Comparing hardened container images

If you are looking for a Chainguard alternative, a Minimus alternative, a replacement for the deprecated Bitnami images, or simply a free source of hardened base images, this section is the honest version: the same scanner, the same database, the same day, published with the raw dataset and with the images where Minimal comes off worse left in.

Which one should you actually use?

Reach for Minimal if you want a small, auditable catalog — 108 images, every recipe MIT-licensed and in one public repo — at no cost, with no account and no paid tier, and you are willing to trade catalog breadth for that.

Reach for a commercial vendor if you need thousands of images, a support contract, FedRAMP or STIG paperwork, SLSA Build L3, or someone contractually obliged to answer the phone. Those are real requirements and this project does not meet them. Minimal publishes SLSA v1.0 Build L2 provenance, and says so rather than rounding up.

Why publish the losses

Because a comparison you cannot check is worth nothing. Solr is the clearest example: Minimal's Solr image carries substantially more findings than Minimus's, and that row is in the table with the same prominence as the wins. The raw CSV is published so you can recompute all of it, and the method is stated so you can disagree with it precisely.

Scan date 2026-07-24 · Grype 0.109.1 · full dataset: cve-comparison-2026-07-24.csv