Pick a runtime image.
Use the matrix to compare runtime, tier, release state, service images, and attached evidence before you containerize or admit an application.
CVE counts on the catalog are refreshed nightly against current vulnerability advisories, so a stable SBOM picks up newly-disclosed issues without a new release. Each image page explains fix state and evidence. Dev images include full toolchains and must not be deployed.
Evidence & Policy Legend
Supply Chain Evidence
Green icons indicate evidence present in the catalog for the OCI manifest: Sigstore keyless OIDC signature, SLSA Build L3 provenance, and SPDX SBOM. Use the audit guide to verify it locally.
The generated evidence-manifest.json indexes each release's expected, observed, and missing evidence channels.
No high/critical in current scan Current Scan Results
Images show No high/critical in current scan when attached scan data reports no active Critical or High findings. Counts of outstanding CVE findings display in red (critical) or orange (high) badges.
SHELL-FREE EVIDENCE LISTED
Shell-Free indicates that shells, core utilities, and package managers are omitted from the runtime. Evidence Listed means the catalog exposes signatures, SBOMs, provenance, and workflow identities separately.
Core
1 version / 3/3 current
LTS
Core
1 version / 3/3 current
Distroless
zero shells · hardened runtime
Slim
runtime + minimal tooling
Dev
build-time · do not deploy
Java
2 versions / 3/3 current
25
Java
2 versions / 3/3 current
Distroless
zero shells · hardened runtime
Slim
runtime + minimal tooling
Dev
build-time · do not deploy
Node.js
2 versions / 3/3 current
24
Node.js
2 versions / 3/3 current
Distroless
zero shells · hardened runtime
Slim
runtime + minimal tooling
Dev
build-time · do not deploy
Python
2 versions / 3/3 current
3.14
Python
2 versions / 3/3 current
Distroless
zero shells · hardened runtime
Slim
runtime + minimal tooling
Dev
build-time · do not deploy
Go
2 versions / 3/3 current
1.26
Go
2 versions / 3/3 current
Distroless
zero shells · hardened runtime
Slim
runtime + minimal tooling
Dev
build-time · do not deploy
.NET
2 versions / 3/3 current
10
.NET
2 versions / 3/3 current
Distroless
zero shells · hardened runtime
Slim
runtime + minimal tooling
Dev
build-time · do not deploy
Rust
1 version / 3/3 current
1.95
Rust
1 version / 3/3 current
Distroless
zero shells · hardened runtime
Slim
runtime + minimal tooling
Dev
build-time · do not deploy
C/C++
1 version / 3/3 current
15
C/C++
1 version / 3/3 current
Distroless
zero shells · hardened runtime
Slim
runtime + minimal tooling
Dev
build-time · do not deploy
Service Images
Platform-owned application services built from Nix package templates, cataloged separately from runtime tiers.