Chainguard Images are a collection of minimal, hardened container images that are patched and rebuilt daily, and come with low-to-zero known CVEs, SLSA 2 compliance, signatures, and SBOMs.
Chainguard Images are a collection of minimal, hardened container images. They only contain what is required to build or run your application, delivering on average a 97.6% reduction in CVEs. Each Chainguard Image is patched and rebuilt daily from source with the latest security fixes and CVE remediations, resulting in low-to-zero known CVEs, verifiable image signatures and attestations, high-quality SBOMs, and SLSA Level 2 - Build compliance.
The Chainguard Images inventory contains images for the most popular base images, including Go, Python, Ruby, PHP, Node, and more; and a selection of common developer tools, applications, data products, and servers.
Chainguard Production Images are available for FIPS compliance, major and minor versions, enterprise SLAs, and customer support. Chainguard offers custom pricing through AWS Marketplace Private Offers.
Chainguard provides custom pricing for customers via Private Offer. Please contact AWS-marketplace@chainguard.dev for more information on our pricing model. Pricing displayed is per Image.
Highlights
Low-to-zero known CVEs with daily patches and rebuilds
Full SLSA Build Level 2 provenance, signatures, and SBOMs
Images with FIPS validation available upon request
Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
The listed pricing is for illustrative purposes only and does not reflect actual pricing, which will be provided upon request, exclusively as part of a private offer from Chainguard
$0.01
Base Image
The listed pricing is for illustrative purposes only and does not reflect actual pricing, which will be provided upon request, exclusively as part of a private offer from Chainguard
$0.01
FIPS Image
The listed pricing is for illustrative purposes only and does not reflect actual pricing, which will be provided upon request, exclusively as part of a private offer from Chainguard
$0.01
AI Image
The listed pricing is for illustrative purposes only and does not reflect actual pricing, which will be provided upon request, exclusively as part of a private offer from Chainguard
$0.01
Standard CSM
The listed pricing is for illustrative purposes only and does not reflect actual pricing, which will be provided upon request, exclusively as part of a private offer from Chainguard
This listing bills through annual contracts, priced per unit. Starter Images give you the :latest version of open source packages. The other options separate images by type and use case: Base Images, Application Images, AI Images, and FIPS Images for regulated environments. Standard CSM covers customer support and management. Under the per-image approach, cost reflects both the count and complexity of the images you license. The listed prices are illustrative only. Actual pricing comes through a private offer from Chainguard, so you request a quote tailored to your usage.
Top-of-mind questions for buyers
What distinguishes the Base, Application, AI, and FIPS image types for billing?
Base Images cover languages and frameworks you build on top of. Application Images are servers, databases, and tools you deploy as-is. AI Images handle machine learning and GPU workloads. FIPS Images use validated encryption and OS-level hardening for regulated environments. Each type carries its own price reflecting its complexity.
How does cost behave under the per-image model as I license more images?
Cost reflects both the count and complexity of the images you license. Adding more images raises your total, and higher-complexity types like AI or FIPS cost more per image than base types. This model fits teams with targeted use cases rather than broad catalog access.
What do the Starter Images include, and how do they differ from the other image dimensions?
Starter Images give you the :latest version tags of open source packages. Unlike the Base, Application, AI, and FIPS Images, these carry only current tags and are not covered under the CVE remediation service-level agreement. Use them to test and deploy without the same support commitments.
www.chainguard.dev
Helpful?
Vendor refund policy
Contact us for refund information
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Container images are patched and rebuilt daily from source with the latest security fixes and CVE remediations.
Vulnerability Reduction
Minimal, hardened container images delivering on average a 97.6% reduction in CVEs with low-to-zero known vulnerabilities.
Supply Chain Security Compliance
Full SLSA Level 2 - Build compliance with verifiable image signatures, attestations, and high-quality SBOMs.
Multi-Language Runtime Support
Pre-built images available for popular programming languages and runtimes including Go, Python, Ruby, PHP, and Node.
FIPS Compliance Availability
Production images with FIPS validation available for regulatory compliance requirements.
Automated Vulnerability Remediation
Automatically removes up to 95% of CVEs without requiring code changes, reducing vulnerability and patch management backlogs.
Daily Security Patching and Hardening
Curated images are patched and hardened daily from source with latest security fixes and CVE remediations, resulting in Zero or Near-Zero CVEs.
Software Bill of Materials Generation
Generates high-quality SBOMs in multiple formats including raw JSON, SPDX, and Cyclone DX to address software supply chain and compliance requirements.
CI/CD Pipeline Integration
Integrates with CI/CD pipelines and container deployment platforms through simple API calls.
Build Compliance Certification
Achieves SLSA Level 2 Build compliance for container images and applications.
Static Application Security Testing
Identifies vulnerabilities and weaknesses in custom code with support for 25+ languages and frameworks, scanning uncompiled code and re-scanning only new or modified code.
Software Composition Analysis
Identifies and prioritizes open source vulnerabilities, takes inventory of open source components and dependencies, and evaluates risks of open source licenses.
Infrastructure as Code Analysis
Detects security misconfigurations in IaC templates using KICS to prevent errors such as open storage buckets, insecure databases, and excessive privileges.
Real-time IDE Security Scanning
Provides real-time vulnerability detection during IDE development for both human-generated and AI-generated code, identifying vulnerabilities, unmasked secrets, vulnerable container images, and malicious open source packages.
Agentic-AI Remediation
Generates remediation suggestions using AI agents that access proprietary databases and customized AI models to provide context-aware code fixes with interactive refinement capabilities.
I like that Chainguard provides secure images for our Kubernetes platform, which means fewer security issues to deal with personally. I appreciate that the images are readily available and updated frequently, and I find it easy to request missing images or updates. Setting up my login and the credential helper was very easy too.
What do you dislike about the product?
Nothing comes to mind.
What problems is the product solving and how is that benefiting you?
Chainguard provides secure images for Kubernetes, reducing security issues. I don't have to handle those issues myself. Images are readily available, frequently updated, and requesting updates is easy.
Defense & Space
Near-Zero CVEs with a Seamless Catalog and Prompt Support
Reviewed on Jul 24, 2026
Review provided by G2
What do you like best about the product?
They’ve delivered on their promise of hardening images to a near-zero CVE posture. The web catalog experience is seamless, easy to navigate, and genuinely useful. On top of that, my support requests have been answered promptly.
What do you dislike about the product?
Pricing has changed over the years and has been expensive at times, but I think it’s on the right track now. That said, updates to an image can sometimes be slow, which can be a bit frustrating.
What problems is the product solving and how is that benefiting you?
It helps us reduce the CVE count on our images by providing equivalent replacements that fit into our existing codebase without much effort.
Trigg B.
Easy Image Access with Smart Quality Recognition
Reviewed on Jul 20, 2026
Review provided by G2
What do you like best about the product?
Easy access to images. Recognized the quality of images
What do you dislike about the product?
Would be nice to have API access to the CVE information.
What problems is the product solving and how is that benefiting you?
Hardened BaseOS image and third-party image builds
Computer Software
Prompt Responses at Every Level
Reviewed on Jul 10, 2026
Review provided by G2
What do you like best about the product?
From every level, I have received prompt responses.
What do you dislike about the product?
I haven't found anything I dislike about them.
What problems is the product solving and how is that benefiting you?
We are early in the process, but the value is the fact that CVEs that hang around for too long in the open-source space are remedied much faster.
The Chainguard images eliminate or reduce known vulnerabilities.
What do you dislike about the product?
While the documentation and workflow for images is great, the same for helm charts is sometimes lacking.
What problems is the product solving and how is that benefiting you?
Chainguard provides us with more secure container images, which is required for some of the secure networks we are deploying to. It saves us a ton of time in building our own custom images by providing secure, minimal containers to build from.