Listing Thumbnail

    Chainguard Images

     Info
    Sold by: Chainguard 
    Deployed on AWS
    Chainguard Images are a collection of minimal, hardened container images that are patched and rebuilt daily, and come with low-to-zero known CVEs, SLSA 2 compliance, signatures, and SBOMs.
    4.8

    Overview

    Chainguard Images are a collection of minimal, hardened container images. They only contain what is required to build or run your application, delivering on average a 97.6% reduction in CVEs. Each Chainguard Image is patched and rebuilt daily from source with the latest security fixes and CVE remediations, resulting in low-to-zero known CVEs, verifiable image signatures and attestations, high-quality SBOMs, and SLSA Level 2 - Build compliance.
    The Chainguard Images inventory contains images for the most popular base images, including Go, Python, Ruby, PHP, Node, and more; and a selection of common developer tools, applications, data products, and servers.
    Chainguard Production Images are available for FIPS compliance, major and minor versions, enterprise SLAs, and customer support. Chainguard offers custom pricing through AWS Marketplace Private Offers.

    Chainguard provides custom pricing for customers via Private Offer. Please contact AWS-marketplace@chainguard.dev  for more information on our pricing model. Pricing displayed is per Image.

    Highlights

    • Low-to-zero known CVEs with daily patches and rebuilds
    • Full SLSA Build Level 2 provenance, signatures, and SBOMs
    • Images with FIPS validation available upon request

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Chainguard Images

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (6)

     Info
    Dimension
    Description
    Cost/12 months
    Starter Images
    :latest version of OSS packages
    $0.00
    Application Image
    The listed pricing is for illustrative purposes only and does not reflect actual pricing, which will be provided upon request, exclusively as part of a private offer from Chainguard
    $0.01
    Base Image
    The listed pricing is for illustrative purposes only and does not reflect actual pricing, which will be provided upon request, exclusively as part of a private offer from Chainguard
    $0.01
    FIPS Image
    The listed pricing is for illustrative purposes only and does not reflect actual pricing, which will be provided upon request, exclusively as part of a private offer from Chainguard
    $0.01
    AI Image
    The listed pricing is for illustrative purposes only and does not reflect actual pricing, which will be provided upon request, exclusively as part of a private offer from Chainguard
    $0.01
    Standard CSM
    The listed pricing is for illustrative purposes only and does not reflect actual pricing, which will be provided upon request, exclusively as part of a private offer from Chainguard
    $0.01

    Vendor refund policy

    Contact us for refund information

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Application Stacks, Operating Systems
    Top
    100
    In Collaboration & Productivity, Application Development
    Top
    10
    In Testing

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    0 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Daily Security Patching and Rebuilding
    Container images are patched and rebuilt daily from source with the latest security fixes and CVE remediations.
    Vulnerability Reduction
    Minimal, hardened container images delivering on average a 97.6% reduction in CVEs with low-to-zero known vulnerabilities.
    Supply Chain Security Compliance
    Full SLSA Level 2 - Build compliance with verifiable image signatures, attestations, and high-quality SBOMs.
    Multi-Language Runtime Support
    Pre-built images available for popular programming languages and runtimes including Go, Python, Ruby, PHP, and Node.
    FIPS Compliance Availability
    Production images with FIPS validation available for regulatory compliance requirements.
    Automated Vulnerability Remediation
    Automatically removes up to 95% of CVEs without requiring code changes, reducing vulnerability and patch management backlogs.
    Daily Security Patching and Hardening
    Curated images are patched and hardened daily from source with latest security fixes and CVE remediations, resulting in Zero or Near-Zero CVEs.
    Software Bill of Materials Generation
    Generates high-quality SBOMs in multiple formats including raw JSON, SPDX, and Cyclone DX to address software supply chain and compliance requirements.
    CI/CD Pipeline Integration
    Integrates with CI/CD pipelines and container deployment platforms through simple API calls.
    Build Compliance Certification
    Achieves SLSA Level 2 Build compliance for container images and applications.
    Static Application Security Testing
    Identifies vulnerabilities and weaknesses in custom code with support for 25+ languages and frameworks, scanning uncompiled code and re-scanning only new or modified code.
    Software Composition Analysis
    Identifies and prioritizes open source vulnerabilities, takes inventory of open source components and dependencies, and evaluates risks of open source licenses.
    Infrastructure as Code Analysis
    Detects security misconfigurations in IaC templates using KICS to prevent errors such as open storage buckets, insecure databases, and excessive privileges.
    Real-time IDE Security Scanning
    Provides real-time vulnerability detection during IDE development for both human-generated and AI-generated code, identifying vulnerabilities, unmasked secrets, vulnerable container images, and malicious open source packages.
    Agentic-AI Remediation
    Generates remediation suggestions using AI agents that access proprietary databases and customized AI models to provide context-aware code fixes with interactive refinement capabilities.

    Contract

     Info
    Standard contract
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.8
    64 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    86%
    12%
    2%
    0%
    0%
    2 AWS reviews
    |
    62 external reviews
    External reviews are from G2  and PeerSpot .
    Adil C.

    Exceptional product, team that genuinely partners with you

    Reviewed on Jun 17, 2026
    Review provided by G2
    What do you like best about the product?
    Reducing CVEs is obviously important, but even more so are the people who work there and the support they provide. They genuinely care about helping their clients get the most out of their products and services.
    What do you dislike about the product?
    Honestly, I cant think of anything that I dislike about them.
    What problems is the product solving and how is that benefiting you?
    Chainguard provides hardened container images that dramatically reduce our CVE exposure. It cuts down the vulnerability noise our team has to triage, letting us focus on shipping product instead of chasing base image issues.
    Information Technology and Services

    Huge CVE Reduction with Chainguard Images, Plus Excellent UI and Documentation

    Reviewed on Jun 15, 2026
    Review provided by G2
    What do you like best about the product?
    The CVE reduction we’ve seen with Chainguard images has been a huge lift for us. The UI offers robust functionality, and it’s well supported by Chainguard’s tooling and integration points. The documentation is excellent, and the team has been amazing—especially Eric and Gem.
    What do you dislike about the product?
    Generally don't have anything to share around dislikes.
    What problems is the product solving and how is that benefiting you?
    Improved supply chain security posture, minimized images, etc.
    Hospital & Health Care

    Well-Engineered, Fast-Updated Secure Container Images with Outstanding Support

    Reviewed on Jun 15, 2026
    Review provided by G2
    What do you like best about the product?
    Chainguard container images are very well engineered, well managed, and well supported. The company stays focused on providing meaningful, effective security, and that focus shows in the overall experience.

    The images are updated promptly as vulnerabilities are resolved by product owners and communities. For example, I was tracking a particularly high-impact npm vulnerability, and our node/npm images were updated within four hours of the release of the new (remediated) npm version.

    Wolfi, as a container-focused Linux distribution, is well planned and well implemented. I especially appreciate the glibc compatibility (in contrast to Alpine).

    Chainguard has also done a great job developing tools and information that can be used in automated processes, rather than only being available via a web page.

    Overall, I’ve appreciated the depth of knowledge on the technical team. I’ve learned a huge amount and added a significant number of security tools based on my conversations with our technical support team. The product support lead for our company has done an amazing job providing everything possible for us to be successful.
    What do you dislike about the product?
    The most difficult issue I’ve encountered when using the Chainguard container images is the complexity of the web pages for the container products.

    My company has a specific need to use only the latest updated version within each supported product major version. Because of that, it was hard to explain to other users which label they should use. For example, I need teams to refer to images by product and major version, e.g., node:24-latest. However, the same image might also be referenced as “node:latest” or “node:24.9,” which created confusion. I ended up developing an internal dashboard to make it clearer which images to use to meet our compliance requirements.

    Note: I understand that many other companies might prefer node:latest or a pinned version, so Chainguard needs to provide all the labels to give customers flexibility and choice. In our case, though, that flexibility made it harder for some of our teams to consistently select the correct option for our needs.
    What problems is the product solving and how is that benefiting you?
    Chainguard provided us with a solution for building containers configured to minimize the attack surface and kept up to date as security patches are released.

    Across our teams, we’ve used images based on a range of distributions, including Ubuntu, Debian, Alpine, and others. Chainguard’s Wolfi OS has been more compatible with glibc-based components, and it’s updated much more frequently than the other container options we’ve used. Chainguard’s container images are the gold standard for deploying and maintaining security-focused containers.
    Computer Software

    Faster way to lower the CVE count with some caveats

    Reviewed on Jun 15, 2026
    Review provided by G2
    What do you like best about the product?
    the idea of not having to think about vulnerabilities
    and their team support
    What do you dislike about the product?
    UI is slighly clunky, the CLI could be improved
    What problems is the product solving and how is that benefiting you?
    Keeping the CVE count low really helps us, because it lets us move faster and avoid having to maintain the base images ourselves.
    Keith B.

    Chainguard: Secure, Minimal Images with World-Class Support

    Reviewed on Jun 12, 2026
    Review provided by G2
    What do you like best about the product?
    What stands out most about Chainguard is the combination of technical excellence, operational maturity, and customer obsession that is rarely found in a single platform.

    First and foremost, the breadth and depth of their image catalog is exceptional. Chainguard provides one of the most comprehensive collections of secure, minimal, and production-ready container images available today. The catalog covers a wide range of modern workloads and significantly reduces the operational burden of building, maintaining, and securing custom base images internally.

    Equally impressive is their flexibility. When an image is not already available in the catalog, the Chainguard team demonstrates a willingness to engage directly with customers and evaluate adding new images based on real-world requirements. This level of responsiveness transforms the relationship from that of a traditional vendor into a true engineering partnership.

    From a security and reliability perspective, the quality of the images themselves is outstanding. The images are thoughtfully curated, continuously maintained, and designed with a strong security-first philosophy. They provide a substantial reduction in vulnerability exposure while preserving compatibility and operational simplicity. For organizations focused on supply chain security, compliance, and reducing risk, Chainguard represents a significant advancement over traditional container image strategies.

    The API they offer is also robust and very polished with a ton of features that are much needed from an operational standpoint that are often not present with other vendors. Chainguard has also curated many helpful tools to help with the process as well.

    The customer experience is equally noteworthy. Their onboarding process is among the best I have encountered. The team is highly knowledgeable, responsive, and capable of engaging at both strategic and deeply technical levels. Whether discussing platform architecture, implementation details, or organizational adoption, they consistently demonstrate expertise and a genuine commitment to customer success.

    The user experience deserves special recognition as well. The platform's UI and UX are exceptionally well designed—clean, intuitive, and efficient. Complex security and image management workflows are presented in a way that is approachable without sacrificing depth or functionality. It is clear that significant attention has been invested in making the platform easy to navigate and operationalize at scale.

    Overall, Chainguard has built a platform that excels across the dimensions that matter most to modern platform engineering and SRE organizations: security, reliability, usability, scalability, and customer partnership. Their extensive image ecosystem, willingness to adapt to customer needs, world-class support organization, and polished user experience make them one of the strongest solutions available for securing and managing containerized workloads.
    What do you dislike about the product?
    There are no real downsides to using chainguard that I've experienced.
    What problems is the product solving and how is that benefiting you?
    One of the biggest challenges Chainguard helps us solve is reducing the operational overhead associated with container image security and vulnerability management. Prior to adopting Chainguard, a significant amount of engineering effort was spent tracking, remediating, rebuilding, and validating container images in response to newly disclosed CVEs. While that work is necessary, it is rarely a differentiating activity for an engineering organization and can quickly consume valuable platform engineering resources.

    Chainguard dramatically shortens the time between vulnerability disclosure and remediation. Their ability to rapidly rebuild and publish updated images allows us to address security findings much faster than we could through internal processes alone. As a result, we are able to maintain a significantly lower vulnerability footprint across our containerized workloads while reducing the operational burden on our teams.

    This has been particularly valuable from a compliance and regulatory perspective. As an organization pursuing and maintaining FedRAMP compliance, minimizing CVE counts and demonstrating strong vulnerability management practices is critical. Chainguard has helped us consistently reduce the number of vulnerabilities identified in our environments, making audits, security reviews, and continuous compliance efforts substantially easier to manage.

    Beyond the direct security benefits, Chainguard allows our engineers to focus on higher-value initiatives rather than spending cycles maintaining base images and chasing vulnerability remediation work. The platform effectively shifts a large portion of the container security lifecycle to a team whose core competency is maintaining secure software supply chains, which improves both our security posture and operational efficiency.

    Ultimately, Chainguard is not just helping us reduce CVEs—it is helping us build a more scalable, secure, and sustainable approach to software supply chain security while freeing engineering resources to focus on delivering business value.
    View all reviews