Container CVE comparison

  • Scan started: 2026-09-11T01:25:07Z
  • Scanner: Grype 0.109.1 (SBOMs from Syft 1.18.1)
  • Platform: linux/amd64
  • Tags resolved to immutable digests before scanning
  • Counts are raw Grype matches; vendor VEX is not applied

Version-matched head-to-head#

Competitor Match Pairs Minimal unique Competitor unique Minimal lower Tie Minimal higher
minimus exact 74 158 378 44 25 5
minimus minor 2 2 6 2 0 0
chainguard exact 13 23 26 3 8 2
chainguard minor 2 2 3 1 1 0

Pairs excluded from the score#

Competitor Version mismatch Version unknown
minimus 8 8
chainguard 3 2

Coverage and aggregate raw findings#

Provider Scanned Unavailable Failed Matches Unique CVEs* Critical High
minimal 112 0 0 511 406 13 109
minimus 92 20 0 593 500 18 261
chainguard 20 92 0 36 35 0 5

* Unique CVEs are summed per image; the same CVE appearing in two images is counted twice.

Counts exclude apk findings that only match a self-built package's name in the distro advisory feed, with the fix being a same-upstream-version rebuild and no corroboration in the image contents (.github/scripts/reconcile-apk-provenance.sh, the same rule the image dashboard uses). Per-image excluded counts are in the apk_provenance_excluded column of results-long.csv; nothing is deleted.

Detailed machine-readable results: results-long.csv (per image/provider) and results-pairs.csv (per head-to-head pair, with version match classification).

Updated

Was this page helpful?