Images
15 imagesApps & productivity images
Hardened container images in the apps & productivity category. Built from source on Wolfi, scanned to zero fixable CVEs, cosign-signed, and pinned by digest.
0 CVE
adminer
vrana's single-file PHP database manager, a web UI for MySQL/MariaDB, PostgreSQL, and SQLite, served by a hardened PHP runtime. Image only, no chart.
image v5.5.1, 5.4.4, 5.3.0
التطبيقات والإنتاجيةstandardApache-2.00 CVE
drupal
Drupal core, the open-source CMS and content framework. Built from the official release tarball on a hardened Wolfi php-8.4-fpm + nginx runtime (nonroot, read-only rootfs, supervisord); the chart supplies settings.php via ConfigMap and a MySQL backend. Ships the 11.3/11.4 lines (11.2 is held because drupal/core-recommended pins guzzle below its CVE fix).
image v11.4.4
التطبيقات والإنتاجيةstandardGPL-2.0+0 CVE
excalidraw
Open-source virtual whiteboard for sketching hand-drawn-style diagrams. Self-hostable as a static SPA served by hardened nginx, with no backend or account required.
image v0.18.1
التطبيقات والإنتاجيةstandardMIT0 CVE
filebrowser
Web-based file manager with a built-in UI, users, and share links. From source (Vite UI embedded in a static Go binary) on a hardened nonroot Wolfi base; data and served roots are volumes.
image v2.63.18, 2.63.17
التطبيقات والإنتاجيةstandardApache-2.00 CVE
floci
Local AWS cloud emulator and LocalStack Community successor, built from source into a Quarkus fast-jar on a hardened Wolfi JRE. The hardened image runs all 55 of Floci's in-process AWS services nonroot with no Docker socket, covering S3, DynamoDB, SQS, SNS, SES, IAM, STS, KMS, Secrets Manager, API Gateway, Cognito, Kinesis, CloudFormation, Step Functions, EventBridge, CloudWatch, Route53, and more. The 10 Docker-backed services (Lambda, RDS, ElastiCache, MSK, ECS, EKS, OpenSearch, ECR, DocumentDB, Neptune) need the host Docker socket plus root and are out of scope for this image.
image v1.5.34
التطبيقات والإنتاجيةstandardMIT0 CVE
floci-full
Opt-in, NON-hardened companion to the floci image: it runs as root and expects the host Docker socket mounted, which lets it emulate all 65 of Floci's AWS services including the 10 Docker-backed ones (Lambda, RDS, ElastiCache, MSK, ECS, EKS, OpenSearch, ECR, DocumentDB, Neptune). Same from-source Quarkus build and 0-CVE Trivy gate as floci, but running root with a mounted /var/run/docker.sock is a node-root / container-escape surface, so use it only in trusted single-tenant dev or CI. The floci Helm chart selects this image via mode=full behind an explicit acknowledgeRisk gate. Image only, no separate chart.
image v1.5.29
التطبيقات والإنتاجيةstandardMIT0 CVE
ghost
Open-source Node.js publishing platform for blogs, newsletters, and membership sites. Packaged from Ghost's official npm distribution on a hardened Wolfi Node 22; configured entirely via environment and backed by an external MySQL/MariaDB with a content PVC for themes, images, and data.
image v6.55.0
التطبيقات والإنتاجيةstandardMIT0 CVE
mailpit
Email and SMTP testing tool with a web UI for capturing and inspecting messages during development. Image only, no chart.
image v1.30.6
التطبيقات والإنتاجيةstandardMIT0 CVE
matomo
Matomo, the self-hosted web analytics platform and a privacy-respecting alternative to Google Analytics: you keep the raw data. Built from the official release tarball on a hardened Wolfi php-8.3-fpm runtime fronted by nginx built from source (nonroot, read-only rootfs, supervisord), with the vendored twig/twig replaced by 3.28.0 to clear 14 advisories the shipped 3.11.3 carries. The tarball ships no composer.lock, so the recipe re-materialises the dependency inventory from vendor/composer/installed.php purely so scanners can enumerate what is vendored. Image only, no chart.
image v5.12.0, 5.11.2
التطبيقات والإنتاجيةstandardGPL-3.0+0 CVE
miniflux
Minimalist, opinionated RSS and Atom feed reader with a clean web UI and a REST API. Single pure-Go static binary on a hardened nonroot Wolfi base; needs PostgreSQL at runtime (operator-provided).
image v2.3.2
التطبيقات والإنتاجيةstandardApache-2.00 CVE
nextcloud
Nextcloud, the self-hosted file-sync and content-collaboration platform. Reconstructed clean-room on a hardened Wolfi php-8.4-fpm + nginx runtime (nonroot, read-only rootfs); the chart installs via occ and provides a MariaDB backend. Nextcloud is AGPL-3.0-only (strong copyleft).
image v34.0.2
التطبيقات والإنتاجيةstandardAGPL-3.00 CVE
phpmyadmin
phpMyAdmin, the web console for MySQL and MariaDB. Built from the official release tarball on a hardened Wolfi php-8.3-fpm + nginx runtime (nonroot, read-only rootfs, supervisord), with the stale vendored composer deps (twig, symfony/cache, symfony/process, sodium_compat) re-resolved to their fixed releases and the bundled js-cookie prototype-pollution hole patched. Stateless — the chart is a Deployment that supplies config.inc.php via a ConfigMap, keeps the blowfish_secret across upgrades, and can bundle MariaDB.
image v5.2.3
التطبيقات والإنتاجيةstandardGPL-2.0