Isolated environments for coding agents
Govern agents and Claws across every team
Your AI Agent across Docker
Local-first LLM inference made easy
Connect and manage MCP tools
Ship with secure, enterprise-ready images
Simplify the software supply chain
Containerize your applications
Discover and share container images
Break free of local constraints
Find guides for Docker products
Learn the Docker basics
Search a library of helpful materials
Skill up your Docker knowledge
Create and share your own extensions
Connect with other Docker developers
Explore open source projects
Help shape the future of Docker
Get inspired with customer stories
Docker Hardened Images
NOW FREE
The new standard for building securely
Minimal and hardened images you can trust.
Get started with DHI Try enterprise Compare plans
Multi-distro compatibility
Near-zero CVEs
Transparent SBOMs
Provenance you can trust
What makes DHI different
Drop-in Adoption
Swap the base image and get instant security gains.
Apache 2.0 on Open Distros
You can migrate to and from with freedom and without surprises. Pay when you need stronger SLAs, compliance, or to leverage our build service.
Easiest path to secure supply chain
Drop-in replacements that require minimal changes. Our event-driven build system keeps images continuously updated, and secure customization allows you to tailor hardened images without breaking provenance.
Built with Docker-Maintained Packages
Every DHI image is built with system packages that Docker builds, patches, and maintains directly from upstream source.
Full Transparency
Signed SBOMs and SLSA Level 3 provenance, with complete CVE data.
Built for Developers, hardened for security
When upstream stops, your protection continues. Up to 5 extra years of hardened patching, SBOMs and provenance.
Security that outlasts upstream
When a software version reaches end-of-life, patches stop but vulnerabilities don’t. DHI ELS gives you up to five more years of hardened coverage.
CVE patching continues after upstream EOL
SBOMs and provenance maintained throughout
Covers the images you rely on most: Node, Python, PostgreSQL, and more
Up and running in seconds
Drop-in migration with minimal workflow changes.
Documentation Browse 1000+ images Migration guide GitHub discussions
“For the first time, I don’t have to worry about what’s hiding in our base images. That mental overhead is gone, and we can finally focus on the security challenges that are unique to Attentive.”
Jacob Rickerd
Principal Security Engineer at Attentive
A complete security model
A secure starting point for every developer and a secure, sustainable path forward for organizations operating at scale.
Free for every developer
Secure, transparent, and no-cost for everyone.
What’s included:
- Hardened, minimal images
- Near-zero CVEs
- Verifiable SBOMs & SLSA Build L3 provenance
- Full, unsuppressed CVE visibility
- Drop-in adoption, no workflow changes
- Full catalog of open source images under Apache 2.0
- Built with Docker Hardened System Packages
- Upstream cadence for Docker-released patches
Starting at $5k/repo
Production-ready security with compliance support
Everything in community, plus:
- FIPS/STIG variants
- Critical CVE fixes < 7 days with SLA-backed continuous patching
- Up to 5 customizations
Contact us for pricing
Advanced security controls and unlimited customization
Everything in select, plus:
- Unlimited customizations, including system packages
- Access to Hardened System Packages repo
- Full catalog access available
- ELS add-on available
- Extended Lifecycle Support
FAQ
What are Docker Hardened Images?
Docker Hardened Images are near-zero CVE, secure-by-default, minimal container images designed to serve as a trusted, verifiable upstream for modern software supply chains. Each image is continuously rebuilt from source, reducing attack surface while patching known CVEs as fixes become available rather than on a manual schedule.
Are Docker Hardened Images free?
Yes. The full Docker Hardened Images catalog is free and open source under the Apache 2.0 license. Any developer can pull and use hardened images from Docker Hub at no cost, with no usage restrictions.
What is the difference between DHI Community, DHI Select, DHI Enterprise, and DHI ELS?
- DHI Community is free and open under the Apache 2.0 license. It includes the full hardened image catalog with near-zero CVEs.
- DHI Select adds SLA-backed CVE remediation (critical fixes within 7 days) and limited image customization.
- DHI Enterprise expands on Select with unlimited customization capabilities and eligibility for Extended Lifecycle Support.
- DHI ELS provides five additional years of security coverage beyond a software version’s end-of-life.
What distributions do Docker Hardened Images support?
Docker Hardened Images support both Alpine and Debian, allowing teams to choose the distribution that matches their existing environment.
How do Docker Hardened Images compare to other hardened image providers?
Docker Hardened Images take a fundamentally different approach by hardening the distributions developers already use rather than requiring migration to proprietary or unfamiliar operating systems.