OCImendby CloudTrace

Free · online · verified

Fix container CVEs online, free

Paste any Docker or OCI image name into OCImend and choose an outcome: CVE-fixed, FIPS-enabled or hardened. OCImend scans it, fixes it, rescans and tests the new image, and publishes it at ocimend.io with a before/after report, usually in minutes. It is free, online, with nothing to install and no sign-up.

Fix an image now → Browse the registry

29ready-to-pull images on this page
460known CVEs removed from them
Freeno sign-up, nothing to install
Verifiedrescanned and run-tested

Why OCImend

1. Paste an image

Any public registry: Docker Hub, GHCR, Quay, ECR Public, GCR, or a private one with a read token.

2. Pick an outcome

CVE-fixed, FIPS-enabled, hardened (smaller, optionally non-root), or a combination.

3. Verified build

Rescanned for CVEs and started side by side with the original before it is published.

4. Pull or adopt

docker pull from ocimend.io, copy into your registry by digest, take the Dockerfile, or open a pull request to the source.

Ready to pull

ImagePullKnown CVEs before → afterBuilt
elasticsearch
from mirror.gcr.io/library/elasticsearch:8.13.0
docker pull ocimend.io/elasticsearch:8.13.0-fixed160 → 1472026-10-01
registry.access.redhat.com/ubi9/ubi-minimal
from registry.access.redhat.com/ubi9/ubi-minimal:9.8-1790754119
docker pull ocimend.io/registry.access.redhat.com/ubi9/ubi-minimal:9.8-1790754119-fips0 → 02026-10-01
wordpress
from mirror.gcr.io/library/wordpress:7.1.1-php8.4-fpm
docker pull ocimend.io/wordpress:7.1.1-php8.4-fpm-fips186 → 1862026-10-01
ruby
from mirror.gcr.io/library/ruby:4.0.2
docker pull ocimend.io/ruby:4.0.2-fips379 → 3792026-10-01
php
from mirror.gcr.io/library/php:8.5.10-zts-alpine3.24
docker pull ocimend.io/php:8.5.10-zts-alpine3.24-fips0 → 02026-10-01
haproxy
from mirror.gcr.io/library/haproxy:2.6-alpine3.22
docker pull ocimend.io/haproxy:2.6-alpine3.22-fips101 → 1012026-10-01
eclipse-temurin
from mirror.gcr.io/library/eclipse-temurin:17.0.20.1_1-jdk
docker pull ocimend.io/eclipse-temurin:17.0.20.1_1-jdk-fixed357 → 3542026-10-01
traefik
from mirror.gcr.io/library/traefik:v3.1.3
docker pull ocimend.io/traefik:v3.1.3-fips141 → 1412026-10-01
mongo
from mirror.gcr.io/library/mongo:bionic
docker pull ocimend.io/mongo:bionic-fixed282 → 1202026-10-01
mariadb
from mirror.gcr.io/library/mariadb:11.4.4
docker pull ocimend.io/mariadb:11.4.4-fips309 → 3092026-10-01
ubuntu
from mirror.gcr.io/library/ubuntu:noble-20250404
docker pull ocimend.io/ubuntu:noble-20250404-fips6 → 62026-10-01
alpine
from mirror.gcr.io/library/alpine:20221110
docker pull ocimend.io/alpine:20221110-fips0 → 02026-10-01
golang
from mirror.gcr.io/library/golang:1.21-alpine3.19
docker pull ocimend.io/golang:1.21-alpine3.19-fixed60 → 582026-10-01
python
from mirror.gcr.io/library/python:3.13.0a1-alpine3.17
docker pull ocimend.io/python:3.13.0a1-alpine3.17-fips48 → 482026-10-01
postgres
from mirror.gcr.io/library/postgres:14.24-trixie
docker pull ocimend.io/postgres:14.24-trixie-fips112 → 1122026-10-01
redis
from mirror.gcr.io/library/redis:7.0.14-alpine3.18
docker pull ocimend.io/redis:7.0.14-alpine3.18-fips26 → 262026-10-01
nginx
from mirror.gcr.io/library/nginx:1.28.2
docker pull ocimend.io/nginx:1.28.2-fips65 → 652026-10-01
registry.access.redhat.com/ubi9/ubi
from registry.access.redhat.com/ubi9/ubi:9.8-1790665138
docker pull ocimend.io/registry.access.redhat.com/ubi9/ubi:9.8-1790665138-fips18 → 182026-09-30
rabbitmq
from mirror.gcr.io/library/rabbitmq:3.7-alpine
docker pull ocimend.io/rabbitmq:3.7-alpine-fixed50 → 02026-09-30
debian
from mirror.gcr.io/library/debian:trixie-20260623-slim
docker pull ocimend.io/debian:trixie-20260623-slim-fips26 → 262026-09-30
node
from mirror.gcr.io/library/node:26.0.0-alpine
docker pull ocimend.io/node:26.0.0-alpine-fixed76 → 262026-09-30
mysql
from mirror.gcr.io/library/mysql:8.0.44-oracle
docker pull ocimend.io/mysql:8.0.44-oracle-fips68 → 682026-09-29
caddy
from mirror.gcr.io/library/caddy:2.10.2-builder-alpine
docker pull ocimend.io/caddy:2.10.2-builder-alpine-fixed260 → 802026-09-28
httpd
from mirror.gcr.io/library/httpd:2.4.61
docker pull ocimend.io/httpd:2.4.61-fips107 → 1072026-09-28
gcr.io/distroless/base-debian12
from gcr.io/distroless/base-debian12:latest
docker pull ocimend.io/gcr.io/distroless/base-debian12:latest-fips3 → 32026-09-27
mcr.microsoft.com/azurelinux/base/core
from mcr.microsoft.com/azurelinux/base/core:3.0.20260909
docker pull ocimend.io/mcr.microsoft.com/azurelinux/base/core:3.0.20260909-fips30 → 302026-09-27
registry
from mirror.gcr.io/library/registry:latest
docker pull ocimend.io/registry:latest-fips0 → 72026-09-27
memcached
from mirror.gcr.io/library/memcached:latest
docker pull ocimend.io/memcached:latest-fips26 → 262026-09-27
ubuntu/nginx
from docker.io/ubuntu/nginx:latest
docker pull ocimend.io/ubuntu/nginx:latest-fips0 → 02026-09-26

Questions

How long does a fix take?
Most images are fixed and verified in a few minutes; large images take longer. The page shows progress live.
What if a CVE has no fix?
It is reported as having no fix yet, with the ways out OCImend measured for that image (a newer base, a hardened image).
Can I use it in CI?
Yes: the API scans, gates and fixes images from a pipeline.
Is my image published?
Only images scanned without credentials are published. Private images stay private.

Also on OCImend

CVE-free images · FIPS-enabled images · Hardened images · Image CVE reports · Guides · For platform teams

Fix an image now →