What each tag means, which one to pin, and how to track a major line without being moved across a breaking release.
Docs
How to use the images, and how they are kept current. For the full inventory see Images; to check the claims yourself see Verify.
Most images ship a -dev companion with a shell and toolchain, for multi-stage builds and in-cluster debugging.
Two independent update loops plus transitive dependency patching — and the guardrails that stop an image going stale unnoticed.
Why a green build does not mean zero CVEs, what VEX changes, and how the raw and effective counts differ.
Grype and Trivy can report different counts for the same image and both be right. What a finding proves, when it is not an exposure, and when it is.
Contributing
Build recipes, the onboarding checklist, and local build instructions live in the repository: github.com/rtvkiz/minimal.