Minimal vs Minimus

Both projects ship small, hardened, low-CVE container images. This page is the measured comparison: 77 images for which both publish an equivalent, scanned with the same Grype binary against the same frozen database on 2026-07-24.

40
Minimal lower
32
Tied
5
Minimal higher
77
Images compared

Summed across those 77 images, Minimal carries 256 unique CVEs against Minimus's 416. That total is dominated by a handful of images on both sides, so the per-image table below matters more than the sum.

Where Minimal is worse

Leading with this because it is the part a vendor comparison normally hides. On 5 of 77 images Minimal reports more unique CVEs than Minimus:

Image Minimal Minimus Δ Minimal crit/high Minimus crit/high
solr 59 26 +33 4 / 28 0 / 12
jenkins 19 9 +10 1 / 8 1 / 3
zookeeper 23 19 +4 0 / 12 0 / 9
go 1 0 +1 0 / 0 0 / 0
fluent-bit 1 0 +1 0 / 0 0 / 0

Solr is the real outlier and a genuine finding against us — most of its gap traces to bundled Java libraries, with a large share of findings associated with a single netty-codec-http version. Minimus's Solr image does not expose that artifact to the scanner, so part of the difference may be different bundled modules rather than only patch levels. Either way it is ours to fix, and it is tracked.

Full head-to-head

Every image where both projects publish an equivalent, best result first. Δ is Minimal minus Minimus, so negative is better for Minimal.

Image Minimal Minimus Δ Minimal crit/high Minimus crit/high
minio 1 75 -74 0 / 0 10 / 36
cassandra 21 43 -22 0 / 11 0 / 17
opensearch 12 31 -19 0 / 7 0 / 65
pulsar 14 23 -9 0 / 5 0 / 8
python 3 8 -5 0 / 1 0 / 3
trufflehog 6 10 -4 0 / 3 0 / 4
alertmanager 1 4 -3 0 / 0 0 / 2
blackbox-exporter 1 4 -3 0 / 0 0 / 1
caddy 1 4 -3 0 / 0 0 / 1
external-dns 1 4 -3 0 / 0 0 / 1
haproxy 0 3 -3 0 / 0 0 / 1
kube-bench 0 3 -3 0 / 0 0 / 0
loki 1 4 -3 0 / 0 0 / 1
mimir 1 4 -3 0 / 0 0 / 1
oauth2-proxy 1 4 -3 0 / 0 0 / 1
opa 2 5 -3 0 / 1 0 / 2
prometheus 1 4 -3 0 / 0 0 / 2
tempo 1 4 -3 0 / 0 0 / 1
thanos 5 8 -3 0 / 2 0 / 3
traefik 1 4 -3 0 / 0 0 / 1
trivy 3 6 -3 0 / 1 0 / 2
velero 1 4 -3 0 / 0 0 / 2
coredns 1 3 -2 0 / 0 0 / 1
cosign 1 3 -2 0 / 0 0 / 1
deno 0 2 -2 0 / 0 0 / 1
etcd 1 3 -2 0 / 0 0 / 0
flux 1 3 -2 0 / 0 0 / 1
kustomize 0 2 -2 0 / 0 0 / 0
opentofu 3 5 -2 0 / 1 0 / 1
pushgateway 1 3 -2 0 / 0 0 / 0
qdrant 0 2 -2 0 / 0 0 / 0
skopeo 2 4 -2 0 / 1 0 / 1
gitleaks 2 3 -1 0 / 0 0 / 0
grype 6 7 -1 0 / 3 0 / 4
kubectl 0 1 -1 0 / 0 0 / 0
kubeseal 1 2 -1 0 / 0 0 / 0
openbao 1 2 -1 0 / 0 0 / 1
ruby 0 1 -1 0 / 0 0 / 1
syft 1 2 -1 0 / 0 0 / 1
telegraf 2 3 -1 1 / 0 1 / 1
bun 0 0 0 / 0 0 / 0
crane 0 0 0 / 0 0 / 0
dotnet 0 0 0 / 0 0 / 0
envoy 0 0 0 / 0 0 / 0
helm 2 2 0 / 1 0 / 1
httpd 1 1 0 / 0 0 / 0
jaeger 1 1 0 / 0 0 / 0
java 0 0 0 / 0 0 / 0
kafka 17 17 0 / 7 0 / 6
keycloak 23 23 0 / 10 0 / 12
mariadb 0 0 0 / 0 0 / 0
memcached 0 0 0 / 0 0 / 0
mosquitto 0 0 0 / 0 0 / 0
mysql 0 0 0 / 0 0 / 0
nats 1 1 0 / 0 0 / 0
nginx 0 0 0 / 0 0 / 0
node-exporter 1 1 0 / 0 0 / 0
node-slim 1 1 0 / 0 0 / 0
notation 2 2 0 / 1 0 / 1
oras 1 1 0 / 0 0 / 0
otelcol 1 1 0 / 0 0 / 0
pgbouncer 0 0 0 / 0 0 / 0
php 1 1 0 / 0 0 / 0
postgres-slim 0 0 0 / 0 0 / 0
rabbitmq 0 0 0 / 0 0 / 0
redis-slim 0 0 0 / 0 0 / 0
regctl 0 0 0 / 0 0 / 0
sqlite 0 0 0 / 0 0 / 0
tomcat 0 0 0 / 0 0 / 0
unbound 0 0 0 / 0 0 / 0
valkey 0 0 0 / 0 0 / 0
victoria-metrics 0 0 0 / 0 0 / 0
fluent-bit 1 0 +1 0 / 0 0 / 0
go 1 0 +1 0 / 0 0 / 0
zookeeper 23 19 +4 0 / 12 0 / 9
jenkins 19 9 +10 1 / 8 1 / 3
solr 59 26 +33 4 / 28 0 / 12

Minimal also publishes 14 scanned images with no equivalent in this comparison set. Those are excluded entirely rather than scored as wins.

The differences that are not CVE counts

CostMinimal is $0 for the entire catalog, with no tier above it.
LicenceEvery Minimal build recipe is MIT-licensed and in one public repo.
AuthMinimal images pull from GHCR with no account.
Rebuild cadenceMinimal rebuilds the whole catalog every 6 hours.
ProvenanceMinimal publishes cosign signatures, an SPDX SBOM and SLSA v1.0 Build L2 provenance.
Catalogue sizeMinimal is deliberately small. If breadth is what you need, it is the wrong tool.

Statements above describe Minimal, and each is checkable with the commands on the verify page. We deliberately do not characterise Minimus's pricing, licensing or roadmap here — those change, and their site is the authority on them.

Trying it

Pull any image and scan it yourself with the same tool used above:

docker pull ghcr.io/rtvkiz/minimal-python:latest
grype ghcr.io/rtvkiz/minimal-python:latest

Migrating an existing deployment? See migrating from Minimus to Minimal.

How these numbers were produced

  • Scanner: Grype 0.109.1, vulnerability DB schema v6.1.9, built 2026-07-23 07:03:49 UTC.
  • DB checksum: 4089fed48894694510d7e5e2f7b9c261bc636eae459ae881f479a2e61c946046
  • Platform: linux/amd64. Scan date: 2026-07-24.
  • Production latest tags were resolved to immutable digests before scanning, so the run is repeatable.
  • Every image was scanned with the same Grype binary and the same frozen database.
  • Raw Grype findings. No vendor VEX suppression was applied to anyone, including us.
  • Only publicly pullable images were scanned. No paid or private registry credentials were used.

The full 273-row dataset, including the resolved reference and digest for every provider/image pair, is here: cve-comparison-2026-07-24.csv. Every figure on this page is derived from that file.

What this does not prove

latest does not guarantee the same application version or feature set across vendors, so an individual outlier should be version- and feature-matched before it is treated as a product-level claim. A scanner reports known findings visible to one database snapshot; a low count is not proof that an image is free of vulnerabilities. An image a vendor does not publish is counted as not available — never as zero.