Images
41 imagesSecurity & supply chain images
Hardened container images in the security & supply chain category. Built from source on Wolfi, scanned to zero fixable CVEs, cosign-signed, and pinned by digest.
0 CVE
buildah
Buildah, the daemonless OCI image builder, built from source and run rootless as uid 1001 with crun and fuse-overlayfs, the same setup as the Podman…
image v1.44.1, 1.45.1
الأمن وسلسلة التوريدstandardApache-2.00 CVE
buildkit
BuildKit, the concurrent container image build engine behind docker build, as the rootless variant: buildkitd runs under rootlesskit as uid 1001 on…
image v0.33.1, 0.31.2, 0.32.2
الأمن وسلسلة التوريدstandardApache-2.00 CVE
cert-manager-acmesolver
acmesolver component of cert-manager. The minimal HTTP server cert-manager runs as ephemeral pods to answer ACME http-01 challenge requests during…
image v1.20.4, 1.21.2, 1.21.1
الأمن وسلسلة التوريدstandardApache-2.00 CVE
cert-manager-cainjector
cainjector component of cert-manager. Injects CA bundles into ValidatingWebhookConfigurations, MutatingWebhookConfigurations, APIServices, and…
image v1.21.2, 1.20.4, 1.21.1
الأمن وسلسلة التوريدstandardApache-2.00 CVE
cert-manager-controller
Core controller of cert-manager, the CNCF standard for X.509 certificate management on Kubernetes. Reconciles Certificate, Issuer, ClusterIssuer, and…
image v1.21.2, 1.21.1, 1.20.4
الأمن وسلسلة التوريدstandardApache-2.00 CVE
cert-manager-webhook
Admission webhook component of cert-manager. Validates and mutates cert-manager API resources and serves the conversion webhook for its CRD versions.
image v1.20.4, 1.21.1, 1.21.2
الأمن وسلسلة التوريدstandardApache-2.00 CVE
checkov
Checkov, the static analysis scanner for infrastructure as code (Terraform, CloudFormation, Kubernetes, Helm, Dockerfile, CI configs). From PyPI into…
image v3.3.25
الأمن وسلسلة التوريدstandardApache-2.00 CVE
clamav
ClamAV antivirus engine built from the release tarball. clamd scans streams over TCP 3310 for apps that check uploads, freshclam keeps the signature…
image v1.4.6, 1.5.4
الأمن وسلسلة التوريدstandardGPL-2.00 CVE
connaisseur
Connaisseur, the Kubernetes admission controller that verifies container image signatures (Cosign/Sigstore, Notary v1 and v2) against trust roots…
image v3.12.0, 3.13.0, 3.11.1
الأمن وسلسلة التوريدstandardApache-2.00 CVE
cosign
Sigstore's container-signing CLI. Keyless sign and verify of images, SBOMs, and attestations against the Fulcio/Rekor transparency log. Image only,…
image v3.1.3
الأمن وسلسلة التوريدstandardApache-2.00 CVE
crane
crane, the go-containerregistry CLI for working with images and registries directly (copy, digest, append, export, mutate, catalog). From Wolfi's…
image v0.22.1
الأمن وسلسلة التوريدstandardApache-2.00 CVE
dependency-track
OWASP Dependency-Track API server, the SBOM analysis platform that tracks components across projects and flags known vulnerabilities, outdated and…
image v5.1.2
الأمن وسلسلة التوريدstandardApache-2.0