# Docker Hardened Images

Published articles for Docker Hardened Images.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Moving from Minimus to Docker Hardened Images

DevFeed: [Moving from Minimus to Docker Hardened Images](<https://devfeed.tech/articles/moving-from-minimus-to-docker-hardened-images-4590.md>)

Original publisher: [Read original article](<https://www.docker.com/blog/moving-from-minimus-to-docker-hardened-images/>)

Author: Vishrut Iyengar

Published: 2026-08-25T22:27:06Z

Content type: article

Language: en

Sources: [Docker](<https://devfeed.tech/sources/docker.md>)

Topics: [Docker Hardened Images](<https://devfeed.tech/topics/docker-hardened-images.md>), [migration](<https://devfeed.tech/topics/migration.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Docker Hub](<https://devfeed.tech/topics/docker-hub.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Debian](<https://devfeed.tech/topics/debian.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [apache](<https://devfeed.tech/tags/apache.md>), [ci](<https://devfeed.tech/tags/ci.md>), [community](<https://devfeed.tech/tags/community.md>), [debian](<https://devfeed.tech/tags/debian.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-hardened-images](<https://devfeed.tech/tags/docker-hardened-images.md>), [docker-hub](<https://devfeed.tech/tags/docker-hub.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [guide](<https://devfeed.tech/tags/guide.md>), [migration](<https://devfeed.tech/tags/migration.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [products](<https://devfeed.tech/tags/products.md>), [security](<https://devfeed.tech/tags/security.md>), [solutions](<https://devfeed.tech/tags/solutions.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Docker explains how Minimus customers can migrate to Docker Hardened Images before the Minimus registry goes offline on October 22, 2026. The article highlights the 60-day maintenance window, free migration assistance, DHI's open-source Apache 2.0 catalog, and a drop-in migration process centered on updating Dockerfile FROM lines.

### Source excerpt

The Minimus registry goes offline on October 22. Here is the migration path, the free help Docker is offering, and where to start.

## MinIO End of Life: How to Stay Patched and Audit-Ready with Docker ELS

DevFeed: [MinIO End of Life: How to Stay Patched and Audit-Ready with Docker ELS](<https://devfeed.tech/articles/minio-end-of-life-how-to-stay-patched-and-audit-ready-with-docker-els-4589.md>)

Original publisher: [Read original article](<https://www.docker.com/blog/minio-end-of-life-how-to-stay-patched-and-audit-ready-with-docker-els/>)

Author: Vishrut Iyengar

Published: 2026-08-24T13:00:00Z

Content type: article

Language: en

Sources: [Docker](<https://devfeed.tech/sources/docker.md>)

Topics: [Docker Hardened Images](<https://devfeed.tech/topics/docker-hardened-images.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [migration](<https://devfeed.tech/topics/migration.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Go](<https://devfeed.tech/topics/go.md>)

Tags: [community](<https://devfeed.tech/tags/community.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-hardened-images](<https://devfeed.tech/tags/docker-hardened-images.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [go](<https://devfeed.tech/tags/go.md>), [migration](<https://devfeed.tech/tags/migration.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [production](<https://devfeed.tech/tags/production.md>), [products](<https://devfeed.tech/tags/products.md>), [releases](<https://devfeed.tech/tags/releases.md>), [security](<https://devfeed.tech/tags/security.md>), [solutions](<https://devfeed.tech/tags/solutions.md>)

### AI overview

Docker's Extended Lifecycle Support keeps MinIO patched and audit-ready after the project's upstream end of life. The article explains how Docker maintains hardened images, tracks CVEs across MinIO and its Go dependencies, backports fixes, and supports teams that cannot immediately migrate their production object storage.

### Source excerpt

MinIO reached end of life in February 2026. Docker Extended Lifecycle Support (ELS) keeps end-of-life software like it patched, compliant, and audit-ready for up to five years, covering versions upstream no longer supports all the way up to entire projects.

## 17,600 Actions: Agent Security Is a Systems Problem

DevFeed: [17,600 Actions: Agent Security Is a Systems Problem](<https://devfeed.tech/articles/17-600-actions-agent-security-is-a-systems-problem-4584.md>)

Original publisher: [Read original article](<https://www.docker.com/blog/ai-agent-security-systems-problem/>)

Author: Jin Kim

Published: 2026-08-18T16:00:00Z

Content type: opinion

Language: en

Sources: [Docker](<https://devfeed.tech/sources/docker.md>)

Topics: [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Security](<https://devfeed.tech/topics/security.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Securing AI](<https://devfeed.tech/topics/securing-ai.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Benchmark](<https://devfeed.tech/topics/benchmark.md>), [benchmarking](<https://devfeed.tech/topics/benchmarking.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [ai-ml](<https://devfeed.tech/tags/ai-ml.md>), [benchmark](<https://devfeed.tech/tags/benchmark.md>), [community](<https://devfeed.tech/tags/community.md>), [company](<https://devfeed.tech/tags/company.md>), [dhi](<https://devfeed.tech/tags/dhi.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-ai-governance](<https://devfeed.tech/tags/docker-ai-governance.md>), [docker-hardened-images](<https://devfeed.tech/tags/docker-hardened-images.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [evaluation](<https://devfeed.tech/tags/evaluation.md>), [hugging-face](<https://devfeed.tech/tags/hugging-face.md>), [incident](<https://devfeed.tech/tags/incident.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [model](<https://devfeed.tech/tags/model.md>), [network](<https://devfeed.tech/tags/network.md>), [openai](<https://devfeed.tech/tags/openai.md>), [opinion](<https://devfeed.tech/tags/opinion.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [sandboxes](<https://devfeed.tech/tags/sandboxes.md>), [security](<https://devfeed.tech/tags/security.md>), [solutions](<https://devfeed.tech/tags/solutions.md>), [systems](<https://devfeed.tech/tags/systems.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article argues that AI-agent security is a systems problem, using the OpenAI/Hugging Face incident and its approximately 17,600 attacker actions to show why human approval and ordinary alert triage cannot control persistent, high-rate workloads. It emphasizes constraining authority, credentials, network access, state, and execution across environments.

### Source excerpt

The OpenAI/Hugging Face incident exposed a new challenge for AI agent security. 17,600 attacker actions show why AI agent security can't rely on human review. Explore the controls needed to constrain, observe, and govern agents at speed.

## ClickHouse on Docker Hardened Images

DevFeed: [ClickHouse on Docker Hardened Images](<https://devfeed.tech/articles/clickhouse-on-docker-hardened-images-5228.md>)

Original publisher: [Read original article](<https://clickhouse.com/blog/docker-hardened-images>)

Author: Karolina Ruiz Rogelj; Melvyn Peignon

Published: 2026-07-10T15:28:34Z

Content type: article

Language: en

Sources: [ClickHouse Blog](<https://devfeed.tech/sources/clickhouse-blog.md>)

Topics: [clickhouse](<https://devfeed.tech/topics/clickhouse.md>), [Docker Hardened Images](<https://devfeed.tech/topics/docker-hardened-images.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Docker Image](<https://devfeed.tech/topics/docker-image.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Ubuntu](<https://devfeed.tech/topics/ubuntu.md>), [apt](<https://devfeed.tech/topics/apt.md>), [Perl](<https://devfeed.tech/topics/perl.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>)

Tags: [apt](<https://devfeed.tech/tags/apt.md>), [clickhouse](<https://devfeed.tech/tags/clickhouse.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [developers](<https://devfeed.tech/tags/developers.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-hardened-images](<https://devfeed.tech/tags/docker-hardened-images.md>), [docker-hub](<https://devfeed.tech/tags/docker-hub.md>), [docker-image](<https://devfeed.tech/tags/docker-image.md>), [images](<https://devfeed.tech/tags/images.md>), [security](<https://devfeed.tech/tags/security.md>), [ubuntu](<https://devfeed.tech/tags/ubuntu.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

ClickHouse is now available as a Docker Hardened Image: a minimal, security-hardened build that preserves ClickHouse behavior while shipping only the components needed to run the database and pass enterprise vulnerability scans.

### Source excerpt

ClickHouse is now available as a Docker Hardened Image: a minimal, security-hardened build that passes enterprise vulnerability scans by shipping only what the database needs to run, with no change to how ClickHouse behaves.

## Docker Hodgepodge Images

DevFeed: [Docker Hodgepodge Images](<https://devfeed.tech/articles/docker-hodgepodge-images-13023.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/docker-hodgepodge-images>)

Published: 2026-04-15T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Docker Hardened Images](<https://devfeed.tech/topics/docker-hardened-images.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Docker](<https://devfeed.tech/topics/docker.md>)

Tags: [chainguard-vs-docker](<https://devfeed.tech/tags/chainguard-vs-docker.md>), [dhi](<https://devfeed.tech/tags/dhi.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-containers](<https://devfeed.tech/tags/docker-containers.md>), [docker-hardened-images](<https://devfeed.tech/tags/docker-hardened-images.md>), [docker-images](<https://devfeed.tech/tags/docker-images.md>), [free-container-images](<https://devfeed.tech/tags/free-container-images.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-scanner](<https://devfeed.tech/tags/vulnerability-scanner.md>)

### AI overview

The article argues that Docker Hardened Images are Debian Trixie derivatives rather than ordinary Debian images. It contends that Docker's custom repository, rebuilt packages, and operating-system identification can cause vulnerability scanners and related tools to produce inaccurate results, creating supply chain security concerns.

### Source excerpt

Docker ships their own Linux distro, they just pretend not to. Learn how misidentification and VEX usage can mislead scanners and impact supply chain security.

## Going deep: Upstream distros and hidden CVEs

DevFeed: [Going deep: Upstream distros and hidden CVEs](<https://devfeed.tech/articles/going-deep-upstream-distros-and-hidden-cves-13069.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/going-deep-upstream-distros-and-hidden-cves>)

Published: 2026-02-25T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Docker Hardened Images](<https://devfeed.tech/topics/docker-hardened-images.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Debian](<https://devfeed.tech/topics/debian.md>), [Docker](<https://devfeed.tech/topics/docker.md>)

Tags: [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [debian](<https://devfeed.tech/tags/debian.md>), [debian-containers](<https://devfeed.tech/tags/debian-containers.md>), [dhi](<https://devfeed.tech/tags/dhi.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-containers](<https://devfeed.tech/tags/docker-containers.md>), [docker-hardened-images](<https://devfeed.tech/tags/docker-hardened-images.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vex](<https://devfeed.tech/tags/vex.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

The article argues that container vendors relying on upstream distributions such as Debian or Alpine can inherit vulnerabilities because fixes may lag between upstream availability and downstream image releases. It examines Docker Hardened Images and claims that some CVEs are suppressed through no-DSA classifications and VEX documents even when fixes exist upstream but have not been incorporated into the images.

### Source excerpt

Are all zero-CVE images truly secure? A deep dive into Debian no-DSA, VEX suppression, and why transparency matters in container supply chain security.

## How I learned to stop worrying and love the latest tag

DevFeed: [How I learned to stop worrying and love the latest tag](<https://devfeed.tech/articles/how-i-learned-to-stop-worrying-and-love-the-latest-tag-13090.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-i-learned-to-stop-worrying-and-love-the-latest-tag>)

Published: 2026-02-11T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [container images](<https://devfeed.tech/topics/container-images.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Docker Hardened Images](<https://devfeed.tech/topics/docker-hardened-images.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [YAML](<https://devfeed.tech/topics/yaml.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-automations](<https://devfeed.tech/tags/chainguard-automations.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-factory](<https://devfeed.tech/tags/chainguard-factory.md>), [container-image-digests](<https://devfeed.tech/tags/container-image-digests.md>), [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [digestabot](<https://devfeed.tech/tags/digestabot.md>), [digests](<https://devfeed.tech/tags/digests.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-hardened-images](<https://devfeed.tech/tags/docker-hardened-images.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [latest-tag](<https://devfeed.tech/tags/latest-tag.md>), [reproducibility](<https://devfeed.tech/tags/reproducibility.md>)

### AI overview

The article explains how to use the latest tag as part of a secure container image update strategy. It recommends pinning images to cryptographic digests to ensure reproducibility, enable reliable rollbacks, and prevent unexpected version changes, while retaining tags for readability and tooling. It also introduces automated workflows for finding and updating digests.

### Source excerpt

The latest tag isn't unsafe by default -- pin images to digests for reproducible, secure updates while staying current with automated workflows.