OCImendby CloudTrace

Free · online · verified

Hardened container images

A hardened container image keeps what the application needs and drops the rest: shells, package managers and libraries it never loads, which removes their CVEs and attack surface; optionally it runs as a non-root user. OCImend hardens any Docker or OCI image for free, verifies it still runs, and publishes it with a hardening report. Pull the ready ones below or harden your own online.

Harden my image → Browse the registry

2ready-to-pull images on this page
7known CVEs removed from them
Freeno sign-up, nothing to install
Verifiedrescanned and run-tested

Why OCImend

Only what it uses

Packages the application does not use are removed, safely: nothing it depends on goes.

Non-root option

Runs as an unprivileged user when the application allows it.

Smaller and fewer CVEs

The report shows size and CVE count before and after.

Still your image

Same application, same entrypoint, tested side by side with the original.

Ready to pull

ImagePullKnown CVEs before → afterBuilt
python
from docker.io/library/python:3.12-slim
docker pull ocimend.io/python:3.12-slim-hardened32 → 262026-09-28
registry.access.redhat.com/ubi9/ubi-minimal
from registry.access.redhat.com/ubi9/ubi-minimal:latest
docker pull ocimend.io/registry.access.redhat.com/ubi9/ubi-minimal:latest-hardened1 → 02026-09-27

Questions

Hardened image vs distroless?
Distroless means rebuilding your application on a new base. A hardened image keeps your image and removes what it does not use, so nothing about your build changes.
Will it break my image?
Every hardened image is started and tested next to the original before it is published.
Is it free?
Yes, online and free, with no sign-up.
Can I combine it with FIPS?
Yes: hardened + FIPS images are built in one step.

Also on OCImend

CVE-free images · FIPS-enabled images · Free online CVE fix · Image CVE reports · Guides · For platform teams

Harden my image →