Ben C.
BC
Ben C.
Senior Software Engineer
Mid-Market (51-1000 emp.)
"Many fewer CVE tickets let me focus on real work"
5/5
What do you like best about Chainguard?

My team had a huge backlog in JIRA of CVEs we had to remediate. Resolving a CVE takes time away from actual work, as we had to wait for the CVE to be resolved, push the fixes, verify the fixes were passing security scans, then finally backport fixes to old releases we maintained.

It all took a long time, was a major effort, and didn't scale well as we had more CVEs than I want to admit :D.

Migrating from our team's existing images to chainguard only took about a day, and now using chainguard images totally saves us from having to deal with these CVEs, and lets us work on actual business problems, and not have to try to figure out how to patch some obscure lib install. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

Sometimes, it's tough to troubleshoot live issues where you need to do kubectl exec into a pod. This is a somewhat rare edge case, but it's something we've run into.

It's also sometimes hard to get certain packages fully working (eg a python pandas packages needs a driver which may not be present in the base image). Review collected by and hosted on G2.com.

Response from Sarah Haberman of Chainguard

Hey Ben 👋 Thanks for the great review! Glad to hear you're having a great experience with Chainguard!

Verified User in Accounting
UA
Verified User in Accounting
Small-Business (50 or fewer emp.)
"Strong Security and a Great Experience So Far"
5/5
What do you like best about Chainguard?

Chainguard is getting a lot of attention because it solves a very real (and growing) problem: software supply chain security—basically making sure the code and containers you run aren’t quietly compromised. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

Nothing yet it can be expensive. Learn g curve Review collected by and hosted on G2.com.

Verified User in Security and Investigations
US
Verified User in Security and Investigations
Mid-Market (51-1000 emp.)
"Great Catalog of FIPS-Compliant Images with Easy Base Image Customization"
5/5
What do you like best about Chainguard?

There is a good catalog of fips compliant images, and they support customization by adding packages directly to a base image. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

Some image were missing which complicated the process of migrating all our services. Review collected by and hosted on G2.com.

Angel B.
AB
Angel B.
Customer Support Supervisor
Small-Business (50 or fewer emp.)
"Easy-to-Use, Secure Container Images"
4/5
What do you like best about Chainguard?

The container images are easy to use and provide a secure environment. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

The integration process is not straightforward, and the cost can be high for individual users. Review collected by and hosted on G2.com.

Verified User in Financial Services
UF
Verified User in Financial Services
Small-Business (50 or fewer emp.)
"Seamless CI/CD Integration and Transparent SBOMs with Chainguard Libraries"
5/5
What do you like best about Chainguard?

The seamless integration with our existing CI/CD pipeline, along with Chainguard’s transparency through SBOM and the overall Chainguard Libraries experience. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

I antipate Chainguard's capability to audit which JS Libraries appear from Chainguard vs NPM even after they're drawn through JFrog/Arctifactory. Review collected by and hosted on G2.com.

Chandra G.
CG
Chandra G.
Senior Release/DevOps Engineer
Enterprise (> 1000 emp.)
"Secure, Minimal, and Well-Supported — A Great Experience with Room for Transparency Improvements"
5/5
What do you like best about Chainguard?

Chainguard Images have been a transformative addition to our software supply chain strategy. The minimal, hardened, and continuously verified container images significantly reduce our attack surface while ensuring compliance and operational reliability.

One of the biggest pain points in container security is managing outdated or bloated base images filled with vulnerabilities. Chainguard solves this brilliantly with distroless, signed images that are continuously updated and come with built-in provenance and SBOMs. It’s clear they’ve thought deeply about what modern development teams need to build secure-by-default applications.

What really sets Chainguard apart, though, is their exceptional support. From day one, their team has been proactive, responsive, and genuinely invested in our success. Whether it was help with integration, optimizing our image choices, or answering security policy questions, their support engineers went above and beyond. Their documentation is also thorough and developer-friendly, which makes onboarding smooth and intuitive.

In summary: Chainguard Images bring peace of mind to any DevSecOps team, and their world-class support makes them a true partner in software supply chain security. Highly recommended for anyone building or deploying containers in a production environment Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

One area that could use improvement is transparency around source code and SBOM (Software Bill of Materials) access. While the images are secure and well-maintained, having easier access to corresponding source repositories and complete SBOMs—preferably in an automated or standardized format—would help us meet internal audit and compliance requirements more seamlessly. Review collected by and hosted on G2.com.

Response from Sarah Haberman of Chainguard

Chandra, thanks for taking the time to write such a thorough review! 🙌

Charlie G.
CG
Charlie G.
SRE Manager
Mid-Market (51-1000 emp.)
"The gold star vendor: sales, onboarding implementation, support, and product"
5/5
What do you like best about Chainguard?

The chainguard team was able to meet us where we were at, move extremely quickly to meet our deadlines, and everything _just worked_. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

Wiz sometimes detects false positives in cgr images. Review collected by and hosted on G2.com.

Response from Sarah Haberman of Chainguard

Charlie, what a great review! We'll take that gold star - thank you! ⭐️

Ken A.
KA
Ken A.
Principal Application Architect
Human Resources
Enterprise (> 1000 emp.)
"We used chainguard base images to"
5/5
What do you like best about Chainguard?

Using chainguard essentially eliminates container library vulnerabilities coming from our Docker base images (as well as standard package installs!). When we scan our chainguard based images with grype, or snyk, the only vulnerabilities left are from our application installs. We are in the process of implementing chainguard base images across the enterprise, and are expecting over 80% reduction in open vulnerabilities across the board. Chainguard's customer support is excellent, they are one of the best software vendors I have ever worked with. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

The only real downside is you have to modify your Dockerfiles to work with the Wolfi OS, which is alpine-like (i.e. you have to use apk, etc.) If your current base image is not alpine based, there is some learning curve and work. Review collected by and hosted on G2.com.

Response from Kirby Koo of Chainguard

Thank you, Ken!

Dan E.
DE
Dan E.
Senior Cybersecurity Engineer
Enterprise (> 1000 emp.)
"Chainguard has changed the game when it comes to remediating vulns in images."
5/5
What do you like best about Chainguard?

I love the ease of use for our dev teams to switch over and cut their vulnerabilities down. Integrating it into our pipelines has been very easy. Customer support has been excellent and responsive. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

At this time of using the product I do not have any dislikes Review collected by and hosted on G2.com.

Response from Kirby Koo of Chainguard

Aww, thanks for taking the time to review us! Your support means a lot :)

VISHNU V.
VV
VISHNU V.
DevOps Engineer
Enterprise (> 1000 emp.)
"Great FIPS compliant images"
5/5
What do you like best about Chainguard?

Zero CVE images which we can directly consume in our products Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

Nothing as of now which we have encountered Review collected by and hosted on G2.com.

Response from Sarah Haberman of Chainguard

Thanks for the great review, Vishnu! So happy to hear that our FIPS containers are helping you ship to federal customers! 🚀