0
Fork 0
mirror of https://github.com/rtvkiz/minimal.git synced 2026-09-29 06:45:13 +00:00
Minimal CVE Hardened container image collection
  • Shell 52.3%
  • Makefile 27%
  • Astro 12.5%
  • JavaScript 5.3%
  • CSS 1.9%
  • Other 1%
Find a file
minimal-ci-bot[bot] 549c5d665f
chore(velero): bump to 1.18.4 (#777)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: minimal-ci-bot[bot] <280164851+minimal-ci-bot[bot]@users.noreply.github.com>
History 2026-09-29 02:20:19 +00:00
.github feat: onboard Kong and CouchDB (Wave 3, part 1) (#779) 2026-09-28 22:00:52 -04:00
assets feat(brand): refresh README logo to match the site monogram (#346) 2026-07-07 00:07:06 -04:00
docs docs(roadmap): correct wave-3 status — kong/couchdb shipped, sonarqube/nextcloud reclassified 2026-09-28 19:51:19 -04:00
images chore(velero): bump to 1.18.4 (#777) 2026-09-29 02:20:19 +00:00
scripts fix(check-autoupdate): ignore comments in the hardcoded-version gate 2026-09-21 19:35:28 -04:00
site blog: add 'Kafka 4.x moved your config paths and didn't make a fuss about it' 2026-09-28 19:53:56 -04:00
tests fix(updater): validate digest algorithms 2026-09-17 14:22:06 -04:00
tools fix(cve-compare): apply apk provenance reconciliation to the comparison 2026-09-10 21:22:54 -04:00
vex feat: onboard Kong and CouchDB (Wave 3, part 1) (#779) 2026-09-28 22:00:52 -04:00
.gitignore feat(site): SEO foundation, comparison pages and blog (#632) 2026-08-31 21:47:43 -04:00
catalog.json feat: onboard Kong and CouchDB (Wave 3, part 1) (#779) 2026-09-28 22:00:52 -04:00
CONTRIBUTING.md refactor: move the 101 image directories under images/ (#551) 2026-08-16 08:36:47 -04:00
LICENSE Add Bun container image 2026-01-30 21:18:30 -05:00
Makefile feat: onboard Kong and CouchDB (Wave 3, part 1) (#779) 2026-09-28 22:00:52 -04:00
README.md feat: onboard Kong and CouchDB (Wave 3, part 1) (#779) 2026-09-28 22:00:52 -04:00

minimal — hardened container images

132 small, hardened container images. Free, MIT-licensed, signed, and rebuilt every six hours.

Browse the catalog →

Build status Images: 132 SLSA Build L2 Architectures: amd64 and arm64 License: MIT


Quick start

docker pull ghcr.io/rtvkiz/minimal-python:latest

No account needed. Every image has a :latest-dev companion with a shell and toolchain for debugging and multi-stage builds.

docker run --rm -p 8080:80 ghcr.io/rtvkiz/minimal-nginx:latest
docker run --rm -p 6379:6379 ghcr.io/rtvkiz/minimal-redis-slim:latest

Find an image → — all 124, with live sizes and CVE counts.

Verify what you pulled

gh attestation verify oci://ghcr.io/rtvkiz/minimal-python:latest --owner rtvkiz

Every published image carries a keyless Cosign signature, an SPDX SBOM, and SLSA v1.0 build provenance tied to the workflow and commit that produced it.

Signature, SBOM, and provenance commands →

What makes these different

  • Small and shell-less — production images ship no /bin/sh where the application permits it, and run as non-root by default.
  • Built from source — public, readable melange recipes, not a repackaged base image. Native amd64 and arm64.
  • Never stale — rebuilt every six hours against current Wolfi packages; upstream releases and transitive CVEs open their own auto-merging PRs.
  • Verifiable — signed, with SBOM and provenance attached to every digest.

No vendor SLA, support contract, or FedRAMP/FIPS/STIG accreditation. The signatures, SBOMs, and provenance help with verification and audits; they do not replace those programs.

Pinning

FROM ghcr.io/rtvkiz/minimal-python@sha256:<digest>   # immutable
FROM ghcr.io/rtvkiz/minimal-python:3                 # patched, no major jumps

:latest crosses major versions; an exact version tag never moves at all.

Tags and pinning →

On vulnerability counts

A green build does not mean zero findings. Grype scans every production image and results are informational — they do not block publication. The catalog shows raw and VEX-effective counts side by side, and suppressions are reconciled against each fresh scan so they cannot quietly go stale.

Reading scan results →

Contributing

make python && make test-python                       # apko-only image
make caddy-melange && make caddy && make test-caddy   # source-built image

PRs welcome. CONTRIBUTING.md covers tooling and layout; docs/onboarding.md is the complete checklist for adding an image; docs/roadmap.md is the demand-ranked backlog.

Security issues: please use private vulnerability reporting rather than a public issue.

License

MIT — see LICENSE. Images include Wolfi and upstream packages under their own licenses; each image's SPDX SBOM has the details.