Skip to content

Docker Hardened Images

Docker Hardened Images is the Docker, Inc. catalog of minimal, hardened container images, with near-zero CVEs, verifiable SBOMs and SLSA Build Level 3 provenance on Alpine and Debian. The DHI Select and DHI Enterprise plans add FIPS and STIG variants, SLA-backed remediation of critical and high CVEs within 7 days and image customization, licensed per repository mirrored into the organization.

Fabricantes: Docker
Category:
Learn more about Docker Hardened Images

Request a Quote

What is Docker Hardened Images?

Docker Hardened Images is a catalog of minimal, hardened container images for development and security teams, developed by Docker, Inc., that delivers base images with near-zero CVEs, verifiable SBOMs and SLSA Build Level 3 provenance. This page covers the DHI Select and DHI Enterprise commercial plans and the Extended Lifecycle Support add-on.

The catalog brings together more than 1,000 images, Helm charts and system packages maintained by Docker on the Alpine and Debian distributions, with the free DHI Community tier under the Apache 2.0 license. The images replace generic base images without changing the workflow: the team swaps the reference in the Dockerfile and keeps using Docker Desktop, Docker Hub and its existing CI/CD pipeline. The paid plans add what audits and compliance require: FIPS and STIG variants, SLA-backed CVE remediation and controlled image customization.

Docker Hardened Images key features

Docker Hardened Images combines minimal images with the compliance artifacts each image carries build time.

  • Minimal, hardened images — base and application images with a reduced surface, built with Docker Hardened System Packages.
  • SBOM and SLSA Build Level 3 provenance — every image ships with a signed component list and verifiable origin attestation.
  • Full CVE visibility — vulnerabilities shown without hidden suppression, with support for VEX statements for those that do not apply.
  • FIPS and STIG variants — images for regulated environments that require validated cryptographic modules and standardized hardening.
  • SLA-backed CVE remediation — critical and high vulnerabilities fixed within 7 days on the DHI Select and DHI Enterprise plans.
  • Image customization — add packages, tools, certificates and configurations: up to 5 customizations on DHI Select and unlimited on DHI Enterprise.
  • DHI Helm charts — charts tested for Kubernetes that already reference the hardened images in the catalog.

Docker Hardened Images benefits

Docker Hardened Images cuts scanner alert volume because the images ship only the packages needed at runtime, removing upfront vulnerabilities inherited libraries the application never uses.

Audit response gets faster because SBOM and SLSA Build Level 3 provenance travel with every image: the team hands the auditor the component list and build origin without building the inventory by hand.

The exposure window shrinks because the 7-day SLA on DHI Select and DHI Enterprise shifts remediation of critical and high CVEs in base images to Docker.

Adoption does not require switching distributions because the images follow Alpine and Debian: migration starts at the Dockerfile FROM instruction and reuses the tests the team already has.

Who Docker Hardened Images is for

Docker Hardened Images serves application security (AppSec) leads, platform engineering, DevOps and compliance teams at companies that ship software in containers. Typical scenarios: a bank that needs FIPS images to meet cryptography requirements; a software vendor for government that needs STIG hardening; and a SaaS company that wants to stop triaging hundreds of CVEs inherited base images on every release.

Docker Hardened Images differentiators

Docker Hardened Images is maintained by the company that publishes Docker Official Images and runs Docker Hub, so the hardened images live in the same registry and workflow developers already use. The images follow Alpine and Debian rather than a proprietary distribution, which preserves portability, and the free catalog is open source under Apache 2.0. On the paid plans, mirrored repositories sit in the organization namespace, with Docker Scout analysis and audit logs. To license Docker Desktop for the team, the matching subscription is Docker Business.

Requirements and compatibility

Docker Hardened Images runs on OCI-standard container runtimes such as Docker Engine, Docker Desktop and Kubernetes clusters, with images based on Alpine (musl) and Debian (glibc). The catalog covers runtimes such as Go, Python, Node.js, .NET and Java, with migration guides Alpine, Debian and Ubuntu images. The paid plans require a Docker organization, where repositories are mirrored, and management is available through Docker Hub, the CLI, the API, Terraform or the DHI MCP server.

Editions: DHI Community, DHI Select and DHI Enterprise

  • DHI Community — free catalog under Apache 2.0, with SBOM, SLSA Build Level 3 provenance and patches at upstream cadence, available at dhi.io.
  • DHI Select — paid plan for organizations, with FIPS and STIG variants, a 7-day SLA for critical and high CVEs, up to 5 customizations and repositories mirrored into the organization.
  • DHI Enterprise — everything in DHI Select, plus unlimited customizations, access to the Hardened System Packages repository and optional full catalog access.
  • Extended Lifecycle Support (ELS) — DHI Enterprise-only add-on that keeps hardened updates coming for up to 5 years after the upstream version reaches end of life.

How much does Docker Hardened Images cost?

DHI Select is licensed per repository mirrored into the organization, as an annual plan. There is no single list price because the investment depends on sizing: how many images the organization standardizes, which edition fits the requirement level (DHI Select or DHI Enterprise), whether Extended Lifecycle Support is in scope, and whether it is a new purchase, a renewal or a repository expansion.

The count is per repository, not per user or per pull: every organization member pulls the mirrored images. For example, a team that standardizes Python, Node.js and Java as base images mirrors 3 repositories, regardless of how many developers, pipelines or clusters use them. Repositories added mid-contract are prorated for the remaining period, and DHI Enterprise and ELS sizing is defined in the commercial proposal.

To buy Docker Hardened Images in Brazil, OSB Software scopes this with you, sends the commercial proposal, issues the Brazilian invoice and delivers the licenses — request a quote to receive the exact figure for your scenario.

Docker Hardened Images frequently asked questions

Does Docker Hardened Images work with my vulnerability scanner?

Yes. Docker documents integrations with market scanners and with Docker Scout, and every image publishes SBOM and VEX statements that the scanner uses to flag only applicable CVEs.

Do I need to rewrite my Dockerfile to use DHI?

No. Adoption starts by swapping the base image in the FROM instruction, and Docker publishes a migration checklist and examples for Go, Python, Node.js, .NET and Java.

Does Docker Hardened Images offer FIPS images?

Yes, on the DHI Select and DHI Enterprise plans, which include FIPS variants and STIG-ready images. DHI Community does not include these variants.

What happens when a version reaches end of life?

On DHI Enterprise, the Extended Lifecycle Support add-on keeps security updates coming for up to 5 years after the upstream version reaches end of life.

Why buy Docker Hardened Images OSB Software?

OSB Software is an official Docker partner in Brazil and supplies 100% genuine Docker Hardened Images licenses to companies, with Brazilian invoicing, local contracting in Portuguese and full legal compliance — the safe way to buy imported software under a Brazilian corporate entity, with no risk of irregular licensing.

When you buy Docker Hardened Images OSB Software, you get:

  • Consultative, specialist support — specialists who size your per-repository licensing to your actual operation, avoiding over- or under-buying.
  • Fast, secure processes — purchase order to delivery of genuine licenses, traceable at every step.
  • Dedicated commercial follow-up — quote to delivery and renewal, with advance notice before your license expires.
  • Invoicing that fits your company — Brazilian invoicing and terms adapted to your corporate procurement process.
  • Proven track record — thousands of customers served across Brazil.

If you are looking for where to buy Docker Hardened Images in Brazil with legal certainty and properly licensed imported software, request a quote: OSB Software delivers reliable technology, qualified support and a simple, transparent purchase.

We help you choose

Not sure which software
you need?

Tell us about your need and our team helps you choose the ideal solution — from over 10,000 options in our catalog.