Minimal vs Minimus
Both projects ship small, hardened, low-CVE container images. This page is the measured comparison: 77 images for which both publish an equivalent, scanned with the same Grype binary against the same frozen database on 2026-07-24.
Summed across those 77 images, Minimal carries 256 unique CVEs against Minimus's 416. That total is dominated by a handful of images on both sides, so the per-image table below matters more than the sum.
Where Minimal is worse
Leading with this because it is the part a vendor comparison normally hides. On 5 of 77 images Minimal reports more unique CVEs than Minimus:
| Image | Minimal | Minimus | Δ | Minimal crit/high | Minimus crit/high |
|---|---|---|---|---|---|
| solr | 59 | 26 | +33 | 4 / 28 | 0 / 12 |
| jenkins | 19 | 9 | +10 | 1 / 8 | 1 / 3 |
| zookeeper | 23 | 19 | +4 | 0 / 12 | 0 / 9 |
| go | 1 | 0 | +1 | 0 / 0 | 0 / 0 |
| fluent-bit | 1 | 0 | +1 | 0 / 0 | 0 / 0 |
Solr is the real outlier and a genuine finding against us — most of its gap traces to
bundled Java libraries, with a large share of findings associated with a single
netty-codec-http version. Minimus's Solr image does not expose
that artifact to the scanner, so part of the difference may be different bundled modules
rather than only patch levels. Either way it is ours to fix, and it is tracked.
Full head-to-head
Every image where both projects publish an equivalent, best result first. Δ is Minimal minus Minimus, so negative is better for Minimal.
| Image | Minimal | Minimus | Δ | Minimal crit/high | Minimus crit/high |
|---|---|---|---|---|---|
| minio | 1 | 75 | -74 | 0 / 0 | 10 / 36 |
| cassandra | 21 | 43 | -22 | 0 / 11 | 0 / 17 |
| opensearch | 12 | 31 | -19 | 0 / 7 | 0 / 65 |
| pulsar | 14 | 23 | -9 | 0 / 5 | 0 / 8 |
| python | 3 | 8 | -5 | 0 / 1 | 0 / 3 |
| trufflehog | 6 | 10 | -4 | 0 / 3 | 0 / 4 |
| alertmanager | 1 | 4 | -3 | 0 / 0 | 0 / 2 |
| blackbox-exporter | 1 | 4 | -3 | 0 / 0 | 0 / 1 |
| caddy | 1 | 4 | -3 | 0 / 0 | 0 / 1 |
| external-dns | 1 | 4 | -3 | 0 / 0 | 0 / 1 |
| haproxy | 0 | 3 | -3 | 0 / 0 | 0 / 1 |
| kube-bench | 0 | 3 | -3 | 0 / 0 | 0 / 0 |
| loki | 1 | 4 | -3 | 0 / 0 | 0 / 1 |
| mimir | 1 | 4 | -3 | 0 / 0 | 0 / 1 |
| oauth2-proxy | 1 | 4 | -3 | 0 / 0 | 0 / 1 |
| opa | 2 | 5 | -3 | 0 / 1 | 0 / 2 |
| prometheus | 1 | 4 | -3 | 0 / 0 | 0 / 2 |
| tempo | 1 | 4 | -3 | 0 / 0 | 0 / 1 |
| thanos | 5 | 8 | -3 | 0 / 2 | 0 / 3 |
| traefik | 1 | 4 | -3 | 0 / 0 | 0 / 1 |
| trivy | 3 | 6 | -3 | 0 / 1 | 0 / 2 |
| velero | 1 | 4 | -3 | 0 / 0 | 0 / 2 |
| coredns | 1 | 3 | -2 | 0 / 0 | 0 / 1 |
| cosign | 1 | 3 | -2 | 0 / 0 | 0 / 1 |
| deno | 0 | 2 | -2 | 0 / 0 | 0 / 1 |
| etcd | 1 | 3 | -2 | 0 / 0 | 0 / 0 |
| flux | 1 | 3 | -2 | 0 / 0 | 0 / 1 |
| kustomize | 0 | 2 | -2 | 0 / 0 | 0 / 0 |
| opentofu | 3 | 5 | -2 | 0 / 1 | 0 / 1 |
| pushgateway | 1 | 3 | -2 | 0 / 0 | 0 / 0 |
| qdrant | 0 | 2 | -2 | 0 / 0 | 0 / 0 |
| skopeo | 2 | 4 | -2 | 0 / 1 | 0 / 1 |
| gitleaks | 2 | 3 | -1 | 0 / 0 | 0 / 0 |
| grype | 6 | 7 | -1 | 0 / 3 | 0 / 4 |
| kubectl | 0 | 1 | -1 | 0 / 0 | 0 / 0 |
| kubeseal | 1 | 2 | -1 | 0 / 0 | 0 / 0 |
| openbao | 1 | 2 | -1 | 0 / 0 | 0 / 1 |
| ruby | 0 | 1 | -1 | 0 / 0 | 0 / 1 |
| syft | 1 | 2 | -1 | 0 / 0 | 0 / 1 |
| telegraf | 2 | 3 | -1 | 1 / 0 | 1 / 1 |
| bun | 0 | 0 | — | 0 / 0 | 0 / 0 |
| crane | 0 | 0 | — | 0 / 0 | 0 / 0 |
| dotnet | 0 | 0 | — | 0 / 0 | 0 / 0 |
| envoy | 0 | 0 | — | 0 / 0 | 0 / 0 |
| helm | 2 | 2 | — | 0 / 1 | 0 / 1 |
| httpd | 1 | 1 | — | 0 / 0 | 0 / 0 |
| jaeger | 1 | 1 | — | 0 / 0 | 0 / 0 |
| java | 0 | 0 | — | 0 / 0 | 0 / 0 |
| kafka | 17 | 17 | — | 0 / 7 | 0 / 6 |
| keycloak | 23 | 23 | — | 0 / 10 | 0 / 12 |
| mariadb | 0 | 0 | — | 0 / 0 | 0 / 0 |
| memcached | 0 | 0 | — | 0 / 0 | 0 / 0 |
| mosquitto | 0 | 0 | — | 0 / 0 | 0 / 0 |
| mysql | 0 | 0 | — | 0 / 0 | 0 / 0 |
| nats | 1 | 1 | — | 0 / 0 | 0 / 0 |
| nginx | 0 | 0 | — | 0 / 0 | 0 / 0 |
| node-exporter | 1 | 1 | — | 0 / 0 | 0 / 0 |
| node-slim | 1 | 1 | — | 0 / 0 | 0 / 0 |
| notation | 2 | 2 | — | 0 / 1 | 0 / 1 |
| oras | 1 | 1 | — | 0 / 0 | 0 / 0 |
| otelcol | 1 | 1 | — | 0 / 0 | 0 / 0 |
| pgbouncer | 0 | 0 | — | 0 / 0 | 0 / 0 |
| php | 1 | 1 | — | 0 / 0 | 0 / 0 |
| postgres-slim | 0 | 0 | — | 0 / 0 | 0 / 0 |
| rabbitmq | 0 | 0 | — | 0 / 0 | 0 / 0 |
| redis-slim | 0 | 0 | — | 0 / 0 | 0 / 0 |
| regctl | 0 | 0 | — | 0 / 0 | 0 / 0 |
| sqlite | 0 | 0 | — | 0 / 0 | 0 / 0 |
| tomcat | 0 | 0 | — | 0 / 0 | 0 / 0 |
| unbound | 0 | 0 | — | 0 / 0 | 0 / 0 |
| valkey | 0 | 0 | — | 0 / 0 | 0 / 0 |
| victoria-metrics | 0 | 0 | — | 0 / 0 | 0 / 0 |
| fluent-bit | 1 | 0 | +1 | 0 / 0 | 0 / 0 |
| go | 1 | 0 | +1 | 0 / 0 | 0 / 0 |
| zookeeper | 23 | 19 | +4 | 0 / 12 | 0 / 9 |
| jenkins | 19 | 9 | +10 | 1 / 8 | 1 / 3 |
| solr | 59 | 26 | +33 | 4 / 28 | 0 / 12 |
Minimal also publishes 14 scanned images with no equivalent in this comparison set. Those are excluded entirely rather than scored as wins.
The differences that are not CVE counts
| Cost | Minimal is $0 for the entire catalog, with no tier above it. |
| Licence | Every Minimal build recipe is MIT-licensed and in one public repo. |
| Auth | Minimal images pull from GHCR with no account. |
| Rebuild cadence | Minimal rebuilds the whole catalog every 6 hours. |
| Provenance | Minimal publishes cosign signatures, an SPDX SBOM and SLSA v1.0 Build L2 provenance. |
| Catalogue size | Minimal is deliberately small. If breadth is what you need, it is the wrong tool. |
Statements above describe Minimal, and each is checkable with the commands on the verify page. We deliberately do not characterise Minimus's pricing, licensing or roadmap here — those change, and their site is the authority on them.
Trying it
Pull any image and scan it yourself with the same tool used above:
docker pull ghcr.io/rtvkiz/minimal-python:latest
grype ghcr.io/rtvkiz/minimal-python:latest Migrating an existing deployment? See migrating from Minimus to Minimal.
How these numbers were produced
- Scanner: Grype 0.109.1, vulnerability DB schema v6.1.9, built 2026-07-23 07:03:49 UTC.
- DB checksum:
4089fed48894694510d7e5e2f7b9c261bc636eae459ae881f479a2e61c946046 - Platform:
linux/amd64. Scan date: 2026-07-24. - Production
latesttags were resolved to immutable digests before scanning, so the run is repeatable. - Every image was scanned with the same Grype binary and the same frozen database.
- Raw Grype findings. No vendor VEX suppression was applied to anyone, including us.
- Only publicly pullable images were scanned. No paid or private registry credentials were used.
The full 273-row dataset, including the resolved reference and digest for every provider/image pair, is here: cve-comparison-2026-07-24.csv. Every figure on this page is derived from that file.
What this does not prove
latest does not guarantee the same application version or feature
set across vendors, so an individual outlier should be version- and feature-matched before it
is treated as a product-level claim. A scanner reports known findings visible to one database
snapshot; a low count is not proof that an image is free of vulnerabilities. An image a vendor
does not publish is counted as not available — never as zero.