Best Software for 2025 is now live!
Show rating breakdown
Save to My Lists
Paid
Claimed
Optimized for quick response

Chainguard Reviews & Product Details

Drew W.
DW
Senior Principal Software Engineer
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about Chainguard?

I was extremely happy with how trivial it was to swap in their FIPS images in place of the FOSS images we were using. They had a whole onboarding call, but we'd already deployed them to development as it was that fast and easy. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

Their pricing was a battle, they don't differentiate between very simple images and very complex ones, so making the case to use them fully is very difficult. I think a pricing model that more accurately reflects their value add would help, as some images are inherently more complex to replace than others. Review collected by and hosted on G2.com.

What problems is Chainguard solving and how is that benefiting you?

They have FIPS support and vulnerability management via SCA. Review collected by and hosted on G2.com.

Response from Kirby Koo of Chainguard

Thank you for the support, Drew!

Chainguard Overview

What is Chainguard?

Chainguard Images is a type of container image that helps users deploy minimalist, continuously updated, and verifiably hardened container images for cloud-native applications with low to no CVEs. Chainguard Images addresses the critical need for secure, up-to-date container images in modern software development and deployment pipelines. Aimed at Developers or Platform teams, security professionals, and organizations adopting cloud-native technologies, this product enhances the security posture of containerized applications while simplifying maintenance and reducing potential attack surfaces. Key features and benefits of Chainguard Images: • Minimal Base Images: Stripped-down container images that contain only the essential components needed to run applications, reducing the attack surface and potential vulnerabilities. • Continuous Updates: Automated patching and updating of images to ensure the latest security fixes are always incorporated, without manual intervention. • Provenance and Attestations: Cryptographic signatures and built-time software bills of materials (SBOMs) that provide independently verifiable evidence of image origins and contents (Cosign and Sigstore). • Language-Specific Variants and curated OSS catalog: Optimized images for popular programming languages and frameworks, allowing developers to easily adopt secure practices without sacrificing familiarity or functionality. Hundreds of open source projects available in our public registry at images dot chainguard dot dev • Compatibility: Designed to work seamlessly with existing container orchestration platforms and CI/CD pipelines, enabling easy integration into current workflows. Chainguard Images serves several key use cases in the realm of cloud-native security. It enables organizations to meet stringent compliance requirements by providing FIPS hardened, STIG-ready images. The product also significantly reduces the time and effort required for image maintenance and security patching, allowing development teams to focus on building and improving applications rather than managing infrastructure security. For organizations concerned with supply chain security, Chainguard Images offers a trusted source of container images that are built with security best practices from the ground up. This approach helps mitigate risks associated with using third-party images or maintaining custom images in-house. The product is particularly valuable in highly regulated industries such as finance, healthcare, and government, where security and compliance are paramount. However, any organization deploying containerized applications can benefit from the enhanced security and operational efficiencies provided by Chainguard Images. By leveraging Chainguard Images, users can expect to see improvements in their overall security posture, reduction in vulnerabilities, and increased confidence in the integrity of their deployed applications. The product's focus on minimalism and continuous updates also contributes to better performance and reduced resource consumption in container environments.

Chainguard Details
Product Website
Languages Supported
English
Show LessShow More
How do you position yourself against your competitors?

G2 should create a Hardened Container Image category for products like Chainguard Images 😉.

In the mean time, Chainguard Images offers distinct advantages over DIY container image security solutions:

1. Cost-effectiveness: It avoids the sunken cost fallacy of in-house solutions, providing a ready-to-use, professionally maintained alternative.

2. Specialized expertise: Chainguard's exclusive focus on container image security results in more robust measures than typical internal solutions.

3. Reduced operational burden: By eliminating the need for custom image pipelines, it frees up engineering resources for core competencies.

4. Continuous improvement: Unlike potentially stagnant DIY solutions, Chainguard Images evolves with emerging threats and best practices.

5. Faster time-to-market: It significantly reduces implementation time for secure container practices, enabling quicker and more secure application deployment compared to building systems from scratch.


Seller Details
Company Website
Year Founded
2021
HQ Location
Kirkland, WA
Twitter
@chainguard_dev
5,805 Twitter followers
LinkedIn® Page
www.linkedin.com
249 employees on LinkedIn®
Description

Founded by the industry's leading experts on open source software, security and cloud native development, we provide secure container images with low-to-no CVEs.


Jordi M.
JM
Overview Provided by:
Director of Product Marketing at Weaveworks

Recent Chainguard Reviews

Verified User
A
Verified UserMid-Market (51-1000 emp.)
3.5 out of 5
"Mix of feelings"
0 CVE's, Good support, Very good technical team
Verified User
A
Verified UserEnterprise (> 1000 emp.)
4.5 out of 5
"Good range of base images, great support"
Since adopting Chainguard the number of vulnerabilities our scanning tools have found in our services has dramaticdally decreased. Chainguard also ...
Verified User
U
Verified UserEnterprise (> 1000 emp.)
5.0 out of 5
"Extremely satisfy with Chainguard support"
Chainguard support is excellent and fast. Chainguard images are lean, secure and easy to integrate. Updates are frequent and easy to implement. U...
Security Badge
This seller hasn't added their security information yet. Let them know that you'd like them to add it.
0 people requested security information

Chainguard Media

Chainguard Demo - Vulnerability Comparison
Comparing the external Golang image to the latest Go Chainguard Image.
Chainguard Demo - Chainguard Image Directory
Find, browse, discover, and get started using minimal, hardened images from Chainguard for all of your application needs.
Chainguard Demo - Security Advisories
Our self-serve portal helps you find the latest information about CVEs, including when the CVE was detected, the current CVE remediation status in a specific Chainguard Image package, and the version of the software it’s fixed in. You can search for a specific CVE ID or filter down to only the so...
Chainguard Demo - Provenance
Detailed provenance information about each of our Images, including docker pull commands, all available tags and variants, and information about verifying our Images' signatures, Software Bill of Materials (SBOMs), and Supply chain Levels for Software Artifacts (SLSA) provenance.
Chainguard Images summary
Play Chainguard Video
Chainguard Images summary
How Chainguard Images are created with low to no CVEs
Play Chainguard Video
How Chainguard Images are created with low to no CVEs
Achieving reproducible builds with Chainguard Images
Play Chainguard Video
Achieving reproducible builds with Chainguard Images
Debugging minimal Chainguard Images
Play Chainguard Video
Debugging minimal Chainguard Images
How Snowflake uses Chainguard Images to deploy secure software to their customers.
Play Chainguard Video
How Snowflake uses Chainguard Images to deploy secure software to their customers.
Answer a few questions to help the Chainguard community
Have you used Chainguard before?
Yes

30 out of 31 Total Reviews for Chainguard

4.9 out of 5
The next elements are filters and will change the displayed results once they are selected.
Search reviews
Popular Mentions
The next elements are radio elements and sort the displayed results by the item selected and will update the results displayed.
Hide FiltersMore Filters
The next elements are filters and will change the displayed results once they are selected.
The next elements are filters and will change the displayed results once they are selected.
30 out of 31 Total Reviews for Chainguard
4.9 out of 5
30 out of 31 Total Reviews for Chainguard
4.9 out of 5

Chainguard Pros and Cons

How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Cons

Overall Review Sentiment for ChainguardQuestion

Time to Implement
<1 day
>12 months
Return on Investment
<6 months
48+ months
Ease of Setup
0 (Difficult)
10 (Easy)
Log In
Want to see more insights from verified reviewers?
Log in to view review sentiment.
G2 reviews are authentic and verified.
Ken A.
KA
Principal Application Architect
Human Resources
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about Chainguard?

Using chainguard essentially eliminates container library vulnerabilities coming from our Docker base images (as well as standard package installs!). When we scan our chainguard based images with grype, or snyk, the only vulnerabilities left are from our application installs. We are in the process of implementing chainguard base images across the enterprise, and are expecting over 80% reduction in open vulnerabilities across the board. Chainguard's customer support is excellent, they are one of the best software vendors I have ever worked with. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

The only real downside is you have to modify your Dockerfiles to work with the Wolfi OS, which is alpine-like (i.e. you have to use apk, etc.) If your current base image is not alpine based, there is some learning curve and work. Review collected by and hosted on G2.com.

What problems is Chainguard solving and how is that benefiting you?

We have a significant backlog of known container vulnerabilities in our containers. Hardening and managing clean base images is a lot of work and takes specialized expertise that our development teams don't have. Changuard provides base images that work out of the box for most of our tech stacks and alleviates the need to manage hardened base images ourselves. Review collected by and hosted on G2.com.

Response from Kirby Koo of Chainguard

Thank you, Ken!

Karl H.
KH
Senior Principal Architect
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about Chainguard?

Since implementing Chainguard's hardened base images, we've seen a dramatic reduction in vulnerabilities—over 70%. This reduction not only enhances our security posture but also saves our engineering teams an enormous amount of time that would otherwise be spent on vulnerability management and patching. Chainguard's approach introduces excellent security practices out of the box, meaning our engineers no longer have to worry about critical security concerns like rootless containers, proper permissions, and secure registries.

Chainguard sets itself apart by providing supply chain security through purpose-built packages in their registry, making it clear that while competitors might still be playing catch-up in the minor leagues, Chainguard is clearly in a league of its own, setting the standard for supply chain security. We've maximized the value of these images by ensuring reuse across our organization, categorizing images into language-based and application-based groups. This strategy allows us to gain the most value through frequent reuse of language-based images, while our centralized platform engineering teams benefit from using application-specific images at a different scale.

To drive adoption, we've integrated Chainguard images into our centralized internal developer portal, which our developers are already familiar with and use regularly. This seamless integration has significantly boosted adoption rates, further supported by our vulnerability management reduction program. Through this program, we've been able to recommend Chainguard images, reassuring teams that transitioning will save time and energy.

The service level agreements (SLAs) provided by Chainguard are also very attractive. The high speed of image updates ensures that we are always protected with the latest security enhancements. We've even integrated Chainguard into our automatic update tools, so our developers are always confident that they're working with the most up-to-date versions.

Overall, Chainguard's hardened base images have been a game-changer for our organization, providing unparalleled security, efficiency, and peace of mind. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

The documentation at times fall a little behind and the modern authentication mechanisms at times can create difficulties in integrating with other existing platforms that are not yet supportive of technologies like OIDC. Quite a few of the images require rework to convert from a standard Dockerhub image however, I believe that's expected. Review collected by and hosted on G2.com.

What problems is Chainguard solving and how is that benefiting you?

Reducing container, image, vulnerabilities and creating a solid secure base to build upon Review collected by and hosted on G2.com.

Response from Kirby Koo of Chainguard

Thank you, Karl!! Your support means the world to us :)

Verified User in Defense & Space
ED
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about Chainguard?

Chainguard has allowed us to develop at speed and scale allowing us to focus on features more than the development overhead, especially in mitigating CVEs. That said, the team that we interact with is the best part of Chainguard. Responsive, intelligent, and customer obsessed is the main reason we value and continue our relationship. Couldn't be happier. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

There isn't anything we don't like that I can think of. Review collected by and hosted on G2.com.

What problems is Chainguard solving and how is that benefiting you?

Chainguard helps our engineers focus on developing features. Previously, most time was spent trying to mitigate CVEs and our customers were getting new features deployed. Using Chainguard has significantly shifted that paradigm. Developing in the DoD landscape is harder than the private sector and this helps a lot. Review collected by and hosted on G2.com.

Response from Kirby Koo of Chainguard

Wow! The feeling is mutual :) Thank you!

Leonardo Z.
LZ
Senior Software Architect
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about Chainguard?

Security is hard on its own, and while many vendors focus on selling detection products, Chainguard does the opposite and solve a painful problem with little effort from users. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

Chainguard offers some free to use images, but only "latest" version and not stable versions. This makes impossible to use as an individual or for open source projects. Review collected by and hosted on G2.com.

What problems is Chainguard solving and how is that benefiting you?

Zero security vulnerability containers. Review collected by and hosted on G2.com.

Response from Kirby Koo of Chainguard

Thank you, Leo! We appreciate you!

MW
Cyber Security Consultant (AppSec Area)
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Review source: Organic
What do you like best about Chainguard?

I wrote a paper on container image security, evaluating the security of containers through reduction of potentially vulnerable components. It concludes that the usage of component reduction methods significantly reduces the amount of security vulnerabilities within container images. It also finds that, even though the probability of exploitation of the majority of vulnerabilities found by scanners is very low, employing them still is a strategically sound decision. When comparing different images with component reduced (i.e. "distroless images") alternatives, chainguard did by far the best job. As a consultant supporting product security teams in large enterprises we are recommending to integrate chainguard images to development teams and decision makers. It will save a lot of dicsussions, headaches and money!

Please find the paper here: https://mwager.de/assets/component_reduction_paper.pdf Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

Nothing so far. Have a look at the paper, it clearly shows that Chainguard did the best job compared to all other alternatives. Review collected by and hosted on G2.com.

What problems is Chainguard solving and how is that benefiting you?

Chainguard provides container images containing zero CVEs (security vulnerabilities within the supply chain) for a lot of relevant runtimes and popular services, is easy to use and integrate and also provides excellent documentation. Review collected by and hosted on G2.com.

Response from Kirby Koo of Chainguard

Thank you for sharing your research paper & review, Michael! We appreciate it!

Verified User in Banking
AB
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about Chainguard?

Since adopting Chainguard the number of vulnerabilities our scanning tools have found in our services has dramaticdally decreased. Chainguard also offers a good range of base images and has been able to build custom app images for us. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

Initial learning curve on how to migrate from standard base images to Chainguard images. We have had issues integrating Chainguard's Docker registry with out artifact storage tool. Review collected by and hosted on G2.com.

What problems is Chainguard solving and how is that benefiting you?

Automating the patching of our base images, so our team doesn't need to worry about it. Review collected by and hosted on G2.com.

Response from Kirby Koo of Chainguard

Thank you for the review!

BM
Senior DevOps Engineer
Small-Business(50 or fewer emp.)
More Options
Validated Reviewer
Review source: Organic
What do you like best about Chainguard?

It's simplicity. Changing from a regular Image to use a Chainguard image as the base helps mitigate a lot of vulnerabilities, and it's a change any developer would be able to easily implement.

This is something that I would recommand to any developer or business that is looking to harden their applications. Securing the base image is the first step everyone should take. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

I have some uncertaincies about what the support will look like for users using the Developer Free tier in the future. Would like them to sllow all image versions and not just latest/stable for Free Tier. Review collected by and hosted on G2.com.

What problems is Chainguard solving and how is that benefiting you?

Bring simplicity to security. It hardens the application image that our containers use to run. Review collected by and hosted on G2.com.

Response from Kirby Koo of Chainguard

Thank you, Brad!

Matheus G.
MG
Software Engineer
Small-Business(50 or fewer emp.)
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about Chainguard?

Chainguard allows developers to save a lot of time and effort by providing ready-to-use container images that are secure. In addition, the images provided are very lightweight. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

The custom linux distribution may be harder to work with, but wolfi-base is still quite similar to Alpine and hence not too complex. Review collected by and hosted on G2.com.

What problems is Chainguard solving and how is that benefiting you?

They provide off the shelf image solutions to secure you deployment/release containers. In other words, Chainguard allows you to secure the environment in which you deploy your applications to. Review collected by and hosted on G2.com.

Verified User in Hospital & Health Care
UH
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about Chainguard?

Chainguard support is excellent and fast. Chainguard images are lean, secure and easy to integrate. Updates are frequent and easy to implement. Users can pull any supported imgages with up-to-date features for frequency of use. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

Base chainguard images include minimum standard security configurations. Distroless prodution images without shell cause some inconvenience for testing, debugging purposes. Users need to learn different way to search and add packages. Review collected by and hosted on G2.com.

What problems is Chainguard solving and how is that benefiting you?

Using Chainguard container images help minimizing security vulnerabities and attack surfaces. Review collected by and hosted on G2.com.

Response from Kirby Koo of Chainguard

Love to hear it! Thank you!

Verified User in Computer Software
AC
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about Chainguard?

Attentive support team

Well documented service

Easy to use portal/UI

Flexible to customizations we requested Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

None I can think of.

The limiting factor for chainguard is the upstream product maintenaners speed. Review collected by and hosted on G2.com.

What problems is Chainguard solving and how is that benefiting you?

We use chainguard images to reduce vulnerabilities and to support FIPS compliance.

They provide updates to OS packages and product dependencies which takes a singificant effort for product development teams.

FIPS compliance also important for ua to deliver our products to federal government customers/prospects. Chainguard makes it easy for us to maintain FIPS compliance by providing us base FIPS images and 3rd party FIPS images. We don't have to do the research and maintenance on our side. Review collected by and hosted on G2.com.

Response from Kirby Koo of Chainguard

We appreciate the support. Thank you so much!