provided upon request, exclusively as part of a private offer from Chainguard
    $0.01

    Vendor refund policy

    Contact us for refund information

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Application Stacks, Operating Systems
    Top
    100
    In Collaboration & Productivity, Application Development
    Top
    25
    In Compliance and Auditing

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    0 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    0 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Container Image Security
    Minimal and hardened container images with low-to-zero known CVEs through daily patching and rebuilding
    Compliance Verification
    SLSA Level 2 build compliance with verifiable image signatures and attestations
    Software Bill of Materials
    High-quality Software Bill of Materials (SBOMs) generated for each container image
    Image Minimalism
    Container images containing only essential components required for application build or runtime
    Cryptographic Integrity
    Cryptographic signatures and provenance tracking for container image validation
    Vulnerability Reduction
    Automatically removes up to 95% of Common Vulnerabilities and Exposures (CVEs) without requiring code modifications
    Software Supply Chain Security
    Generates high-quality Software Bill of Materials (SBOMs) in multiple standard formats including JSON, SPDX, and Cyclone DX
    Continuous Security Hardening
    Provides daily patched and hardened images for operating systems, frameworks, and applications with near-zero vulnerability status
    CI/CD Integration
    Supports seamless integration with multiple popular continuous integration and container deployment platforms through API calls
    Compliance Automation
    Enables compliance with security standards including FedRAMP, DSS, and PCI through automated vulnerability management and remediation
    Security Hardening
    Pre-configured image hardened to CIS Benchmarks Level 2 security recommendations with comprehensive configuration controls
    Compliance Reporting
    Includes detailed HTML reports from CIS Configuration Assessment Tool (CIS-CAT Pro) documenting pre and post-hardening system configurations
    Benchmark Alignment
    Follows industry-recognized security guidance developed through consensus-based process across government, business, and academic sectors
    System Configuration
    Implements hardened account policies, firewall configurations, and administrative templates without modifying base image package set
    Continuous Security Update
    Monthly patched image maintaining alignment with software vendor security updates and latest benchmark recommendations

    Contract

     Info
    Standard contract
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 AWS reviews
    |
    43 external reviews
    Star ratings include only reviews from verified AWS customers. External reviews can also include a star rating, but star ratings from external reviews are not averaged in with the AWS customer star ratings.
    Gopalji S.

    Effortless Supply Chain Security with Seamless Integration

    Reviewed on Nov 19, 2025
    Review provided by G2
    What do you like best about the product?
    What I appreciate most about Chainguard is how it simplifies and strengthens software supply chain security. The platform offers transparent visibility into dependencies, vulnerabilities, and build pipelines, all without introducing unnecessary complexity. I also value its seamless integration with our existing workflows, which enables our team to identify potential issues early and maintain confidence in our software releases. The combination of automation and practical insights truly sets it apart.
    What do you dislike about the product?
    The main challenge I’ve encountered with Chainguard is that the initial setup and configuration process can be somewhat time-consuming, particularly if you’re dealing with complex pipelines or managing several environments. After the setup is complete, everything operates smoothly, but getting all the integrations in place and fine-tuning the system at the start does demand some effort.
    What problems is the product solving and how is that benefiting you?
    Chainguard addresses the challenges of software supply chain security and dependency management. It enables us to spot vulnerabilities, apply necessary policies, and guarantee that only trusted components are included in our builds. As a result, we experience fewer security risks, quicker identification of potential problems, and greater assurance in the reliability of our software releases. The tool streamlines our workflow by saving time, minimizing manual checks, and providing our team with peace of mind that our pipelines remain secure.
    anan H.

    Effortless Security and Zero CVEs for Container Images

    Reviewed on Nov 18, 2025
    Review provided by G2
    What do you like best about the product?
    Chainguard provides a strong security approach for container images and supply chain hygiene the images are minimal and well maintained by them and fully SBOM verified with consistently updated which reduces operational risk
    the platform makes it easy to adopt secure by default practices without adding overhead to CI/CD pipelines and it helps a security companies to have images with zero CVEs
    What do you dislike about the product?
    I think the only concern is the pricing that can be a bit high for smaller teams
    What problems is the product solving and how is that benefiting you?
    Chainguard solves the ongoing challenge of keeping container images secure with zero CVEs instead of start patching these images from week to week
    Angel B.

    Easy-to-Use, Secure Container Images

    Reviewed on Nov 06, 2025
    Review provided by G2
    What do you like best about the product?
    The container images are easy to use and provide a secure environment.
    What do you dislike about the product?
    The integration process is not straightforward, and the cost can be high for individual users.
    What problems is the product solving and how is that benefiting you?
    Vulnerability scanner which helps me detect complex issues easily.
    Insurance

    Great product, great customer service

    Reviewed on Jul 24, 2025
    Review provided by G2
    What do you like best about the product?
    A wealth of images and packages at the highest standard of security.
    What do you dislike about the product?
    It’s kinda pricey for a startup, but, ultimately, worth it
    What problems is the product solving and how is that benefiting you?
    Building rocket images on top of very secure base images, using secured packages.
    Charlie G.

    The gold star vendor: sales, onboarding implementation, support, and product

    Reviewed on Jul 24, 2025
    Review provided by G2
    What do you like best about the product?
    The chainguard team was able to meet us where we were at, move extremely quickly to meet our deadlines, and everything _just worked_.
    What do you dislike about the product?
    Wiz sometimes detects false positives in cgr images.
    What problems is the product solving and how is that benefiting you?
    Passing audits, and getting our vuln counts to zero.
    View all reviews