[go: up one dir, main page]

Introducing G2.ai, the future of software buying.Try now
Share your insights with Chainguard

Thousands of people like you come to G2 to find out whether solutions like Chainguard are the right fit for them. Share your real experiences with Chainguard and the G2 community and help someone make the right decision about their software.

It's been two months since this profile received a new review
Leave a Review

Chainguard Reviews & Product Details - Page 3

Chainguard Product Details

Value at a Glance

Averages based on real user reviews.

Time to Implement

2 months

Chainguard Media

Chainguard Demo - Secure-by-default container images
Build software better with minimal, zero-CVE container images guarded under our industry-leading remediation SLA.
Chainguard Demo - Chainguard Image Directory
Find, browse, discover, and get started using minimal, hardened images from Chainguard for all of your application needs.
Chainguard Demo - Security Advisories
Our self-serve portal helps you find the latest information about CVEs, including when the CVE was detected, the current CVE remediation status in a specific Chainguard Image package, and the version of the software it’s fixed in. You can search for a specific CVE ID or filter down to only the so...
Chainguard Demo - Provenance
Detailed provenance information about each of our Images, including docker pull commands, all available tags and variants, and information about verifying our Images' signatures, Software Bill of Materials (SBOMs), and Supply chain Levels for Software Artifacts (SLSA) provenance.
How Snowflake uses Chainguard Images to deploy secure software to their customers.
Play Chainguard Video
How Snowflake uses Chainguard Images to deploy secure software to their customers.
Shift5 uses Chainguard Containers to save their team time and effort reaching vulnerability management goals, and move towards compliance standards like FedRAMP and CMMC
Play Chainguard Video
Shift5 uses Chainguard Containers to save their team time and effort reaching vulnerability management goals, and move towards compliance standards like FedRAMP and CMMC
Discover how GitGuardian turned the tide against software vulnerabilities, achieving nearly zero CVEs with Chainguard Containers.
Play Chainguard Video
Discover how GitGuardian turned the tide against software vulnerabilities, achieving nearly zero CVEs with Chainguard Containers.
Learn more about the Chainguard Factory and how we are able to build Chainguard Containers, Libraries, and VMs with world class security and efficiency.

This video is a condensed recording of Dustin Kirkland's talk at Assemble 2025.
Play Chainguard Video
Learn more about the Chainguard Factory and how we are able to build Chainguard Containers, Libraries, and VMs with world class security and efficiency. This video is a condensed recording of Dustin Kirkland's talk at Assemble 2025.
Product Avatar Image

Have you used Chainguard before?

Answer a few questions to help the Chainguard community

Chainguard Reviews (39)

Reviews

Chainguard Reviews (39)

4.8
40 reviews

Pros & Cons

Generated from real user reviews
View All Pros and Cons
Search reviews
View Filters
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
Verified User in Computer Software
AC
Mid-Market (51-1000 emp.)
"Easy and positive experience"
What do you like best about Chainguard?

Attentive support team

Well documented service

Easy to use portal/UI

Flexible to customizations we requested Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

None I can think of.

The limiting factor for chainguard is the upstream product maintenaners speed. Review collected by and hosted on G2.com.

Response from Kirby Koo of Chainguard

We appreciate the support. Thank you so much!

Andy T.
AT
Mid-Market (51-1000 emp.)
"Secure software supply chain"
What do you like best about Chainguard?

Chainguard has a rock solid product offering that's allowed our teams to build on top of a secure foundation. Chainguard's Linux (un)distro and vast library of language runtimes and open source building blocks allowed us to compose a secure software catalog of first and third party software to distribute to our customers. On top of this, all of Chainguard's engineering and customer success staff have been a great pleasure to work with! All our collab is over Slack and they feel like an extended part of the team. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

This falls more to us than Chainguard, but ways to better track all the places we're making use of their base images would be helpful. Review collected by and hosted on G2.com.

Mark M.
MM
Organizer
Enterprise (> 1000 emp.)
"Spend less time talking about CVEs"
What do you like best about Chainguard?

We've all seen a ton of projects that will detect CVEs but then you have the secondary problem of deciding where the CVE originated from (base image or first party code), how to patch or upgrade, when to patch so not to impact customers, who should own the updates, what to tell customers and compliance...

Chainguard Images removes the CVEs -- no debate, no CVSS, no triaging, no work tickets. It's done. Enterprises that appreciate this problem will see an ROI in weeks if not days. Not to mention that enterprise customers get an SLA for patches -- I challenge anyone to do what they are doing internally without spending millions on a team who does this as a full time job.

Then for the orgs that are investing in the software supply chain risks, they provide provenance, signing, and an accurate SBOM out-of-The box to start your journey in managing a secure software supply chain. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

The free offering is (reasonably) only the :latest tag which might be fine for personal projects but not most production environments. I don't know the costs for individuals or small orgs (I'm an enterprise customer) but its not free. Review collected by and hosted on G2.com.

Nuno D.
ND
Senior IT System Analyst
Enterprise (> 1000 emp.)
"Software supply chain starts at the container level!"
What do you like best about Chainguard?

Since its inception, Chainguard has been modernizing the software supply chain ecosystem and one of their most critical work, and often thought for granted, is their containers image repository.

In a perfect world, every end-user company, would create container images that are signed (ever heard about Sigstore? Chainguard created it), have a software bill of materials (SBOMs) and are scanned (0 CVEs) before being used in production.

Well, we don't live in such world and Chainguard, instead of playing the role of "use our base images at your own risk", they moved towards the hardest direction and provide us with updated, signed and scanned base images at their own costs!

Want to have the latest node.js image with 0 CVEs? docker/podman/nerdctl pull cgr.dev/chainguard/node. That's that easy. Nothing to implement, change the source repository and you're good to go.

Of course, for production you should never run the latest image and instead target a specific version. This is where their customer support comes into play by helping you customizing the usage of their images to your needs.

Chainguard took ownership of what I call a "grey area", where providers and customers tend to finger point when something goes wrong. And by doing so, with their team of experts, I can confidently say the container ecosystem feels a little bit more secure, and this means a lot. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

Maybe the only downside I can see about Chainguard efforts, is to know if keeping all these 0 CVEs images on the long term will not impact other sections/innovations due to this very demanding workload.

The company seems to grow at a good pace (not too fast or slow), however the security is a daily fight and the ressources can be limited.

I fully trust their solutions, and believe they automated the most of their tasks. Still, it's a lot of efforts for "only one side" of Chainguard's offering. Review collected by and hosted on G2.com.

Verified User in Computer Software
AC
Mid-Market (51-1000 emp.)
"Mix of feelings"
What do you like best about Chainguard?

0 CVE's, Good support, Very good technical team Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

Sometimes we need remind them to update some images Review collected by and hosted on G2.com.

Response from Sarah Haberman of Chainguard

Hey there! Thanks for your review and feedback. It's great to hear that Chainguard is helping with your FedRAMP journey!

EF
Software developer
Small-Business (50 or fewer emp.)
"My experiences using Chainguard Nodejs base image was amazing!"
What do you like best about Chainguard?

- Very small image size,

- Very small to none CVEs from my experiences.

- Very large repo supporting many languages and technologies,

- Ease to use,

- Ease of implementation. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

A great part of it, is free, but for some custom implementation or features , you may pay. Review collected by and hosted on G2.com.

Benjamin Y.
BY
Freelance Developer
Small-Business (50 or fewer emp.)
"Amazing drop-in SECURE replacement for your images!"
What do you like best about Chainguard?

Chainguard makes it easy to pull and use actually secure images. If you're using images from another registry, in most cases you can just drop in the chainguard images in place. Not only do you get the elimination of CVEs and massive risk, you get an INSANE reduction in size! It's an amazing resource that is somehow available for open use, and comes with a cadre of passionate and attentive people to support. As the registry grows, I can see this becoming my only source of trusted images for platform deployments. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

It's hard to find something to dislike, but perhaps the requirement of authentication to pull images, and also that it's not THE mandatory registry for everyone. Review collected by and hosted on G2.com.

Raphael D.
RD
IT Consultant
Small-Business (50 or fewer emp.)
"Secure and Efficient Toolbox for Containers"
What do you like best about Chainguard?

As a professional deeply engaged in Kubernetes projects, I have found Chainguard's Images and Digestabot to be essential tools in elevating the security and efficiency of my daily tasks. One remarkable feature, from my perspective, is the robust nature of Chainguard's images. Integrating these images with multi-stage builds has enabled me to significantly reduce container sizes, all while guaranteeing the final image's resilience against vulnerabilities.

Furthermore, the seamless integration with Digestabot has revolutionized the way I manage containerized applications, making it a pivotal asset in my work. Digestabot ensures the automatic and up-to-date maintenance of my images, alleviating the need for constant monitoring and manual updates for each component. This automated process has proven to be a valuable time-saving and stress-free element in my professional workflow. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

I have not encountered any dislikes with Chainguard thus far, even utilizing it with frequency. It has been easy to implement, and whenever I needed support, the responses were prompt and helpful. Review collected by and hosted on G2.com.

Chris H.
CH
Mid-Market (51-1000 emp.)
"Secure-by-Design Exemplified"
What do you like best about Chainguard?

There's a lot of talk about Secure-by-Design software in the industry. That said, Chainguard moves beyond the talk and walks the walk with their Chainguard images and innovative approaches to software supply chain security. Rather than just focusing on identifying and reporting on vulnerabilities, Chainguard gets to the root of the issue, driving down vulnerabilities exponentially and enabling Developers to build on a secure foundation, eliminating toil, reducing attack surface and benefiting the entire software ecosystem. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

There's not much to dislike about Chainguard other than the industry needed them sooner. Review collected by and hosted on G2.com.

Jorge C.
JC
Developer Relations
Small-Business (50 or fewer emp.)
"Great base images"
What do you like best about Chainguard?

There's not much to say, and I mean that in a good way. Their base images are small, and almost always have a significant amount of less surface area and vulnerabilities than containers based on traditional distributions. I like that the build process is on github so you can open up their merge queue and watch the updates go in in real time. It's also great that they can be as small as Alpine images but with glibc so you don't have to worry about dealing with musl. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

I don't have experience with their commercial support. Review collected by and hosted on G2.com.

Pricing Insights

Averages based on real user reviews.

Time to Implement

2 months

Return on Investment

6 months

Chainguard Comparisons
Product Avatar Image
Snyk
Compare Now
Product Avatar Image
Wiz
Compare Now
Chainguard Features
Risk Scoring
Secrets Management
Security Auditing
Continuous Image Assurance
Behavior Monitoring
Observability
Dynamic Image Scanning
Runtime Protection
Workload Protection
Product Avatar Image
Product Avatar Image