VOOZH about

URL: https://thenewstack.io/dockers-sets-free-the-hardened-container-images/

⇱ Docker Sets Free the Hardened Container Images - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2025-12-17 06:30:11
Docker Sets Free the Hardened Container Images
Containers / Security

Docker Sets Free the Hardened Container Images

Docker has made Docker Hardened Images (DHI) a free service, offering prepatched, secure SBOM-ready versions of widely used open source applications.
Dec 17th, 2025 6:30am by Joab Jackson
👁 Featued image for: Docker Sets Free the Hardened Container Images
Feature imaged via Unsplash.

With a sprawling cloud native ecosystem, security needs to be as scalable as everything else. Hence, the rise of the software bill of materials (SBOM), a systematic accounting for all the software being used in an environment. An SBOM is important because it reveals where all the newly found security holes would be found, and gives the admin a stage for streamlining, if not automating, the remediation process.

Hardened images are the industry’s way of getting ahead of the never-ending river of freshly unrooted security holes by preapplying all the security holes identified by common vulnerabilities and exposures (CVEs).

Today, about 20 billion images a month are pulled from Docker Hub, and so it made sense that the company started offering hardened images for its users, which it did last May.

Now, Docker Inc. has expanded its service of providing security-hardened images of the most widely used open source software applications.

Going forward, the full catalogue from the Docker Hardened Images (DHI) collection, which numbers over 200 packages, is free to download.

“The reason we’re doing this is to set the new standard for the container ecosystem overall,” said Mike Donovan, vice president of product at Docker, in an interview with TNS. “It’s like every customer, every engineering team was faced with evaluating 10 different vendors. That’s not going to get us to a more secure foundation that we need.”

A paid enterprise extension for enterprises will concentrate on ensuring these images meet the necessary government and regulatory mandates.

In addition, the company has launched, for a fee, an extended warranty service for selected images, guaranteeing they will remain patched even if the originator of that application has stopped supporting them.

Docker has also extended its hardening methodology to Model Context Protocol (MCP) servers, bringing the same security rigor to the AI agent infrastructure that developers are rapidly adopting.

Organizations that previously purchased DHI are automatically upgraded to DHI Enterprise at no additional cost.

What Are Hardened Images?

How are images hardened? Strong provenance, reproducible builds and clear attestations built on finely chiseled containers, according to Docker.

For developers, having access to prehardened images means they don’t have to spend time updating them with the latest security patches. But they are also built in such a way that all their component sources are clearly documented and signed to ensure against any changes made in on-path attacks.

Thus far, DHI images have 96% fewer vulnerabilities, compared to traditional base images.

Each image includes:

  • Complete SBOM
  • Transparent public CVE data
  • SLSA Build Level 3 provenance
  • Cryptographic proof of authenticity

Because DHI is built on Debian and Alpine, it will be immediately compatible with variants of those distributions.

How could they be used?

Socket offers a platform that detects malicious packages and stops them from being used in real time. An organization could combine Socket’s platform and Docker’s hardened images “without lifting a finger,” wrote Feross Aboukhadijeh, founder & CEO at Socket, in a statement.

“Pull a hardened image, run npm install, and the Socket firewall embedded in the DHI is already working for you,” Aboukhadijeh boasted. “That is what true secure-by-default should look like.”

With the rise of SBOM, a number of organizations have stepped up with catalogues of security-hardened open source images, including Chainguard, Broadcom’s Bitnami, RapidFort and ActiveState.

👁 Screenshot

Docker Hardened Images.

Docker’s Enterprise Extension

Docker focused its paid subscription on providing services essential to the enterprise.

DHI Premium is a paid offering with service-level agreements (SLAs) to ensure CVE remediation is done on a timely basis.

Images are made FIPS– and STIG-compliant for U.S. Defense Department work. Docker will also support the ability to customize tools, certificates and runtime configuration.

The service is promising (in the company’s words):

  • SLA-backed CVE remediation for critical vulnerabilities in under seven days, with a roadmap toward same-day fixes.
  • FIPS-enabled and STIG-ready images.
  • Full customization, including adding or changing runtime configuration, tools, certificates and image contents, while maintaining trust and provenance.
  • Complete catalog access.

Extended Life Cycle Support

Extended Life Cycle Support (ELS) is a paid add-on to DHI Enterprise, aimed at organizations that require hardened updates and compliance continuity for end-of-life software. If a software package is only supported by the project maintainers for five years, but the user needs it to run for several more years, due to internal upgrade cycles or some other factor, Docker itself will ensure the software itself is maintained.

In detail, the service offers:

  • Five additional years of security coverage beyond upstream end of life.
  • Continued CVE patches, SBOM updates and provenance attestations.
  • Ongoing signing and auditability for compliance framework.

“Extended Life Cycle Support helps … keep long-running systems secure without constant replatforming,” said Temporal.io CEO Samar Abbas, in a statement.

MCP Hardened, Too

Docker is extending its hardening platform to MCP server images on the hub as well.

With this announcement, the company has launched today hardened versions of a number of the most popular servers, including Grafana, MongoDB, GitHub and Context7. In the weeks ahead, the company plans to harden the full MCP catalog.

They get the same treatment as other hardened images, with the same minimal footprint, CVE remediation and provenance attestations.

TRENDING STORIES
Joab Jackson is a senior editor for The New Stack, covering cloud native computing and system operations. He has reported on IT infrastructure and development for over 30 years, including stints at IDG and Government Computer News. Before that, he...
Read more from Joab Jackson
SHARE THIS STORY
TRENDING STORIES
Docker is a sponsor of The New Stack.
TNS owner Insight Partners is an investor in: Docker.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.