Chainguard Images - GovCloud
ChainguardReviews from AWS customer
0 AWS reviews
-
5 star0
-
4 star0
-
3 star0
-
2 star0
-
1 star0
External reviews
47 reviews
from
External reviews are not included in the AWS star rating for the product.
Great Catalog of FIPS-Compliant Images with Easy Base Image Customization
What do you like best about the product?
There is a good catalog of fips compliant images, and they support customization by adding packages directly to a base image.
What do you dislike about the product?
Some image were missing which complicated the process of migrating all our services.
What problems is the product solving and how is that benefiting you?
It is helping us achieve fedramp high which expands our client base.
Secure, Low-Vulnerability Containers That Integrate Seamlessly into Our Pipelines
What do you like best about the product?
Chainguard zero- and minimum-vulnerability containers help us deliver secure services and products to our customers with less effort and reduced cybersecurity risk. These containers are a 1-to-1 replacement for existing publicly available containers, and they integrate easily into our development pipelines with no additional effort.
What do you dislike about the product?
Chainguard containers are expensive. However, when I consider how many staff hours go into building and maintaining hardened, low-vulnerability containers for applications, the cost does pay off.
What problems is the product solving and how is that benefiting you?
Chainguard helps reduce cybersecurity risks and the effort associated with our applications by providing secure open-source containers. This, in turn, lowers our need to build and maintain low-vulnerability forks of open-source packages.
Secured Workloads with Excellent Support
What do you like best about the product?
I like the hardened images and their support for debugging and other channels. I appreciate the vLLM and OSS support along with the images that we need major upgrades for. I also like their release cadence and find their customer support to be good. I value the minimal, hardened, continuously patched base images that work with vLLM, which has a fast release cadence and evolving dependencies. I also like the immutable image tags, SBOM, and continuous rebuild features.
What do you dislike about the product?
I find the lack of easy migration guides and more FDE support frustrating. Also, the initial setup was problematic for GPU services as core NVIDIA images are not supported.
What problems is the product solving and how is that benefiting you?
I use Chainguard for hardened images, better CVE metrics, securing workloads without root access, and aligning with compliance requirements.
Essential for CVE-Free Container Management
What do you like best about the product?
I appreciate Chainguard's extensive range of catalog with more than 500 public images to choose from, which significantly enhances my experience by ensuring that an image such as Linkerd is available and likely vulnerability-free compared to other sources like DockerHub. The availability of such a vast selection of images provides us with assurance and flexibility, making it easier to maintain security standards. I value the proactive approach of Chainguard in addressing CVEs by ensuring the images are rebuilt daily, which gives me confidence in their security posture. Additionally, I find the initial setup process to be very easy, and I enjoy the self-management feature allowing me to choose the right images from the catalog effortlessly.
What do you dislike about the product?
It would be great if Chainguard's container registry could sync with AWS ECR so I could use my own private registry instead. I believe it's being worked on though.
What problems is the product solving and how is that benefiting you?
I use Chainguard for vulnerability-free container images, addressing CVE vulnerabilities and rebuilding daily. It offers over 500 compatible public images, enhancing security by avoiding CVE-prone DockerHub alternatives.
Effortless Supply Chain Security with Seamless Integration
What do you like best about the product?
What I appreciate most about Chainguard is how it simplifies and strengthens software supply chain security. The platform offers transparent visibility into dependencies, vulnerabilities, and build pipelines, all without introducing unnecessary complexity. I also value its seamless integration with our existing workflows, which enables our team to identify potential issues early and maintain confidence in our software releases. The combination of automation and practical insights truly sets it apart.
What do you dislike about the product?
The main challenge I’ve encountered with Chainguard is that the initial setup and configuration process can be somewhat time-consuming, particularly if you’re dealing with complex pipelines or managing several environments. After the setup is complete, everything operates smoothly, but getting all the integrations in place and fine-tuning the system at the start does demand some effort.
What problems is the product solving and how is that benefiting you?
Chainguard addresses the challenges of software supply chain security and dependency management. It enables us to spot vulnerabilities, apply necessary policies, and guarantee that only trusted components are included in our builds. As a result, we experience fewer security risks, quicker identification of potential problems, and greater assurance in the reliability of our software releases. The tool streamlines our workflow by saving time, minimizing manual checks, and providing our team with peace of mind that our pipelines remain secure.
Effortless Security and Zero CVEs for Container Images
What do you like best about the product?
Chainguard provides a strong security approach for container images and supply chain hygiene the images are minimal and well maintained by them and fully SBOM verified with consistently updated which reduces operational risk
the platform makes it easy to adopt secure by default practices without adding overhead to CI/CD pipelines and it helps a security companies to have images with zero CVEs
the platform makes it easy to adopt secure by default practices without adding overhead to CI/CD pipelines and it helps a security companies to have images with zero CVEs
What do you dislike about the product?
I think the only concern is the pricing that can be a bit high for smaller teams
What problems is the product solving and how is that benefiting you?
Chainguard solves the ongoing challenge of keeping container images secure with zero CVEs instead of start patching these images from week to week
Easy-to-Use, Secure Container Images
What do you like best about the product?
The container images are easy to use and provide a secure environment.
What do you dislike about the product?
The integration process is not straightforward, and the cost can be high for individual users.
What problems is the product solving and how is that benefiting you?
Vulnerability scanner which helps me detect complex issues easily.
Great product, great customer service
What do you like best about the product?
A wealth of images and packages at the highest standard of security.
What do you dislike about the product?
It’s kinda pricey for a startup, but, ultimately, worth it
What problems is the product solving and how is that benefiting you?
Building rocket images on top of very secure base images, using secured packages.
The gold star vendor: sales, onboarding implementation, support, and product
What do you like best about the product?
The chainguard team was able to meet us where we were at, move extremely quickly to meet our deadlines, and everything _just worked_.
What do you dislike about the product?
Wiz sometimes detects false positives in cgr images.
What problems is the product solving and how is that benefiting you?
Passing audits, and getting our vuln counts to zero.
Why we chose Chainguard for securing container images
What do you like best about the product?
Chainguard’s minimalist, hardened container images with zero known CVEs, is going to significantly reduce our vulnerability management overhead. Not having to constantly chase patch cycles will save our teams countless hours.
The images are not just secure by default but gives us the confidence in both their integrity and provenance. We are currently looking at wider adoption across our teams and the society. What sets Chainguard apart is their commitment to transparency and compliance, making them a top choice for organisations with high security and regulatory requirements. If you are looking to build a secure, resilient container strategy, Changuard is worth serious consideration.
The images are not just secure by default but gives us the confidence in both their integrity and provenance. We are currently looking at wider adoption across our teams and the society. What sets Chainguard apart is their commitment to transparency and compliance, making them a top choice for organisations with high security and regulatory requirements. If you are looking to build a secure, resilient container strategy, Changuard is worth serious consideration.
What do you dislike about the product?
This is very stage at the moment, but we look forward to working closely with Chainguard for feedbacks we get from our team as we start our wider rollout.
What problems is the product solving and how is that benefiting you?
We spend countless hours triaging CVEs, chasing patches and validating fixes - only to repeat the process when another image or dependency gets flagged. This endless cycle drains time, and slows down releases, Chainguard addresses this by eliminating the problem at the source with their secure, minimal images.
Shift left has become a must in modern DevSecOps, pushing security earlier into the development cycle to catch vulnerabilities before they reach production. By embedding security early in our CICD pipelines, Chainguard will allow the team to focus on building features and not fixing vulnerabilities, it's about making left lighter.
Shift left has become a must in modern DevSecOps, pushing security earlier into the development cycle to catch vulnerabilities before they reach production. By embedding security early in our CICD pipelines, Chainguard will allow the team to focus on building features and not fixing vulnerabilities, it's about making left lighter.
showing 1 - 10