Introducing G2.ai, the future of software buying.Try now

Chainguard Reviews & Product Details

Value at a Glance

Averages based on real user reviews.

Time to Implement

2 months

Chainguard Media

Chainguard Demo - Secure-by-default container images
Build software better with minimal, zero-CVE container images guarded under our industry-leading remediation SLA.
Chainguard Demo - Chainguard Image Directory
Find, browse, discover, and get started using minimal, hardened images from Chainguard for all of your application needs.
Chainguard Demo - Security Advisories
Our self-serve portal helps you find the latest information about CVEs, including when the CVE was detected, the current CVE remediation status in a specific Chainguard Image package, and the version of the software it’s fixed in. You can search for a specific CVE ID or filter down to only the so...
Chainguard Demo - Provenance
Detailed provenance information about each of our Images, including docker pull commands, all available tags and variants, and information about verifying our Images' signatures, Software Bill of Materials (SBOMs), and Supply chain Levels for Software Artifacts (SLSA) provenance.
With trusted open source from Chainguard, Anduril’s application security and platform teams dramatically reduced engineering toil.
Play Chainguard Video
With trusted open source from Chainguard, Anduril’s application security and platform teams dramatically reduced engineering toil.
How Snowflake uses Chainguard Images to deploy secure software to their customers.
Play Chainguard Video
How Snowflake uses Chainguard Images to deploy secure software to their customers.
Appian utilizes Chainguard Containers to simplify risk management and fuel innovation.
Play Chainguard Video
Appian utilizes Chainguard Containers to simplify risk management and fuel innovation.
Shift5 uses Chainguard Containers to save their team time and effort reaching vulnerability management goals, and move towards compliance standards like FedRAMP and CMMC
Play Chainguard Video
Shift5 uses Chainguard Containers to save their team time and effort reaching vulnerability management goals, and move towards compliance standards like FedRAMP and CMMC
Learn more about the Chainguard Factory and how we are able to build Chainguard Containers, Libraries, and VMs with world class security and efficiency.

This video is a condensed recording of Dustin Kirkland's talk at Assemble 2025.
Play Chainguard Video
Learn more about the Chainguard Factory and how we are able to build Chainguard Containers, Libraries, and VMs with world class security and efficiency. This video is a condensed recording of Dustin Kirkland's talk at Assemble 2025.
Product Avatar Image

Have you used Chainguard before?

Answer a few questions to help the Chainguard community

Chainguard Reviews (44)

Reviews

Chainguard Reviews (44)

4.8
44 reviews

Pros & Cons

Generated from real user reviews
View All Pros and Cons
Search reviews
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
Mathieu L.
ML
Head Of Cloud Infrastructure
Mid-Market (51-1000 emp.)
"Essential for CVE-Free Container Management"
What do you like best about Chainguard?

I appreciate Chainguard's extensive range of catalog with more than 500 public images to choose from, which significantly enhances my experience by ensuring that an image such as Linkerd is available and likely vulnerability-free compared to other sources like DockerHub. The availability of such a vast selection of images provides us with assurance and flexibility, making it easier to maintain security standards. I value the proactive approach of Chainguard in addressing CVEs by ensuring the images are rebuilt daily, which gives me confidence in their security posture. Additionally, I find the initial setup process to be very easy, and I enjoy the self-management feature allowing me to choose the right images from the catalog effortlessly. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

It would be great if Chainguard's container registry could sync with AWS ECR so I could use my own private registry instead. I believe it's being worked on though. Review collected by and hosted on G2.com.

GS
Technology Consultant
Enterprise (> 1000 emp.)
"Effortless Supply Chain Security with Seamless Integration"
What do you like best about Chainguard?

What I appreciate most about Chainguard is how it simplifies and strengthens software supply chain security. The platform offers transparent visibility into dependencies, vulnerabilities, and build pipelines, all without introducing unnecessary complexity. I also value its seamless integration with our existing workflows, which enables our team to identify potential issues early and maintain confidence in our software releases. The combination of automation and practical insights truly sets it apart. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

The main challenge I’ve encountered with Chainguard is that the initial setup and configuration process can be somewhat time-consuming, particularly if you’re dealing with complex pipelines or managing several environments. After the setup is complete, everything operates smoothly, but getting all the integrations in place and fine-tuning the system at the start does demand some effort. Review collected by and hosted on G2.com.

anan H.
AH
Senior DevOps
Computer Software
Mid-Market (51-1000 emp.)
"Effortless Security and Zero CVEs for Container Images"
What do you like best about Chainguard?

Chainguard provides a strong security approach for container images and supply chain hygiene the images are minimal and well maintained by them and fully SBOM verified with consistently updated which reduces operational risk

the platform makes it easy to adopt secure by default practices without adding overhead to CI/CD pipelines and it helps a security companies to have images with zero CVEs Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

I think the only concern is the pricing that can be a bit high for smaller teams Review collected by and hosted on G2.com.

Naweed J.
NJ
Lead Engineer - Platform
Enterprise (> 1000 emp.)
"Why we chose Chainguard for securing container images"
What do you like best about Chainguard?

Chainguard’s minimalist, hardened container images with zero known CVEs, is going to significantly reduce our vulnerability management overhead. Not having to constantly chase patch cycles will save our teams countless hours.

The images are not just secure by default but gives us the confidence in both their integrity and provenance. We are currently looking at wider adoption across our teams and the society. What sets Chainguard apart is their commitment to transparency and compliance, making them a top choice for organisations with high security and regulatory requirements. If you are looking to build a secure, resilient container strategy, Changuard is worth serious consideration. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

This is very stage at the moment, but we look forward to working closely with Chainguard for feedbacks we get from our team as we start our wider rollout. Review collected by and hosted on G2.com.

Response from Sarah Haberman of Chainguard

Hi Naweed - Thanks for sharing your experience! It's great to hear that our approach is giving your teams more time to focus on building.

Ben C.
BC
Senior Software Engineer
Mid-Market (51-1000 emp.)
"Many fewer CVE tickets let me focus on real work"
What do you like best about Chainguard?

My team had a huge backlog in JIRA of CVEs we had to remediate. Resolving a CVE takes time away from actual work, as we had to wait for the CVE to be resolved, push the fixes, verify the fixes were passing security scans, then finally backport fixes to old releases we maintained.

It all took a long time, was a major effort, and didn't scale well as we had more CVEs than I want to admit :D.

Migrating from our team's existing images to chainguard only took about a day, and now using chainguard images totally saves us from having to deal with these CVEs, and lets us work on actual business problems, and not have to try to figure out how to patch some obscure lib install. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

Sometimes, it's tough to troubleshoot live issues where you need to do kubectl exec into a pod. This is a somewhat rare edge case, but it's something we've run into.

It's also sometimes hard to get certain packages fully working (eg a python pandas packages needs a driver which may not be present in the base image). Review collected by and hosted on G2.com.

Response from Sarah Haberman of Chainguard

Hey Ben 👋 Thanks for the great review! Glad to hear you're having a great experience with Chainguard!

Angel B.
AB
Customer Support Supervisor
Small-Business (50 or fewer emp.)
"Easy-to-Use, Secure Container Images"
What do you like best about Chainguard?

The container images are easy to use and provide a secure environment. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

The integration process is not straightforward, and the cost can be high for individual users. Review collected by and hosted on G2.com.

Chandra G.
CG
Senior Release/DevOps Engineer
Enterprise (> 1000 emp.)
"Secure, Minimal, and Well-Supported — A Great Experience with Room for Transparency Improvements"
What do you like best about Chainguard?

Chainguard Images have been a transformative addition to our software supply chain strategy. The minimal, hardened, and continuously verified container images significantly reduce our attack surface while ensuring compliance and operational reliability.

One of the biggest pain points in container security is managing outdated or bloated base images filled with vulnerabilities. Chainguard solves this brilliantly with distroless, signed images that are continuously updated and come with built-in provenance and SBOMs. It’s clear they’ve thought deeply about what modern development teams need to build secure-by-default applications.

What really sets Chainguard apart, though, is their exceptional support. From day one, their team has been proactive, responsive, and genuinely invested in our success. Whether it was help with integration, optimizing our image choices, or answering security policy questions, their support engineers went above and beyond. Their documentation is also thorough and developer-friendly, which makes onboarding smooth and intuitive.

In summary: Chainguard Images bring peace of mind to any DevSecOps team, and their world-class support makes them a true partner in software supply chain security. Highly recommended for anyone building or deploying containers in a production environment Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

One area that could use improvement is transparency around source code and SBOM (Software Bill of Materials) access. While the images are secure and well-maintained, having easier access to corresponding source repositories and complete SBOMs—preferably in an automated or standardized format—would help us meet internal audit and compliance requirements more seamlessly. Review collected by and hosted on G2.com.

Response from Sarah Haberman of Chainguard

Chandra, thanks for taking the time to write such a thorough review! 🙌

Charlie G.
CG
SRE Manager
Mid-Market (51-1000 emp.)
"The gold star vendor: sales, onboarding implementation, support, and product"
What do you like best about Chainguard?

The chainguard team was able to meet us where we were at, move extremely quickly to meet our deadlines, and everything _just worked_. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

Wiz sometimes detects false positives in cgr images. Review collected by and hosted on G2.com.

Response from Sarah Haberman of Chainguard

Charlie, what a great review! We'll take that gold star - thank you! ⭐️

Ken A.
KA
Principal Application Architect
Human Resources
Enterprise (> 1000 emp.)
"We used chainguard base images to"
What do you like best about Chainguard?

Using chainguard essentially eliminates container library vulnerabilities coming from our Docker base images (as well as standard package installs!). When we scan our chainguard based images with grype, or snyk, the only vulnerabilities left are from our application installs. We are in the process of implementing chainguard base images across the enterprise, and are expecting over 80% reduction in open vulnerabilities across the board. Chainguard's customer support is excellent, they are one of the best software vendors I have ever worked with. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

The only real downside is you have to modify your Dockerfiles to work with the Wolfi OS, which is alpine-like (i.e. you have to use apk, etc.) If your current base image is not alpine based, there is some learning curve and work. Review collected by and hosted on G2.com.

Response from Kirby Koo of Chainguard

Thank you, Ken!

Dan E.
DE
Senior Cybersecurity Engineer
Enterprise (> 1000 emp.)
"Chainguard has changed the game when it comes to remediating vulns in images."
What do you like best about Chainguard?

I love the ease of use for our dev teams to switch over and cut their vulnerabilities down. Integrating it into our pipelines has been very easy. Customer support has been excellent and responsive. Review collected by and hosted on G2.com.

What do you dislike about Chainguard?

At this time of using the product I do not have any dislikes Review collected by and hosted on G2.com.

Response from Kirby Koo of Chainguard

Aww, thanks for taking the time to review us! Your support means a lot :)

Pricing Insights

Averages based on real user reviews.

Time to Implement

2 months

Return on Investment

6 months

Chainguard Comparisons
Product Avatar Image
Snyk
Compare Now
Product Avatar Image
Wiz
Compare Now
Chainguard Features
Risk Scoring
Secrets Management
Security Auditing
Continuous Image Assurance
Behavior Monitoring
Observability
Dynamic Image Scanning
Runtime Protection
Workload Protection
Product Avatar Image
Product Avatar Image