OCImendby CloudTrace

Free · online · verified

CVE-free container images

OCImend gives you CVE-free container images for free: any Docker or OCI image goes in, every known vulnerability that has a fixed package comes out fixed, and the new image is rescanned and started side by side with the original before it is published. Pull the ready ones below, or paste your own image and get it back fixed in minutes, no sign-up.

Make my image CVE-free → Browse the registry

21ready-to-pull images on this page
1,366known CVEs removed from them
Freeno sign-up, nothing to install
Verifiedrescanned and run-tested

Why OCImend

Same image, fixed

Your image, not a rebuild on a different base: the vulnerable packages are upgraded to the versions that fix them and compiled Go programs are rebuilt with fixed releases.

Verified, not promised

Every image is rescanned (the before/after CVE count is on its report) and started next to the original to make sure it still runs.

Honest about what is left

A CVE with no fix released anywhere is listed as such, with the measured ways out: a newer base, a hardened image.

Yours to keep

Pull from ocimend.io, promote by digest into your own registry, or take the Dockerfile and rebuild it in your CI.

Ready to pull

ImagePullKnown CVEs before → afterBuilt
elasticsearch
from mirror.gcr.io/library/elasticsearch:8.13.0
docker pull ocimend.io/elasticsearch:8.13.0-fixed160 → 1472026-10-01
haproxy
from mirror.gcr.io/library/haproxy:2.6-alpine3.22
docker pull ocimend.io/haproxy:2.6-alpine3.22-fixed101 → 02026-10-01
eclipse-temurin
from mirror.gcr.io/library/eclipse-temurin:17.0.20.1_1-jdk
docker pull ocimend.io/eclipse-temurin:17.0.20.1_1-jdk-fixed357 → 3542026-10-01
mongo
from mirror.gcr.io/library/mongo:bionic
docker pull ocimend.io/mongo:bionic-fixed282 → 1202026-10-01
alpine
from mirror.gcr.io/library/alpine:3.17.7
docker pull ocimend.io/alpine:3.17.7-fixed20 → 02026-10-01
golang
from mirror.gcr.io/library/golang:1.21-alpine3.19
docker pull ocimend.io/golang:1.21-alpine3.19-fixed60 → 582026-10-01
python
from mirror.gcr.io/library/python:3.13.0a1-alpine3.17
docker pull ocimend.io/python:3.13.0a1-alpine3.17-fixed48 → 02026-10-01
redis
from mirror.gcr.io/library/redis:7.0.14-alpine3.18
docker pull ocimend.io/redis:7.0.14-alpine3.18-fixed26 → 02026-10-01
ubuntu
from mirror.gcr.io/library/ubuntu:resolute-20260108
docker pull ocimend.io/ubuntu:resolute-20260108-fixed220 → 922026-09-30
rabbitmq
from mirror.gcr.io/library/rabbitmq:3.7-alpine
docker pull ocimend.io/rabbitmq:3.7-alpine-fixed50 → 02026-09-30
node
from mirror.gcr.io/library/node:26.0.0-alpine
docker pull ocimend.io/node:26.0.0-alpine-fixed76 → 262026-09-30
ruby
from mirror.gcr.io/library/ruby:3.3.9-alpine
docker pull ocimend.io/ruby:3.3.9-alpine-fixed100 → 02026-09-29
mariadb
from mirror.gcr.io/library/mariadb:10.6.16
docker pull ocimend.io/mariadb:10.6.16-fixed190 → 1652026-09-29
php
from mirror.gcr.io/library/php:7.3.28-fpm
docker pull ocimend.io/php:7.3.28-fpm-fixed121 → 02026-09-28
caddy
from mirror.gcr.io/library/caddy:2.10.2-builder-alpine
docker pull ocimend.io/caddy:2.10.2-builder-alpine-fixed260 → 802026-09-28
httpd
from mirror.gcr.io/library/httpd:2.4.61
docker pull ocimend.io/httpd:2.4.61-fixed107 → 892026-09-28
registry.access.redhat.com/ubi9/ubi-minimal
from registry.access.redhat.com/ubi9/ubi-minimal:latest
docker pull ocimend.io/registry.access.redhat.com/ubi9/ubi-minimal:latest-fixed1 → 02026-09-27
traefik
from mirror.gcr.io/library/traefik:v3.3.0
docker pull ocimend.io/traefik:v3.3.0-fixed210 → 1342026-09-27
postgres
from mirror.gcr.io/library/postgres:16.12-alpine3.22
docker pull ocimend.io/postgres:16.12-alpine3.22-fixed123 → 462026-09-27
nginx
from mirror.gcr.io/library/nginx:1.19.5-alpine-perl
docker pull ocimend.io/nginx:1.19.5-alpine-perl-fixed98 → 02026-09-27
mysql
from mirror.gcr.io/library/mysql:8.0.17
docker pull ocimend.io/mysql:8.0.17-fixed67 → 02026-09-27

Questions

Is a CVE-free image really zero CVEs?
Every CVE that has a fixed package is fixed. A CVE with no fix released yet cannot be fixed by anyone without changing the software; OCImend lists those separately so the count you see is honest.
Is it free?
Yes. Scanning, fixing and pulling public images from ocimend.io is free, with no sign-up.
Does it work for my private image?
Yes. Scan it with a read token (used once, never stored); the fixed image is delivered privately and is not published.
How do I stay CVE-free?
Watch the image: it is rescanned as new CVEs are published, and rebuilt when new fixes ship.

Also on OCImend

FIPS-enabled images · Free online CVE fix · Hardened images · Image CVE reports · Guides · For platform teams

Make my image CVE-free →