BM
Brad M.
Senior DevOps Engineer
Small-Business (50 or fewer emp.)
"Chainguard makes securing applications much easier"
4.5/5
What do you like best about Chainguard?

It's simplicity. Changing from a regular Image to use a Chainguard image as the base helps mitigate a lot of vulnerabilities, and it's a change any developer would be able to easily implement.

This is something that I would recommand to any developer or business that is looking to harden their applications. Securing the base image is the first step everyone should take. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

I have some uncertaincies about what the support will look like for users using the Developer Free tier in the future. Would like them to sllow all image versions and not just latest/stable for Free Tier. Review collected by and hosted on G2.com.

Response from Kirby Koo of Chainguard

Thank you, Brad!

Matheus G.
MG
Matheus G.
Software Engineer
Small-Business (50 or fewer emp.)
"Time-Saving, Secure Containers Solutions!"
4.5/5
What do you like best about Chainguard?

Chainguard allows developers to save a lot of time and effort by providing ready-to-use container images that are secure. In addition, the images provided are very lightweight. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

The custom linux distribution may be harder to work with, but wolfi-base is still quite similar to Alpine and hence not too complex. Review collected by and hosted on G2.com.

Verified User in Hospital & Health Care
UH
Verified User in Hospital & Health Care
Enterprise (> 1000 emp.)
"Extremely satisfy with Chainguard support"
5/5
What do you like best about Chainguard?

Chainguard support is excellent and fast. Chainguard images are lean, secure and easy to integrate. Updates are frequent and easy to implement. Users can pull any supported imgages with up-to-date features for frequency of use. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

Base chainguard images include minimum standard security configurations. Distroless prodution images without shell cause some inconvenience for testing, debugging purposes. Users need to learn different way to search and add packages. Review collected by and hosted on G2.com.

Response from Kirby Koo of Chainguard

Love to hear it! Thank you!

Verified User in Computer Software
AC
Verified User in Computer Software
Mid-Market (51-1000 emp.)
"Easy and positive experience"
5/5
What do you like best about Chainguard?

Attentive support team

Well documented service

Easy to use portal/UI

Flexible to customizations we requested Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

None I can think of.

The limiting factor for chainguard is the upstream product maintenaners speed. Review collected by and hosted on G2.com.

Response from Kirby Koo of Chainguard

We appreciate the support. Thank you so much!

Andy T.
AT
Andy T.
Mid-Market (51-1000 emp.)
"Secure software supply chain"
5/5
What do you like best about Chainguard?

Chainguard has a rock solid product offering that's allowed our teams to build on top of a secure foundation. Chainguard's Linux (un)distro and vast library of language runtimes and open source building blocks allowed us to compose a secure software catalog of first and third party software to distribute to our customers. On top of this, all of Chainguard's engineering and customer success staff have been a great pleasure to work with! All our collab is over Slack and they feel like an extended part of the team. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

This falls more to us than Chainguard, but ways to better track all the places we're making use of their base images would be helpful. Review collected by and hosted on G2.com.

Mark M.
MM
Mark M.
Organizer
Enterprise (> 1000 emp.)
"Spend less time talking about CVEs"
5/5
What do you like best about Chainguard?

We've all seen a ton of projects that will detect CVEs but then you have the secondary problem of deciding where the CVE originated from (base image or first party code), how to patch or upgrade, when to patch so not to impact customers, who should own the updates, what to tell customers and compliance...

Chainguard Images removes the CVEs -- no debate, no CVSS, no triaging, no work tickets. It's done. Enterprises that appreciate this problem will see an ROI in weeks if not days. Not to mention that enterprise customers get an SLA for patches -- I challenge anyone to do what they are doing internally without spending millions on a team who does this as a full time job.

Then for the orgs that are investing in the software supply chain risks, they provide provenance, signing, and an accurate SBOM out-of-The box to start your journey in managing a secure software supply chain. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

The free offering is (reasonably) only the :latest tag which might be fine for personal projects but not most production environments. I don't know the costs for individuals or small orgs (I'm an enterprise customer) but its not free. Review collected by and hosted on G2.com.

Nuno D.
ND
Nuno D.
Senior IT System Analyst
Enterprise (> 1000 emp.)
"Software supply chain starts at the container level!"
5/5
What do you like best about Chainguard?

Since its inception, Chainguard has been modernizing the software supply chain ecosystem and one of their most critical work, and often thought for granted, is their containers image repository.

In a perfect world, every end-user company, would create container images that are signed (ever heard about Sigstore? Chainguard created it), have a software bill of materials (SBOMs) and are scanned (0 CVEs) before being used in production.

Well, we don't live in such world and Chainguard, instead of playing the role of "use our base images at your own risk", they moved towards the hardest direction and provide us with updated, signed and scanned base images at their own costs!

Want to have the latest node.js image with 0 CVEs? docker/podman/nerdctl pull cgr.dev/chainguard/node. That's that easy. Nothing to implement, change the source repository and you're good to go.

Of course, for production you should never run the latest image and instead target a specific version. This is where their customer support comes into play by helping you customizing the usage of their images to your needs.

Chainguard took ownership of what I call a "grey area", where providers and customers tend to finger point when something goes wrong. And by doing so, with their team of experts, I can confidently say the container ecosystem feels a little bit more secure, and this means a lot. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

Maybe the only downside I can see about Chainguard efforts, is to know if keeping all these 0 CVEs images on the long term will not impact other sections/innovations due to this very demanding workload.

The company seems to grow at a good pace (not too fast or slow), however the security is a daily fight and the ressources can be limited.

I fully trust their solutions, and believe they automated the most of their tasks. Still, it's a lot of efforts for "only one side" of Chainguard's offering. Review collected by and hosted on G2.com.

Verified User in Computer Software
AC
Verified User in Computer Software
Mid-Market (51-1000 emp.)
"Mix of feelings"
3.5/5
What do you like best about Chainguard?

0 CVE's, Good support, Very good technical team Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

Sometimes we need remind them to update some images Review collected by and hosted on G2.com.

Response from Sarah Haberman of Chainguard

Hey there! Thanks for your review and feedback. It's great to hear that Chainguard is helping with your FedRAMP journey!

EF
Emmanuel F.
Software developer
Small-Business (50 or fewer emp.)
"My experiences using Chainguard Nodejs base image was amazing!"
4.5/5
What do you like best about Chainguard?

- Very small image size,

- Very small to none CVEs from my experiences.

- Very large repo supporting many languages and technologies,

- Ease to use,

- Ease of implementation. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

A great part of it, is free, but for some custom implementation or features , you may pay. Review collected by and hosted on G2.com.

Benjamin Y.
BY
Benjamin Y.
Freelance Developer
Small-Business (50 or fewer emp.)
"Amazing drop-in SECURE replacement for your images!"
5/5
What do you like best about Chainguard?

Chainguard makes it easy to pull and use actually secure images. If you're using images from another registry, in most cases you can just drop in the chainguard images in place. Not only do you get the elimination of CVEs and massive risk, you get an INSANE reduction in size! It's an amazing resource that is somehow available for open use, and comes with a cadre of passionate and attentive people to support. As the registry grows, I can see this becoming my only source of trusted images for platform deployments. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

It's hard to find something to dislike, but perhaps the requirement of authentication to pull images, and also that it's not THE mandatory registry for everyone. Review collected by and hosted on G2.com.