Verify any image
The point of these images is that you don't have to trust us. Every claim below is checkable from your terminal, no account required.
1 · Pull it (no login)
docker pull ghcr.io/rtvkiz/minimal-python:latest 2 · Verify build provenance (SLSA v1.0, Build L2)
Proves the image was produced by the workflow in the repo, at a specific commit, on a GitHub-hosted runner.
gh attestation verify oci://ghcr.io/rtvkiz/minimal-python:latest --owner rtvkiz 3 · Inspect the SBOM
cosign verify-attestation --type spdxjson \
--certificate-identity-regexp='https://github.com/rtvkiz/minimal/' \
--certificate-oidc-issuer='https://token.actions.githubusercontent.com' \
ghcr.io/rtvkiz/minimal-python:latest \
| jq -r '.payload | @base64d | fromjson | .predicate' > python-sbom.spdx.json How this compares
| Minimal | Chainguard | Docker Hardened | |
|---|---|---|---|
| Catalog size | 108 | Thousands | 1,000+ free |
| Cost | $0, whole catalog | Free tier; paid for the full catalog | $0 for 1,000+ images (Apache-2.0, Dec 2025); paid for SLA/FIPS/STIG |
| Auth to pull | No | No (free tier) | No (community tier) |
| Build recipes public | Yes | Yes | Yes |
| Cosign + SBOM + provenance | Yes (SLSA Build L2) | Yes | Yes (SLSA Build L3) |
| Rebuild cadence | Every 6 hours | Daily or faster | Daily or faster |
Competitor details verified 2026-08-30 from their public documentation; they change often, so check for yourself rather than taking this table's word for it. Our own row is checkable with the commands above.
Reach for Minimal if you want a small, readable catalog you can audit end to end — every recipe is MIT-licensed and in one repo — without an account or a paid tier. The bigger vendors will serve you better if you need thousands of images, a support contract, FedRAMP/STIG paperwork, or SLSA Build L3.
“Free” is no longer a differentiator on its own: Docker released 1,000+ hardened images under Apache-2.0 in December 2025, no account needed. The honest case for Minimal is narrower — a catalog small enough to read end to end, every recipe MIT-licensed in one repo, and no vendor in the loop. See the full comparison.
More
Source, build recipes and security policy live on
GitHub.
Images are published to ghcr.io/rtvkiz/minimal-*.