// OSSeva Blog
MigrationChainguard vs Docker Hardened Images vs Bitnami Secure Images: Which Covers EOL Versions?
The short answer
Of the three, only Docker Hardened Images publishes a way to keep patching a version after upstream end of life: Extended Lifecycle Support, a paid add-on to the Enterprise tier, for up to five years. Chainguard builds upstream-supported versions only; when one reaches end of life, its grace period keeps the image rebuilt for up to six months, but it does not patch or backport fixes into the end-of-life software itself. Bitnami Secure Images sells long-term support branches, but Broadcom publishes no policy for application versions past upstream end of life.
So for current versions, choose on catalogue, layout and SLA. For a version that is already past end of life, such as PostgreSQL 13, RabbitMQ 3.13 or Kafka 3.x on ZooKeeper, the realistic sources are Docker's ELS, if your image is in it, or a vendor that backports fixes into that version, such as OSSeva's Bitnami-compatible images.
Side by side
Each row reflects what the vendor publishes on its own site and documentation, checked on 6 October 2026.
| Chainguard | Docker Hardened Images | Bitnami Secure Images | |
|---|---|---|---|
| Versions built | Upstream-supported versions only; for projects with several supported tracks, such as PostgreSQL, every track that still receives updates | Supported versions in the standard catalogue; end-of-life versions with the ELS add-on | Current versions; stable tags and long-term support versions with a subscription |
| After upstream end of life | EOL Grace Period of up to six months: other packages in the image are updated, the end-of-life package is not, and no backports are made. Afterwards the image is no longer rebuilt. | Extended Lifecycle Support: up to five years of hardened updates past upstream end of life | No published policy for application versions. Operating system versions are removed when their support ends. |
| Free tier | A free tier exists; check the pricing page for what it currently includes | Community tier free under Apache 2.0 since 17 December 2025 | A portion of the catalogue for non-production use, on latest tags only |
| Paid tiers | Per image or whole catalogue | Select and Enterprise; ELS as an add-on that requires Enterprise | Commercial subscription, by quote |
| Published CVE remediation | Contractual: 7 days for critical, 14 days for high, medium and low | Signed SLA: critical and high within 7 calendar days, medium and low within 30; ELS images critical and high within 14, medium and low within 45 | Critical and high within 2 business days of a verified upstream fix; medium and low within 30 business days |
| Image layout | Chainguard's own; iamguarded charts forked from Bitnami's for the latest versions | Docker's own, on Alpine or Debian | Bitnami's, so the Bitnami Helm charts work |
One detail in the SLA row is easy to get wrong. Docker's product page leads with critical fixes in under seven days, but its signed service level agreement puts critical and high in the same seven-day bracket. Broadcom's figure is measured from when a verified, stable fix is released upstream, so it says nothing about a version upstream no longer fixes.
What happens when a version reaches end of life
Chainguard
Chainguard's lifecycle documentation says the images it supports are those whose upstream software is still maintained. When a version reaches end of life, eligible images enter the EOL Grace Period for up to six months, with no exceptions to that limit. During it, Chainguard updates the non-end-of-life packages in the image and fixes their vulnerabilities, but it does not update the image's primary package or backport patches into it. A build failure ends the grace period early. After that, images you bought stay available but are not rebuilt and, in Chainguard's words, start to accrue CVEs. Eligibility depends in part on the release and end-of-life dates being listed on endoflife.date. Our OSSeva vs Chainguard comparison goes further on catalogue and supply-chain evidence.
Docker Hardened Images
Docker made the core Hardened Images catalogue free and open source under Apache 2.0 on 17 December 2025. End-of-life versions are a paid extra: with the Extended Lifecycle Support add-on, which requires DHI Enterprise, you enable end-of-life versions when you set up mirroring, and Docker builds and maintains an ELS image for up to five years past upstream end of life. Critical and high CVEs in ELS images fall under a 14-day SLA. Docker's documentation does not say what happens to a non-ELS tag once its version reaches end of life, so ask before relying on an old tag staying patched.
Bitnami Secure Images
Bitnami Secure Images is Broadcom's paid successor to the free catalogue. It keeps the Bitnami layout, and Broadcom says the images work with the same Helm charts. The subscription includes the full catalogue of more than 350 container images and 140 Helm charts, stable tags and long-term support versions, and Broadcom publishes the remediation timelines in the table above. What it does not publish is a policy for an application version, such as PostgreSQL 14 or RabbitMQ 3.13, after upstream end of life. If that matters to you, get the list of covered versions and their end dates in writing. Bitnami Secure Images explained covers licensing and the buying process, and OSSeva vs Bitnami Secure Images compares coverage.
Where patched end-of-life images come from
Hardened catalogues are built around a simple rule: stay on supported versions and roll forward to new digests. That works until an application is certified on one database version, a Kafka cluster still depends on ZooKeeper, or an upgrade programme runs for several quarters. Then you have three options:
- Upgrade to a version the catalogue supports. Usually the right long-term answer, and the one all three vendors are built for.
- Docker's ELS, if your images are in it and you are on, or willing to buy, DHI Enterprise. You also adopt Docker's image layout, so Bitnami charts need changes.
- A vendor that backports fixes into the end-of-life version. OSSeva patches the software inside the image, not only the base layer: PostgreSQL 11 to 14, Redis 6.x and 7.2, Kafka 2.8 to 3.9 including ZooKeeper-mode clusters, ZooKeeper 3.5 to 3.8, RabbitMQ 3.8 to 3.13 with a patched Erlang/OTP runtime, MongoDB 4.2 to 6.0, and Elasticsearch 7.10.2 and 7.17. The images keep Bitnami's variables,
/bitnamidata paths and non-root user, so existing charts work after a registry change.
The trade-off runs the other way on breadth. Chainguard and Docker each offer catalogues of a thousand images or more, and Bitnami Secure Images more than 350; OSSeva covers seven data and messaging image families. Many teams use a hardened catalogue for current versions and a separate source for the few end-of-life systems they cannot move yet.
Which to choose
| Your situation | Usual fit |
|---|---|
| Current versions, want minimal images and a contractual SLA across many languages | Chainguard or Docker Hardened Images |
| Current versions, free, open source images with SBOMs and provenance | Docker Hardened Images, Community tier |
| Dozens of Bitnami charts on current versions, want to keep the charts | Bitnami Secure Images |
| Versions past end of life, willing to adopt a new image layout, and the image is in Docker's ELS | Docker Hardened Images Enterprise with ELS |
| Bitnami charts pinned to end-of-life PostgreSQL, Redis, Kafka, ZooKeeper, RabbitMQ, MongoDB or Elasticsearch | OSSeva drop-in images |
If your pods are failing to pull right now, start with fixing ImagePullBackOff after the Bitnami change. For the full field of replacements, see Bitnami alternatives compared.
Frequently asked questions
Chainguard vs Docker Hardened Images vs Bitnami: which is best for EOL versions?
Docker Hardened Images, if your image is covered by its paid Extended Lifecycle Support, which runs up to five years past upstream end of life and requires DHI Enterprise. Chainguard stops at six months and does not patch the end-of-life package. Broadcom publishes no end-of-life policy for application versions in Bitnami Secure Images. For Bitnami-style images of end-of-life PostgreSQL, Redis, Kafka, ZooKeeper, RabbitMQ, MongoDB or Elasticsearch, OSSeva backports fixes into those versions.
What is the best Bitnami alternative in 2026?
It depends on the versions you run. For current versions with the Bitnami charts unchanged, Bitnami Secure Images. For current versions with new charts or operators, Docker Hardened Images, Chainguard, or the official images. For pinned end-of-life versions with the charts unchanged, Bitnami-compatible patched images such as OSSeva's.
Are Bitnami images still free?
Partly. A portion of Bitnami Secure Images is free for non-production use on latest tags only. Versioned images are part of the paid subscription, and the free bitnamilegacy copies receive no updates.
Are Docker Hardened Images free?
The Community tier is free under Apache 2.0 since 17 December 2025. The SLA-backed Select and Enterprise tiers, and Extended Lifecycle Support for end-of-life versions, are paid.
Does Chainguard patch end-of-life versions?
Not the end-of-life software itself. During the grace period of up to six months, Chainguard updates the other packages in the image; it does not update or backport fixes into the primary package, and after the grace period the image is no longer rebuilt.
What CVE SLAs do Chainguard, Docker and Bitnami publish?
Chainguard: 7 days for critical and 14 for other severities. Docker Hardened Images: critical and high within 7 calendar days, medium and low within 30, and 14 and 45 days for ELS images. Bitnami Secure Images: critical and high within 2 business days of a verified upstream fix, medium and low within 30 business days.
Tags
Related articles
Apache Storm Vulnerabilities by Version: CVEs for Storm 1.2, 2.x and 3.x
October 6, 2026Securityetcd Vulnerabilities by Version: CVEs for etcd 3.3, 3.4, 3.5, 3.6 and 3.7
October 6, 2026SecurityClickHouse Vulnerabilities by Version: CVEs for ClickHouse 22.x to 26.x, LTS and Stable
October 6, 2026Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.