Back to blog

// OSSeva Blog

Migration

Chainguard vs Docker Hardened Images vs Bitnami Secure Images: Which Covers EOL Versions?

Matt Reynolds9 min read

The short answer

Of the three, only Docker Hardened Images publishes a way to keep patching a version after upstream end of life: Extended Lifecycle Support, a paid add-on to the Enterprise tier, for up to five years. Chainguard builds upstream-supported versions only; when one reaches end of life, its grace period keeps the image rebuilt for up to six months, but it does not patch or backport fixes into the end-of-life software itself. Bitnami Secure Images sells long-term support branches, but Broadcom publishes no policy for application versions past upstream end of life.

So for current versions, choose on catalogue, layout and SLA. For a version that is already past end of life, such as PostgreSQL 13, RabbitMQ 3.13 or Kafka 3.x on ZooKeeper, the realistic sources are Docker's ELS, if your image is in it, or a vendor that backports fixes into that version, such as OSSeva's Bitnami-compatible images.

Side by side

Each row reflects what the vendor publishes on its own site and documentation, checked on 6 October 2026.

ChainguardDocker Hardened ImagesBitnami Secure Images
Versions builtUpstream-supported versions only; for projects with several supported tracks, such as PostgreSQL, every track that still receives updatesSupported versions in the standard catalogue; end-of-life versions with the ELS add-onCurrent versions; stable tags and long-term support versions with a subscription
After upstream end of lifeEOL Grace Period of up to six months: other packages in the image are updated, the end-of-life package is not, and no backports are made. Afterwards the image is no longer rebuilt.Extended Lifecycle Support: up to five years of hardened updates past upstream end of lifeNo published policy for application versions. Operating system versions are removed when their support ends.
Free tierA free tier exists; check the pricing page for what it currently includesCommunity tier free under Apache 2.0 since 17 December 2025A portion of the catalogue for non-production use, on latest tags only
Paid tiersPer image or whole catalogueSelect and Enterprise; ELS as an add-on that requires EnterpriseCommercial subscription, by quote
Published CVE remediationContractual: 7 days for critical, 14 days for high, medium and lowSigned SLA: critical and high within 7 calendar days, medium and low within 30; ELS images critical and high within 14, medium and low within 45Critical and high within 2 business days of a verified upstream fix; medium and low within 30 business days
Image layoutChainguard's own; iamguarded charts forked from Bitnami's for the latest versionsDocker's own, on Alpine or DebianBitnami's, so the Bitnami Helm charts work

One detail in the SLA row is easy to get wrong. Docker's product page leads with critical fixes in under seven days, but its signed service level agreement puts critical and high in the same seven-day bracket. Broadcom's figure is measured from when a verified, stable fix is released upstream, so it says nothing about a version upstream no longer fixes.

What happens when a version reaches end of life

Chainguard

Chainguard's lifecycle documentation says the images it supports are those whose upstream software is still maintained. When a version reaches end of life, eligible images enter the EOL Grace Period for up to six months, with no exceptions to that limit. During it, Chainguard updates the non-end-of-life packages in the image and fixes their vulnerabilities, but it does not update the image's primary package or backport patches into it. A build failure ends the grace period early. After that, images you bought stay available but are not rebuilt and, in Chainguard's words, start to accrue CVEs. Eligibility depends in part on the release and end-of-life dates being listed on endoflife.date. Our OSSeva vs Chainguard comparison goes further on catalogue and supply-chain evidence.

Docker Hardened Images

Docker made the core Hardened Images catalogue free and open source under Apache 2.0 on 17 December 2025. End-of-life versions are a paid extra: with the Extended Lifecycle Support add-on, which requires DHI Enterprise, you enable end-of-life versions when you set up mirroring, and Docker builds and maintains an ELS image for up to five years past upstream end of life. Critical and high CVEs in ELS images fall under a 14-day SLA. Docker's documentation does not say what happens to a non-ELS tag once its version reaches end of life, so ask before relying on an old tag staying patched.

Bitnami Secure Images

Bitnami Secure Images is Broadcom's paid successor to the free catalogue. It keeps the Bitnami layout, and Broadcom says the images work with the same Helm charts. The subscription includes the full catalogue of more than 350 container images and 140 Helm charts, stable tags and long-term support versions, and Broadcom publishes the remediation timelines in the table above. What it does not publish is a policy for an application version, such as PostgreSQL 14 or RabbitMQ 3.13, after upstream end of life. If that matters to you, get the list of covered versions and their end dates in writing. Bitnami Secure Images explained covers licensing and the buying process, and OSSeva vs Bitnami Secure Images compares coverage.

Where patched end-of-life images come from

Hardened catalogues are built around a simple rule: stay on supported versions and roll forward to new digests. That works until an application is certified on one database version, a Kafka cluster still depends on ZooKeeper, or an upgrade programme runs for several quarters. Then you have three options:

  1. Upgrade to a version the catalogue supports. Usually the right long-term answer, and the one all three vendors are built for.
  2. Docker's ELS, if your images are in it and you are on, or willing to buy, DHI Enterprise. You also adopt Docker's image layout, so Bitnami charts need changes.
  3. A vendor that backports fixes into the end-of-life version. OSSeva patches the software inside the image, not only the base layer: PostgreSQL 11 to 14, Redis 6.x and 7.2, Kafka 2.8 to 3.9 including ZooKeeper-mode clusters, ZooKeeper 3.5 to 3.8, RabbitMQ 3.8 to 3.13 with a patched Erlang/OTP runtime, MongoDB 4.2 to 6.0, and Elasticsearch 7.10.2 and 7.17. The images keep Bitnami's variables, /bitnami data paths and non-root user, so existing charts work after a registry change.

The trade-off runs the other way on breadth. Chainguard and Docker each offer catalogues of a thousand images or more, and Bitnami Secure Images more than 350; OSSeva covers seven data and messaging image families. Many teams use a hardened catalogue for current versions and a separate source for the few end-of-life systems they cannot move yet.

Which to choose

Your situationUsual fit
Current versions, want minimal images and a contractual SLA across many languagesChainguard or Docker Hardened Images
Current versions, free, open source images with SBOMs and provenanceDocker Hardened Images, Community tier
Dozens of Bitnami charts on current versions, want to keep the chartsBitnami Secure Images
Versions past end of life, willing to adopt a new image layout, and the image is in Docker's ELSDocker Hardened Images Enterprise with ELS
Bitnami charts pinned to end-of-life PostgreSQL, Redis, Kafka, ZooKeeper, RabbitMQ, MongoDB or ElasticsearchOSSeva drop-in images

If your pods are failing to pull right now, start with fixing ImagePullBackOff after the Bitnami change. For the full field of replacements, see Bitnami alternatives compared.

Frequently asked questions

Chainguard vs Docker Hardened Images vs Bitnami: which is best for EOL versions?

Docker Hardened Images, if your image is covered by its paid Extended Lifecycle Support, which runs up to five years past upstream end of life and requires DHI Enterprise. Chainguard stops at six months and does not patch the end-of-life package. Broadcom publishes no end-of-life policy for application versions in Bitnami Secure Images. For Bitnami-style images of end-of-life PostgreSQL, Redis, Kafka, ZooKeeper, RabbitMQ, MongoDB or Elasticsearch, OSSeva backports fixes into those versions.

What is the best Bitnami alternative in 2026?

It depends on the versions you run. For current versions with the Bitnami charts unchanged, Bitnami Secure Images. For current versions with new charts or operators, Docker Hardened Images, Chainguard, or the official images. For pinned end-of-life versions with the charts unchanged, Bitnami-compatible patched images such as OSSeva's.

Are Bitnami images still free?

Partly. A portion of Bitnami Secure Images is free for non-production use on latest tags only. Versioned images are part of the paid subscription, and the free bitnamilegacy copies receive no updates.

Are Docker Hardened Images free?

The Community tier is free under Apache 2.0 since 17 December 2025. The SLA-backed Select and Enterprise tiers, and Extended Lifecycle Support for end-of-life versions, are paid.

Does Chainguard patch end-of-life versions?

Not the end-of-life software itself. During the grace period of up to six months, Chainguard updates the other packages in the image; it does not update or backport fixes into the primary package, and after the grace period the image is no longer rebuilt.

What CVE SLAs do Chainguard, Docker and Bitnami publish?

Chainguard: 7 days for critical and 14 for other severities. Docker Hardened Images: critical and high within 7 calendar days, medium and low within 30, and 14 and 45 days for ELS images. Bitnami Secure Images: critical and high within 2 business days of a verified upstream fix, medium and low within 30 business days.

Tags

ChainguardDocker Hardened ImagesBitnami Secure ImagesContainer ImagesEnd of Life

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.