Shell-less Python 3 runtime built on Wolfi.
Free hardened container images
Free. Signed. Verifiable. Small images — most built from source — rebuilt every six hours, each one cosign-signed with an SPDX SBOM and SLSA v1.0 build provenance. No account, no Docker Hub pull limits.
Pull and verify in 30 seconds
You don't have to trust us — check the provenance yourself.
# Pull — public, no login, no Docker Hub pull limits
docker pull ghcr.io/rtvkiz/minimal-python:latest
# Verify build provenance (SLSA v1.0, Build L2)
gh attestation verify oci://ghcr.io/rtvkiz/minimal-python:latest --owner rtvkiz What every image ships with
Signed, scanned, and rebuilt on a schedule — the same guarantees on every production tag.
Cosign keyless signature
Verifiable against the public Rekor transparency log — no keys to manage.
SPDX SBOM attestation
Every package, version and license, attached as an in-toto attestation.
SLSA v1.0 provenance
Cryptographic proof of which workflow, commit and runner built the image.
CVE scan every rebuild
Grype runs on every production image each cycle; results published here and in the GitHub Security tab.
Non-root by default
Runs as UID 65532 unless the upstream insists otherwise.
No shell where possible
Most images don't ship /bin/sh, shrinking the attack surface.
Common questions
Short answers to what people ask before swapping a base image.
Are these hardened container images really free?
Yes — all 130 images are free for any use, including commercial, under the MIT license. There is no paid tier, no free-trial window, and no image held back behind a subscription. The catalogue you see is the whole catalogue.
Do I need an account to pull them?
No. Images are published to the GitHub Container Registry as public packages, so an anonymous docker pull works with no login, no token and none of the Docker Hub anonymous pull-rate limits.
What makes a container image "hardened"?
Here it means four concrete things: the image ships only the packages the application needs, most images have no shell or package manager, the default user is non-root (UID 65532), and every published tag carries a cosign signature, an SPDX SBOM and SLSA v1.0 build provenance you can verify yourself.
How often are the images rebuilt?
Every six hours. A rebuild picks up new Wolfi packages, so a fix that lands upstream reaches a published tag the same day rather than at the next release. Each rebuild is re-scanned with Grype and the counts are published on this site.
How do these compare to Chainguard, Minimus or Docker Hardened Images?
The comparison pages publish head-to-head Grype scans run against a single pinned vulnerability database, including the images where Minimal has more CVEs than the alternative. The short version: comparable hardening and provenance, MIT-licensed and free, with a much smaller catalogue than the commercial vendors.
Can I debug an image with no shell?
Most images ship a -dev companion tag that adds a shell and a toolchain. Use the -dev variant as the build stage or for interactive debugging, and ship the shell-less production tag.
Popular images
A few of the 130 available. See all →
Shell-less Node.js runtime built on Wolfi.
Go builder image built on Wolfi.
Shell-less Nginx built on Wolfi.
PostgreSQL built on Wolfi.
Shell-less Redis built from source via melange.