Cyber Security News

Docker Open Sources Production-Ready Hardened Images for Free

Docker has announced a significant shift in its container security strategy, making its Docker Hardened Images (DHI) freely available to all developers.

Previously a commercial-only offering, DHI provides a set of secure, minimal, and production-ready container images.

By releasing these under an Apache 2.0 license, Docker aims to combat the rising tide of software supply chain attacks, which caused over $60 billion in damages in 2025.

With over 20 billion monthly pulls on Docker Hub, Docker is the standard for software delivery. The new initiative ensures that every developer, regardless of budget, starts with a secure foundation.

Unlike proprietary alternatives, DHI is fully open source and compatible with popular foundations like Alpine and Debian.

This ensures teams can adopt these secure images without rewriting their existing Dockerfiles or changing workflows.

Docker emphasizes that “hardened” does not mean opaque. The free DHI offering includes:

FeatureDescription
Full TransparencyProvides a complete Software Bill of Materials (SBOM) for every image
ProvenanceUses SLSA Build Level 3 verification
Honest ReportingShows full CVE status without hiding vulnerability warnings
Reduced Attack SurfaceImages are up to 95% smaller, lowering security risk

Enterprise Options Remain

While the base images are now free, Docker continues to offer DHI Enterprise for organizations with strict regulatory requirements.

The commercial tier focuses on service-level agreements (SLAs) rather than gatekeeping the security technology itself. Docker is also expanding this program beyond basic OS images.

FeatureDocker Hardened Images (Free)DHI Enterprise (Paid)
AvailabilityOpen Source (Apache 2.0)Commercial License
Base OSAlpine, DebianAlpine, Debian + Custom
Patching SpeedStandard Release Cycle<7 Day SLA for Critical CVEs
ComplianceStandard SecurityFIPS, FedRAMP, STIG
LifecycleStandard SupportExtended Lifecycle Support (ELS)

The release includes Hardened Helm Charts for Kubernetes and trusted versions of the Model Context Protocol (MCP) servers for popular tools such as MongoDB, Grafana, and GitHub.

By making these tools free, Docker is effectively raising the “security poverty line,” ensuring that secure software delivery is a standard, not a luxury.

AI-Powered ISO 27001, SOC 2, NIST, NIS 2, and GDPR Compliance Checklist => Start for Free

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

CISA Red Team Breaches Critical Infrastructure to Reveal SOC and Cloud Security Gaps

CISA's latest advisory for red teams warns critical infrastructure operators that security systems can fail…

6 hours ago

AI Security Startup Alice Raises $140 Million as Enterprise AI Threats Surge

Alice, the AI trust, safety, and security company formerly known as ActiveFence, has closed a…

7 hours ago

SynkLoader Mimic as IT Support Personnel Attacking Users Via Microsoft Teams

SynkLoader is using Microsoft Teams conversations to turn routine IT support requests into a route…

8 hours ago

ToxNetV2 Linux Botnet Uses NVIDIA AI to Generate Shell and Remote SSH Attack Actions

ToxNetV2 is a Linux botnet that shows how artificial intelligence can move closer to real…

8 hours ago

WhatsApp Passkeys Reach 1 Billion Users as Two-Step Verification Gets Stronger Passwords

WhatsApp has confirmed that more than 1 billion people now use passkeys to log into…

8 hours ago

ASOS Warns Customer Accounts Were Accessed Using Compromised Login Credentials

ASOS US Sales LLC reported unauthorized access to customer accounts using credentials obtained from outside…

9 hours ago