Verify any image

The point of these images is that you don't have to trust us. Every claim below is checkable from your terminal, no account required.

1 · Pull it (no login)

docker pull ghcr.io/rtvkiz/minimal-python:latest

2 · Verify build provenance (SLSA v1.0, Build L2)

Proves the image was produced by the workflow in the repo, at a specific commit, on a GitHub-hosted runner.

gh attestation verify oci://ghcr.io/rtvkiz/minimal-python:latest --owner rtvkiz

3 · Inspect the SBOM

cosign verify-attestation --type spdxjson \
  --certificate-identity-regexp='https://github.com/rtvkiz/minimal/' \
  --certificate-oidc-issuer='https://token.actions.githubusercontent.com' \
  ghcr.io/rtvkiz/minimal-python:latest \
  | jq -r '.payload | @base64d | fromjson | .predicate' > python-sbom.spdx.json

How this compares

MinimalChainguardDocker Hardened
Catalog size108Thousands1,000+ free
Cost$0, whole catalogFree tier; paid for the full catalog$0 for 1,000+ images (Apache-2.0, Dec 2025); paid for SLA/FIPS/STIG
Auth to pullNoNo (free tier)No (community tier)
Build recipes publicYesYesYes
Cosign + SBOM + provenanceYes (SLSA Build L2)YesYes (SLSA Build L3)
Rebuild cadenceEvery 6 hoursDaily or fasterDaily or faster

Competitor details verified 2026-08-30 from their public documentation; they change often, so check for yourself rather than taking this table's word for it. Our own row is checkable with the commands above.

Reach for Minimal if you want a small, readable catalog you can audit end to end — every recipe is MIT-licensed and in one repo — without an account or a paid tier. The bigger vendors will serve you better if you need thousands of images, a support contract, FedRAMP/STIG paperwork, or SLSA Build L3.

“Free” is no longer a differentiator on its own: Docker released 1,000+ hardened images under Apache-2.0 in December 2025, no account needed. The honest case for Minimal is narrower — a catalog small enough to read end to end, every recipe MIT-licensed in one repo, and no vendor in the loop. See the full comparison.

More

Source, build recipes and security policy live on GitHub. Images are published to ghcr.io/rtvkiz/minimal-*.