Ocimend

Fixed images, ready to pull

Every image here was rebuilt from the original by Ocimend: the fixable vulnerabilities patched with the image's own package manager (-fixed) or FIPS mode enforced with a validated OpenSSL provider (-fips). Each one was rescanned, started side by side with the original and, for FIPS, tested live. The application, entrypoint and settings are unchanged.

1. Pointat any public image in the scanner
2. Scanevery CVE, what the app really loads, FIPS status
3. Fixpatched or FIPS image, rebuilt and re-tested
4. Pullocimend.io/name:tag-fixed

Published images are rebuilt from public sources only; images scanned with credentials are never published. FIPS images: OpenSSL FIPS Provider 3.1.2 (CMVP certificate #4985) built from the unmodified upstream source, or the image's own validated provider. A FIPS 140-3 module inside an image is evidence for your assessor, not a certification of your system.