Free · online · verified
Hardened container images
A hardened container image keeps what the application needs and drops the rest: shells, package managers and libraries it never loads, which removes their CVEs and attack surface; optionally it runs as a non-root user. OCImend hardens any Docker or OCI image for free, verifies it still runs, and publishes it with a hardening report. Pull the ready ones below or harden your own online.
Harden my image → Browse the registry
Why OCImend
Only what it uses
Packages the application does not use are removed, safely: nothing it depends on goes.
Non-root option
Runs as an unprivileged user when the application allows it.
Smaller and fewer CVEs
The report shows size and CVE count before and after.
Still your image
Same application, same entrypoint, tested side by side with the original.
Ready to pull
| Image | Pull | Known CVEs before → after | Built |
|---|---|---|---|
| python from docker.io/library/python:3.12-slim | docker pull ocimend.io/python:3.12-slim-hardened | 32 → 26 | 2026-09-28 |
| registry.access.redhat.com/ubi9/ubi-minimal from registry.access.redhat.com/ubi9/ubi-minimal:latest | docker pull ocimend.io/registry.access.redhat.com/ubi9/ubi-minimal:latest-hardened | 1 → 0 | 2026-09-27 |
Questions
Hardened image vs distroless?
Will it break my image?
Is it free?
Can I combine it with FIPS?
Also on OCImend
CVE-free images · FIPS-enabled images · Free online CVE fix · Image CVE reports · Guides · For platform teams