The new standard for building securely
Multi-distro compatibility
Near-zero CVEs
Transparent SBOMs
Provenance you can trust
What makes DHI different
Drop-in Adoption
Swap the base image and get instant security gains.
Apache 2.0 on Open Distros
You can migrate to and from with freedom and without surprises. Pay when you need stronger SLAs, compliance, or to leverage our build service.
Easiest path to secure supply chain
Drop-in replacements that require minimal changes. Our event-driven build system keeps images continuously updated, and secure customization allows you to tailor hardened images without breaking provenance.
Built with Docker-Maintained
Packages
Every DHI image is built with system packages that Docker builds, patches, and maintains directly from upstream source.
Full Transparency
Signed SBOMs and SLSA Level 3 provenance, with complete CVE data.
Built for Developers, hardened for security
When upstream stops, your protection continues. Up to 5 extra years of hardened patching, SBOMs and provenance.
Security that outlasts upstream
CVE patching continues after upstream EOL
SBOMs and provenance maintained throughout
Covers the images you rely on most: Node, Python, PostgreSQL, and more
Up and running in seconds
“For the first time, I don’t have to worry about what’s hiding in our base images. That mental overhead is gone, and we can finally focus on the security challenges that are unique to Attentive.”
Jacob Rickerd
Principal Security Engineer at Attentive
A complete security model
forward for organizations operating at scale.
Free for every developer
What’s included:
Hardened, minimal images
Near-zero CVEs
Verifiable SBOMs & SLSA Build L3 provenance
Full, unsuppressed CVE visibility
Drop-in adoption, no workflow changes
Full catalog of open source images under Apache 2.0
Built with Docker Hardened System Packages
Upstream cadence for Docker-released patches
Starting at $5k/repo
Everything in community, plus:
FIPS/STIG variants
Critical CVE fixes < 7 days with
SLA-backed continuous patching
Up to 5 customizations per repo (including system packages)
Contact us for pricing
Everything in select, plus:
Critical CVE fixes < 7 days with SLA-backed continuous patching
FIPS/STIG variants
Unlimited customizations, including system packages
Access to Hardened System Packages repo
Full catalog access available
ELS add-on available
Extended Lifecycle Support
Add onSecurity and compliance for end-of-life software. Requires DHI Enterprise.
+5 years of hardened updates
Maintains security updates after upstream EOL
SBOMs & provenance
Protects long-lived workloads
Trusted by the ecosystem
DHI vs. the Alternatives
|
Docker Hardened Images |
Others |
|
|---|---|---|
|
Distro |
Alpine/Debian |
Proprietary |
|
License |
Apache 2.0 |
Mixed |
|
Access |
Free, full catalog |
Trials / paywalled |
|
Adoption |
Drop-in migration |
Requires workflow changes |
|
Security |
Minimal, near-zero CVEs, SLSA Build L3 |
Inconsistent |
|
Transparency |
SBOMs & Provenance |
Partial visibility (suppressed CVEs, proprietary scoring) |
|
Lifecycle |
ELS provides up to 5 years |
Typically ends up to 6 months |
Docker Hardened Images are now available to every developer
Hear how how containers shaped the trust model we rely on today at Docker, and what AI-driven systems mean for the next chapter of software supply chain security.
Watch on demand now
Hardened Images for everyone
Docker Hardened Images are now free and open source under Apache 2.0.
Read
Containers are the new supply chain attack vector
Docker engineers break down the five pillars of supply chain security and why minimal, non-root images are a safer default.
Watch