Chainguard's Factory 2.0 and DriftlessAF rebuild images from source on upstream changes. They produce 2,000+ minimal zero‑CVE images. Each image includes an SBOM and a cryptographic signature.
Docker's DHI builds on Debian and Alpine. It mirrors Debian's no‑DSA triage into VEX. It also suppresses real CVEs until Debian patches and rebuilds.










