frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

A Safer Container Ecosystem with Docker: Free Docker Hardened Images

https://www.docker.com/blog/docker-hardened-images-for-every-developer/
132•anttiharju•1h ago

Comments

jitl•1h ago
I went to "Hardened Images Catalog" and searched for pgbouncer, not found (https://hub.docker.com/hardened-images/catalog?search=pgboun...)

There's a "Make a request" button, but it links to this 404-ing GitHub URL: https://github.com/docker-hardened-images/discussion/issues

oh well. hope its good stuff otherwise.

pploug•1h ago
Thanks for reporting, team is fixing it, the right url is: https://github.com/docker-hardened-images/catalog/issues/
tecleandor•1h ago
Is this the response to the Bitnami/VMWare/Broadcom Helm charts thing?
kamrannetic•1h ago
no need for chainguard/bitnami anymore?
progbits•54m ago
Bitnami is in broadcom hell, nobody should use that.

Chainguard still has better CVE response time and can better guarantee you zero active exploits found by your prod scanners.

(No affiliation with either, but we use chainguard at work, and used to use bitnami too before I ripped it all out)

mmbleh•49m ago
CVE response time is a toss up, they all patch fast. Chainguard can only guarantee zero active exploits because they control their own exploit feed, and don't publish anything on it until they've patched. So while this makes it look better, it may not actually be better
dlor•2m ago
Hey!

I work at Chainguard. We don't guarantee zero active exploits, but we do have a contractual SLA we offer around CVE scan results (those aren't quite the same thing unfortunately).

We do issue an advisory feed in a few versions that scanners integrate with. The traditional format we used (which is what most scanners supported at the time) didn't have a way to include pending information so we couldn't include it there.

The basic flow was: * scanner finds CVE and alerts * we issue statement showing when and where we fixed it

so there wasn't really a spot to put "this is present", that was the scanner's job. Not all scanners work that way though, and some just rely on our feed and don't do their own homework so it's hit or miss.

We do have another feed now that uses the newer OSV format, in that feed we have all the info around when we detect it, when we patch it, etc.

All this info is available publicly and shown in our console, many of them you can see here: https://github.com/wolfi-dev/advisories

You can take this example: https://github.com/wolfi-dev/advisories/blob/main/amass.advi... and see the timestamps for when we detected CVEs, in what version, and how long it took us to patch.

digi59404•47m ago
FWIW - A whole host of the pre-IPO GitLab folks went to Chainguard. A lot of them, many in leadership roles. Most importantly, In Sales Leadership. These are people whom don’t really believe in high-pressure sales. Rather they aim to show the value and not squeeze customers for profit or making a number on a chart go up.

Do with that knowledge what you may.

nine_k•1h ago
The news: Docker Hardened Images (DHI) are now free to use for everyone. No reason not to use them.

Offering image hardening to custom images looks like a reasonable way for Docker to have a source of sustained income. Regulated industries like banks, insurers, or governmental agencies are likely interested.

scottydelta•1h ago
After their last rug pull when they started charging projects for registry after parading it as a fully free service for almost a decade, it has become hard to trust anything free.

Bait and switch once the adoption happens has become way too common in the industry.

skyline879•55m ago
When was this?
simlevesque•31m ago
https://www.docker.com/developers/free-team-faq/

> Is Docker sunsetting the Free Team plan?

> No. Docker communicated its intent to sunset the Docker Free Team plan on March 14, 2023, but this decision was reversed on March 24, 2023.

pploug•20m ago
For oss projects with heavy pulls, the (free) dsos programme removes all rate limits on their public images, the intention was never to impact projects, but rather mega corporations using hub as free hosting:

https://www.docker.com/community/open-source/application/

imglorp•25m ago
> 100 pulls per 6 hours for unauthenticated users and 200 pulls per 6 hours for Docker Personal users

Not a problem for casual users but even a small team like mine, a dozen people with around a dozen public images, can hit the pull limit deploying a dozen landscapes a day. We just cache all the public images ourselves and avoid it.

https://www.docker.com/blog/revisiting-docker-hub-policies-p...

pploug•40m ago
Projects are not charged for hub usage
cedws•30m ago
Docker is a company I just can’t hate on. They’ve completely transformed how software is deployed. Containers gained so much momentum it kind of outgrew them and they lost a lot of potential business. I would hardly call beginning to charge after a decade of free service a rug pull, especially now that dependence on Docker’s registry is shrinking all the time.
simlevesque•29m ago
I don't hate them. But I don't want to depend on them for any product I manage.
politelemon•26m ago
Given the wealth and productivity creation that they're responsible for enabling across the industry, they deserve to be paid for it. There is no way for them to have achieved this with zero friction.
dudeWithAMood•17m ago
I am a little confused because I got a 401 when I tried to pull an image from there. Do I need a login or something? For a free image it sure doesn't feel that way.
darkwater•9m ago
This smells like LLM generated
BSVogler•30m ago
First look shows me that this is not an easy drop in replacement. First thing is this requires a log-in and makes me wonder why this is required. Perhaps some upselling coming.

With Bitnami discontinuing their offer, we recently switched to other providers. For some we are using a helm chart and this new offer provides some helm charts but for some software just the image. I would be interested to give this a try but e.g. the python image only various '(dev)' images while the guide mentions the non-dev images. So this requires some planning.

EDIT: Digging deeper, I notice it requires a PAT and a PAT is bound to a personal account. I guess you need the enterprise offering for organisation support. I am not going to waste my time to contact them for an enterprise offer for a small start-up. What is the use case for CVE hardened images that you cannot properly run in an CICD and only on your dev machine? Are there companies that need to follow compliance rules or need this security guarantee but don't have CICD in place?

politelemon•27m ago
I appreciate what they're doing here, which is something I haven't seen other vendors doing.
jiehong•15m ago
At $work, we switched everything to Redhat’s ubi images (micro and minimal) for that.

But, we pay for support already.

Nice from docker!

Gemini 3 Flash: frontier intelligence built for speed

https://blog.google/products/gemini/gemini-3-flash/
375•meetpateltech•2h ago•171 comments

Make Me CEO of Mozilla

https://blog.kingcons.io/posts/make-me-ceo-of-mozilla.html
14•phyzome•14m ago•1 comments

AWS CEO says replacing junior devs with AI is 'one of the dumbest ideas'

https://www.finalroundai.com/blog/aws-ceo-ai-cannot-replace-junior-developers
312•birdculture•1h ago•171 comments

How SQLite Is Tested

https://sqlite.org/testing.html
26•whatisabcdefgh•52m ago•2 comments

Coursera to combine with Udemy

https://investor.coursera.com/news/news-details/2025/Coursera-to-Combine-with-Udemy-to-Empower-th...
249•throwaway019254•6h ago•149 comments

A Safer Container Ecosystem with Docker: Free Docker Hardened Images

https://www.docker.com/blog/docker-hardened-images-for-every-developer/
132•anttiharju•1h ago•23 comments

Tell HN: HN was down

268•uyzstvqs•2h ago•172 comments

FCC chair suggests agency isn't independent, word cut from mission statement

https://www.axios.com/2025/12/17/brendan-carr-fcc-independent-senate-testimony-website
45•jmsflknr•53m ago•11 comments

Notes on Sorted Data

https://amit.prasad.me/blog/sorted-data
30•surprisetalk•6d ago•2 comments

Flick (YC F25) Is Hiring Founding Engineer to Build Figma for AI Filmmaking

https://www.ycombinator.com/companies/flick/jobs/Tdu6FH6-founding-frontend-engineer
1•rayruiwang•2h ago

Launch HN: Kenobi (YC W22) – Personalize your website for every visitor

14•sarreph•2h ago•29 comments

AI will make formal verification go mainstream

https://martin.kleppmann.com/2025/12/08/ai-formal-verification.html
757•evankhoury•21h ago•383 comments

alpr.watch

https://alpr.watch/
855•theamk•1d ago•400 comments

Yep, Passkeys Still Have Problems

https://fy.blackhats.net.au/blog/2025-12-17-yep-passkeys-still-have-problems/
101•todsacerdoti•5h ago•69 comments

No Graphics API

https://www.sebastianaaltonen.com/blog/no-graphics-api
759•ryandrake•23h ago•143 comments

Announcing the Beta release of ty

https://astral.sh/blog/ty
754•gavide•22h ago•141 comments

AI's real superpower: consuming, not creating

https://msanroman.io/blog/ai-consumption-paradigm
155•firefoxd•10h ago•104 comments

Why outcome-billing makes sense for AI Agents

https://www.valmi.io/blog/an-imperative-for-ai-agents-outcome-billing-with-valmi/
8•rajvarkala•1h ago•5 comments

Linux Kernel Rust Code Sees Its First CVE Vulnerability

https://www.phoronix.com/news/First-Linux-Rust-CVE
68•weinzierl•1h ago•60 comments

Learning the oldest programming language (2024)

https://uncenter.dev/posts/learning-fortran/
26•lioeters•5h ago•21 comments

Is Mozilla trying hard to kill itself?

https://infosec.press/brunomiguel/is-mozilla-trying-hard-to-kill-itself
672•pabs3•9h ago•589 comments

No AI* Here – A Response to Mozilla's Next Chapter

https://www.waterfox.com/blog/no-ai-here-response-to-mozilla/
458•MrAlex94•21h ago•260 comments

I created a publishing system for step-by-step coding guides in Typst

https://press.knowledge.dev/p/new-150-pages-rust-guide-create-a
7•deniskolodin•3d ago•2 comments

Zmij: Faster floating point double-to-string conversion

https://vitaut.net/posts/2025/faster-dtoa/
5•fanf2•3d ago•0 comments

TLA+ Modeling Tips

http://muratbuffalo.blogspot.com/2025/12/tla-modeling-tips.html
90•birdculture•11h ago•21 comments

Pricing Changes for GitHub Actions

https://resources.github.com/actions/2026-pricing-changes-for-github-actions/
749•kevin-david•1d ago•781 comments

GPT Image 1.5

https://openai.com/index/new-chatgpt-images-is-here/
491•charlierguo•1d ago•238 comments

Thin desires are eating life

https://www.joanwestenberg.com/thin-desires-are-eating-your-life/
649•mitchbob•1d ago•217 comments

Modern SID chip substitutes [video]

https://www.youtube.com/watch?v=nooPmXxO6K0
46•vismit2000•3d ago•2 comments

I ported JustHTML from Python to JavaScript with Codex CLI and GPT-5.2 in hours

https://simonwillison.net/2025/Dec/15/porting-justhtml/
228•pbowyer•20h ago•122 comments