Docker Hardened Images Reach 500k Daily Pulls One Year After Launch
Docker reflects on the first year of its Docker Hardened Images (DHI) initiative, highlighting significant adoption milestones including over 500,000 daily pulls and a catalog exceeding 2,000 hardened artifacts. The company emphasizes its strategic decision to pursue a more complex engineering path that prioritizes ecosystem security and developer convenience over proprietary lock-in. Unlike competitors offering proprietary distroless operating systems, Docker hardens established distributions like Debian and Alpine, allowing teams to maintain existing workflows without costly migration efforts. By making DHI free and open-source under the Apache 2.0 license, Docker aims to raise the global security baseline for software supply chains. The platform continuously patches OS-level artifacts through a SLSA Build Level 3 pipeline, generating millions of builds regularly. This approach ensures independent verifiability via signed attestations while avoiding the vendor lock-in associated with unfamiliar proprietary OS migrations. The article underscores Docker's commitment to accessibility, arguing that security should not be a premium feature, and details how their multi-distro support reduces adoption friction for engineering teams already utilizing standard Linux distributions.
Wire timeline
Docker Hardened Images Reach 500k Daily Pulls One Year After Launch
Docker reflects on the first year of its Docker Hardened Images (DHI) initiative, highlighting significant adoption milestones including over 500,000 daily pulls and a catalog exceeding 2,000 hardened artifacts. The company emphasizes its strategic decision to pursue a more complex engineering path that prioritizes ecosystem security and developer convenience over proprietary lock-in. Unlike competitors offering proprietary distroless operating systems, Docker hardens established distributions like Debian and Alpine, allowing teams to maintain existing workflows without costly migration efforts. By making DHI free and open-source under the Apache 2.0 license, Docker aims to raise the global security baseline for software supply chains. The platform continuously patches OS-level artifacts through a SLSA Build Level 3 pipeline, generating millions of builds regularly. This approach ensures independent verifiability via signed attestations while avoiding the vendor lock-in associated with unfamiliar proprietary OS migrations. The article underscores Docker's commitment to accessibility, arguing that security should not be a premium feature, and details how their multi-distro support reduces adoption friction for engineering teams already utilizing standard Linux distributions.
Docker