Chainguard Registry

The trusted source for open source

Also known as
chainguard-registry

What is Chainguard Registry?

Hardened, secure-by-design container images, language libraries, and VM images built from source with CVE remediation SLAs and AI attack prevention. Includes 2,500+ projects and 520K+ images.

Independently observed

Chainguard Registry pricing

Plans, per-tier features and add-ons, dated and linked to live pricing. Pricing changes often; always verify at source before you rely on it.

Pricing as of verify at live pricing ↗Independently observed
HybridFree tier

Free tier with 5 images, or subscription from $19K/year for full catalog access

Free Images

Free
Free

Up to five container images per organization for testing and production deployment

images
5 per organization
  • Five images of choice, including previous versions
  • Continuously built from source in SLSA L3 hardened infrastructure
  • Sigstore signed artifacts with full build-time SBOMs and digital attestations
  • Unlimited pulls with no metering

Per Image

Contact sales
Contact sales

Licensed by number and type of images (base, application, AI/ML, FIPS)

  • Scoped production deployments per image
  • Contractual CVE SLA (7 days critical, 14 days high/medium/low)
  • All upstream supported versions including major/minor tags
  • STIG-hardened and FIPS-validated images available
  • Custom Assembly tooling and access to 10K+ packages
  • EOL Grace Period updates for up to 6 months
  • Console-based user management

Catalog

Contact sales
Contact sales

Licensed by engineering organization size with full access to complete image catalog

  • Full access to 2,000+ images and growing
  • Contractual CVE SLA
  • Ability to request net new images at no additional cost
  • All upstream supported versions
  • Continuous updates from source in SLSA L3 hardened infrastructure
  • Console to manage images, entitlements, and pull tokens

What Chainguard Registry does

The capabilities that matter for container registries, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.

Deployment
Hosting
Cloud only
Standards
OCI Distribution Spec compliant
-
Scope
Artifact types
Container images only
Security
Built-in vulnerability scanning
Image signing (Cosign/Notation)
SBOM generation / storage
Access
Fine-grained RBAC / robot accounts
Private repositories
-
Distribution
Geo-replication / mirroring
-
Pull-through cache / proxy
-
Integration
Native cloud IAM integration
-
Pricing
Pull-rate limits
None
UX
Web UI / console
Ops
High-availability deployment
-
Independently observed

Platform & deployment

Independently observed
Platforms
  • Web
Deployment
  • Cloud / SaaS

Chainguard Registry alternatives

Other container registries we track, ranked by the same independent score.

Independent · unbought · dated

The Vioscale score: one lens on the evidence

Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for Chainguard Registry, not the verdict.

Balanced composite 63 / 100
medium · 50%
Signal contributions to the composite score
SignalScoreWeightContributionEvidence
Security Posture5526.001430.0
Capabilities7514.001046.1
Pricing Transparency806.00480.0
Reliability508.00400.0
Price Level804.00320.0
Integrations08.000.0-

Computed . Re-weight it by intent, or see the full method.

All data & sourcesshow ↓

Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.

Features

AttributeValueEvidence
Capabilities{"rbac":true,"web_ui":true,"hosting":"cloud","sbom_support":true,"image_signing":true,"artifact_types":"images","pull_rate_limits":"none","vulnerability_scanning":true}mediumsource · 2026-08-03 · 60%

Pricing

AttributeValueEvidence
Free tierYesmediumsource · 2026-08-03 · 60%
Modelcommercialmediumsource · 2026-08-03 · 60%
Price levellowmediumsource · 2026-08-03 · 60%
TransparentYesmediumsource · 2026-08-03 · 60%

Reliability

AttributeValueEvidence
Status pageYesmediumsource · 2026-08-03 · 60%

Security

AttributeValueEvidence
FedrampYeshighsource · 2026-08-03 · 75%
PciYeshighsource · 2026-08-03 · 75%
Soc2Yeslowsource · 2026-08-03 · 48%