[go: up one dir, main page]

Introducing G2.ai, the future of software buying.Try now
Share your insights with Chainguard

Thousands of people like you come to G2 to find out whether solutions like Chainguard are the right fit for them. Share your real experiences with Chainguard and the G2 community and help someone make the right decision about their software.

It's been two months since this profile received a new review
Leave a Review

Chainguard Reviews & Product Details

Mathieu B.
MB
Senior Customer Success Engineer
Small-Business (50 or fewer emp.)
"Chainguard’s container images, towards effortless and strong security posture"
What do you like best about Chainguard?

I was looking for replacing my base images with more a secure approach (i.e. distroless), Chainguard images were a great fit because easy to use and well maintained. The other aspect is the customer support that the Chainguard team is providing, even with the free container images. As an example, they took my feedback, answered my questions as well as educated around the different concepts. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

Not yet widely used out there, but it's coming as more awareness and education are provided and shared. I haven't built my own container image with wolfi, melange and apko yet, as I will to spend more time to get started with them. Review collected by and hosted on G2.com.

Chainguard Product Details

Value at a Glance

Averages based on real user reviews.

Time to Implement

2 months

Chainguard Media

Chainguard Demo - Secure-by-default container images
Build software better with minimal, zero-CVE container images guarded under our industry-leading remediation SLA.
Chainguard Demo - Chainguard Image Directory
Find, browse, discover, and get started using minimal, hardened images from Chainguard for all of your application needs.
Chainguard Demo - Security Advisories
Our self-serve portal helps you find the latest information about CVEs, including when the CVE was detected, the current CVE remediation status in a specific Chainguard Image package, and the version of the software it’s fixed in. You can search for a specific CVE ID or filter down to only the so...
Chainguard Demo - Provenance
Detailed provenance information about each of our Images, including docker pull commands, all available tags and variants, and information about verifying our Images' signatures, Software Bill of Materials (SBOMs), and Supply chain Levels for Software Artifacts (SLSA) provenance.
How Snowflake uses Chainguard Images to deploy secure software to their customers.
Play Chainguard Video
How Snowflake uses Chainguard Images to deploy secure software to their customers.
Shift5 uses Chainguard Containers to save their team time and effort reaching vulnerability management goals, and move towards compliance standards like FedRAMP and CMMC
Play Chainguard Video
Shift5 uses Chainguard Containers to save their team time and effort reaching vulnerability management goals, and move towards compliance standards like FedRAMP and CMMC
Discover how GitGuardian turned the tide against software vulnerabilities, achieving nearly zero CVEs with Chainguard Containers.
Play Chainguard Video
Discover how GitGuardian turned the tide against software vulnerabilities, achieving nearly zero CVEs with Chainguard Containers.
Learn more about the Chainguard Factory and how we are able to build Chainguard Containers, Libraries, and VMs with world class security and efficiency.

This video is a condensed recording of Dustin Kirkland's talk at Assemble 2025.
Play Chainguard Video
Learn more about the Chainguard Factory and how we are able to build Chainguard Containers, Libraries, and VMs with world class security and efficiency. This video is a condensed recording of Dustin Kirkland's talk at Assemble 2025.
Product Avatar Image

Have you used Chainguard before?

Answer a few questions to help the Chainguard community

Chainguard Reviews (40)

Reviews

Chainguard Reviews (40)

4.8
40 reviews

Pros & Cons

Generated from real user reviews
View All Pros and Cons
Search reviews
View Filters
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
Naweed J.
NJ
Lead Engineer - Platform
Enterprise (> 1000 emp.)
"Why we chose Chainguard for securing container images"
What do you like best about Chainguard?

Chainguard’s minimalist, hardened container images with zero known CVEs, is going to significantly reduce our vulnerability management overhead. Not having to constantly chase patch cycles will save our teams countless hours.

The images are not just secure by default but gives us the confidence in both their integrity and provenance. We are currently looking at wider adoption across our teams and the society. What sets Chainguard apart is their commitment to transparency and compliance, making them a top choice for organisations with high security and regulatory requirements. If you are looking to build a secure, resilient container strategy, Changuard is worth serious consideration. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

This is very stage at the moment, but we look forward to working closely with Chainguard for feedbacks we get from our team as we start our wider rollout. Review collected by and hosted on G2.com.

Response from Sarah Haberman of Chainguard

Hi Naweed - Thanks for sharing your experience! It's great to hear that our approach is giving your teams more time to focus on building.

Ben C.
BC
Senior Software Engineer
Mid-Market (51-1000 emp.)
"Many fewer CVE tickets let me focus on real work"
What do you like best about Chainguard?

My team had a huge backlog in JIRA of CVEs we had to remediate. Resolving a CVE takes time away from actual work, as we had to wait for the CVE to be resolved, push the fixes, verify the fixes were passing security scans, then finally backport fixes to old releases we maintained.

It all took a long time, was a major effort, and didn't scale well as we had more CVEs than I want to admit :D.

Migrating from our team's existing images to chainguard only took about a day, and now using chainguard images totally saves us from having to deal with these CVEs, and lets us work on actual business problems, and not have to try to figure out how to patch some obscure lib install. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

Sometimes, it's tough to troubleshoot live issues where you need to do kubectl exec into a pod. This is a somewhat rare edge case, but it's something we've run into.

It's also sometimes hard to get certain packages fully working (eg a python pandas packages needs a driver which may not be present in the base image). Review collected by and hosted on G2.com.

Response from Sarah Haberman of Chainguard

Hey Ben 👋 Thanks for the great review! Glad to hear you're having a great experience with Chainguard!

Chandra G.
CG
Senior Release/DevOps Engineer
Enterprise (> 1000 emp.)
"Secure, Minimal, and Well-Supported — A Great Experience with Room for Transparency Improvements"
What do you like best about Chainguard?

Chainguard Images have been a transformative addition to our software supply chain strategy. The minimal, hardened, and continuously verified container images significantly reduce our attack surface while ensuring compliance and operational reliability.

One of the biggest pain points in container security is managing outdated or bloated base images filled with vulnerabilities. Chainguard solves this brilliantly with distroless, signed images that are continuously updated and come with built-in provenance and SBOMs. It’s clear they’ve thought deeply about what modern development teams need to build secure-by-default applications.

What really sets Chainguard apart, though, is their exceptional support. From day one, their team has been proactive, responsive, and genuinely invested in our success. Whether it was help with integration, optimizing our image choices, or answering security policy questions, their support engineers went above and beyond. Their documentation is also thorough and developer-friendly, which makes onboarding smooth and intuitive.

In summary: Chainguard Images bring peace of mind to any DevSecOps team, and their world-class support makes them a true partner in software supply chain security. Highly recommended for anyone building or deploying containers in a production environment Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

One area that could use improvement is transparency around source code and SBOM (Software Bill of Materials) access. While the images are secure and well-maintained, having easier access to corresponding source repositories and complete SBOMs—preferably in an automated or standardized format—would help us meet internal audit and compliance requirements more seamlessly. Review collected by and hosted on G2.com.

Response from Sarah Haberman of Chainguard

Chandra, thanks for taking the time to write such a thorough review! 🙌

Charlie G.
CG
SRE Manager
Mid-Market (51-1000 emp.)
"The gold star vendor: sales, onboarding implementation, support, and product"
What do you like best about Chainguard?

The chainguard team was able to meet us where we were at, move extremely quickly to meet our deadlines, and everything _just worked_. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

Wiz sometimes detects false positives in cgr images. Review collected by and hosted on G2.com.

Response from Sarah Haberman of Chainguard

Charlie, what a great review! We'll take that gold star - thank you! ⭐️

Ken A.
KA
Principal Application Architect
Human Resources
Enterprise (> 1000 emp.)
"We used chainguard base images to"
What do you like best about Chainguard?

Using chainguard essentially eliminates container library vulnerabilities coming from our Docker base images (as well as standard package installs!). When we scan our chainguard based images with grype, or snyk, the only vulnerabilities left are from our application installs. We are in the process of implementing chainguard base images across the enterprise, and are expecting over 80% reduction in open vulnerabilities across the board. Chainguard's customer support is excellent, they are one of the best software vendors I have ever worked with. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

The only real downside is you have to modify your Dockerfiles to work with the Wolfi OS, which is alpine-like (i.e. you have to use apk, etc.) If your current base image is not alpine based, there is some learning curve and work. Review collected by and hosted on G2.com.

Response from Kirby Koo of Chainguard

Thank you, Ken!

Dan E.
DE
Senior Cybersecurity Engineer
Enterprise (> 1000 emp.)
"Chainguard has changed the game when it comes to remediating vulns in images."
What do you like best about Chainguard?

I love the ease of use for our dev teams to switch over and cut their vulnerabilities down. Integrating it into our pipelines has been very easy. Customer support has been excellent and responsive. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

At this time of using the product I do not have any dislikes Review collected by and hosted on G2.com.

Response from Kirby Koo of Chainguard

Aww, thanks for taking the time to review us! Your support means a lot :)

VISHNU V.
VV
DevOps Engineer
Enterprise (> 1000 emp.)
"Great FIPS compliant images"
What do you like best about Chainguard?

Zero CVE images which we can directly consume in our products Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

Nothing as of now which we have encountered Review collected by and hosted on G2.com.

Response from Sarah Haberman of Chainguard

Thanks for the great review, Vishnu! So happy to hear that our FIPS containers are helping you ship to federal customers! 🚀

Verified User in Financial Services
AF
Enterprise (> 1000 emp.)
"Fantastic Product and an Even Better Team!"
What do you like best about Chainguard?

From scoping to project completion the Chainguard team was amazing to work with and provided excellent customer support! The ease of use, implementation and integration also helped! Looking forward for new features being released! Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

I have found no issue while working with the product so far! Review collected by and hosted on G2.com.

Response from Sarah Haberman of Chainguard

Thanks for the kind words! We’re so glad you’ve had a great experience with our team 🙌

Karl H.
KH
Senior Principal Architect
Enterprise (> 1000 emp.)
"Game-Changer"
What do you like best about Chainguard?

Since implementing Chainguard's hardened base images, we've seen a dramatic reduction in vulnerabilities—over 70%. This reduction not only enhances our security posture but also saves our engineering teams an enormous amount of time that would otherwise be spent on vulnerability management and patching. Chainguard's approach introduces excellent security practices out of the box, meaning our engineers no longer have to worry about critical security concerns like rootless containers, proper permissions, and secure registries.

Chainguard sets itself apart by providing supply chain security through purpose-built packages in their registry, making it clear that while competitors might still be playing catch-up in the minor leagues, Chainguard is clearly in a league of its own, setting the standard for supply chain security. We've maximized the value of these images by ensuring reuse across our organization, categorizing images into language-based and application-based groups. This strategy allows us to gain the most value through frequent reuse of language-based images, while our centralized platform engineering teams benefit from using application-specific images at a different scale.

To drive adoption, we've integrated Chainguard images into our centralized internal developer portal, which our developers are already familiar with and use regularly. This seamless integration has significantly boosted adoption rates, further supported by our vulnerability management reduction program. Through this program, we've been able to recommend Chainguard images, reassuring teams that transitioning will save time and energy.

The service level agreements (SLAs) provided by Chainguard are also very attractive. The high speed of image updates ensures that we are always protected with the latest security enhancements. We've even integrated Chainguard into our automatic update tools, so our developers are always confident that they're working with the most up-to-date versions.

Overall, Chainguard's hardened base images have been a game-changer for our organization, providing unparalleled security, efficiency, and peace of mind. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

The documentation at times fall a little behind and the modern authentication mechanisms at times can create difficulties in integrating with other existing platforms that are not yet supportive of technologies like OIDC. Quite a few of the images require rework to convert from a standard Dockerhub image however, I believe that's expected. Review collected by and hosted on G2.com.

Response from Kirby Koo of Chainguard

Thank you, Karl!! Your support means the world to us :)

Drew W.
DW
Senior Principal Software Engineer
Mid-Market (51-1000 emp.)
"Chainguard is very easy to use and deploy"
What do you like best about Chainguard?

I was extremely happy with how trivial it was to swap in their FIPS images in place of the FOSS images we were using. They had a whole onboarding call, but we'd already deployed them to development as it was that fast and easy. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

Their pricing was a battle, they don't differentiate between very simple images and very complex ones, so making the case to use them fully is very difficult. I think a pricing model that more accurately reflects their value add would help, as some images are inherently more complex to replace than others. Review collected by and hosted on G2.com.

Response from Kirby Koo of Chainguard

Thank you for the support, Drew!

Pricing Insights

Averages based on real user reviews.

Time to Implement

2 months

Return on Investment

6 months

Chainguard Comparisons
Product Avatar Image
Snyk
Compare Now
Product Avatar Image
Wiz
Compare Now
Chainguard Features
Risk Scoring
Secrets Management
Security Auditing
Continuous Image Assurance
Behavior Monitoring
Observability
Dynamic Image Scanning
Runtime Protection
Workload Protection
Product Avatar Image
Product Avatar Image