Docker Releases Free, Production-Grade Hardened Container Images
Docker has announced the release of its production-grade hardened container images as a free, open-source offering under an Apache 2.0 license. This decision enhances accessibility to software supply chain security for developers in the container…
Docker has announced the release of its production-grade hardened container images as a free, open-source offering under an Apache 2.0 license. This decision enhances accessibility to software supply chain security for developers in the container ecosystem.
Previously a commercial product, Docker Hardened Images (DHI) now provide an industry standard for secure container foundations. These images address the threat of supply chain attacks, which have caused significant financial damage in recent years.
Since May 2025, Docker has hardened over 1,000 images and Helm charts. These images maintain compatibility with open-source foundations such as Alpine and Debian Linux distributions, minimizing migration barriers for development teams.
Each DHI image includes a complete Software Bill of Materials (SBOM) and SLSA Build Level 3 provenance. Docker uses public CVE data without suppressing vulnerabilities, even if patches are in development. The offering includes hardened Helm Charts for Kubernetes and Hardened MCP Servers for agentic applications. Initial MCP servers support MongoDB, Grafana, and GitHub, with future expansions planned.
Docker has announced the release of its production-grade hardened container images as a free, open-source offering under an Apache 2.0 license.
Major technology partners endorse Docker's initiative, highlighting the integration of CNCF projects into the DHI catalog. This move strengthens community-wide supply chain security.
For organizations requiring enhanced security, Docker Hardened Images Enterprise offers continuous security patching and supports regulated industries requiring FIPS and FedRAMP compliance. The enterprise version achieves significant size reduction while maintaining low CVE counts.
Docker’s AI assistant can recommend equivalent hardened images for existing containers, simplifying migration processes. This initiative aligns with Docker’s historical strategy of providing free access, comprehensive documentation, and consistent maintenance to developers.
Based on reporting by GBHackers.
