Container CVE comparison
- Scan started: 2026-09-11T01:25:07Z
- Scanner: Grype 0.109.1 (SBOMs from Syft 1.18.1)
- Platform: linux/amd64
- Tags resolved to immutable digests before scanning
- Counts are raw Grype matches; vendor VEX is not applied
Version-matched head-to-head#
| Competitor | Match | Pairs | Minimal unique | Competitor unique | Minimal lower | Tie | Minimal higher |
|---|---|---|---|---|---|---|---|
| minimus | exact | 74 | 158 | 378 | 44 | 25 | 5 |
| minimus | minor | 2 | 2 | 6 | 2 | 0 | 0 |
| chainguard | exact | 13 | 23 | 26 | 3 | 8 | 2 |
| chainguard | minor | 2 | 2 | 3 | 1 | 1 | 0 |
Pairs excluded from the score#
| Competitor | Version mismatch | Version unknown |
|---|---|---|
| minimus | 8 | 8 |
| chainguard | 3 | 2 |
Coverage and aggregate raw findings#
| Provider | Scanned | Unavailable | Failed | Matches | Unique CVEs* | Critical | High |
|---|---|---|---|---|---|---|---|
| minimal | 112 | 0 | 0 | 511 | 406 | 13 | 109 |
| minimus | 92 | 20 | 0 | 593 | 500 | 18 | 261 |
| chainguard | 20 | 92 | 0 | 36 | 35 | 0 | 5 |
* Unique CVEs are summed per image; the same CVE appearing in two images is counted twice.
Counts exclude apk findings that only match a self-built package's name in the
distro advisory feed, with the fix being a same-upstream-version rebuild and no
corroboration in the image contents (.github/scripts/reconcile-apk-provenance.sh,
the same rule the image dashboard uses). Per-image excluded counts are in the
apk_provenance_excluded column of results-long.csv; nothing is deleted.
Detailed machine-readable results: results-long.csv (per image/provider) and
results-pairs.csv (per head-to-head pair, with version match classification).