Sign in

Minimus

@minimus.io
48 followers 5 following 141 posts

Secure, minimal container images with 97% fewer vulnerabilities.

PostsRepliesMedia
Minimus @minimus.io · 10/07/2026
Community Edition, done right. Browse and pull hardened, near-zero CVE container images from the full Minimus gallery, for free, no registration required: images.minimus.io
010
Minimus @minimus.io · 01/07/2026
Curious what your vulnerability counts, image sizes, or maintenance burden would look like with a different foundation? Minimus Community Edition lets you try hardened, minimal container images immediately - no contracts, approvals, or workflow changes required. images.minimus.io
images.minimus.io
Images & Charts - Minimus
Access the Minimus image library to browse and pull production-ready container images. New here? Create an account in seconds.
000
Minimus @minimus.io · 30/06/2026
328 CVEs ➡️ 0 CVEs. One line changed. Same Node. Same version. No code changes. Sometimes the easiest way to fix vulnerabilities is changing where you pull your image from.
000
Minimus @minimus.io · 29/06/2026
All of our hardened, near-zero CVE container images. No registration. No auth wall. No procurement process. Just pull and start building: images.minimus.io
000
Minimus @minimus.io · 26/06/2026
We like making developers happy with free surprises. First, it was a Mini Cooper at RSAC/KubeCon. Now, it’s the entire Minimus image gallery, open to everyone. images.minimus.io
000
Minimus @minimus.io · 26/06/2026
📸 Minimus team in NYC 📍 GBI CISO NYC 📍 PlatformCon NYC 📍 World Cup Screening with @edera.dev & @dash0.com Great day connecting with platform and security teams!
120
Minimus @minimus.io · 24/06/2026
The security industry doesn't need more ways to find vulnerabilities. AI is accelerating discovery, but remediation remains largely unchanged. The gap between the two keeps growing. That's why we believe secure foundations should be the default, not a premium feature:
minimus.io
010
Minimus @minimus.io · 23/06/2026
Today we're launching Minimus Community Edition: Hundreds of near-zero CVE, built-from-source container images are now available for free. No trial. No auth wall. No signup. Our entire gallery. Hardened, minimal, continuously maintained: buff.ly/xQhyMSV
020
Minimus @minimus.io · 20/06/2026
CIS, NIST, and FedRAMP are often discussed together, but they solve different problems at different layers of the security stack. Learn how the frameworks fit together, why containerized environments change the compliance equation, and what teams should prioritize for audits:
minimus.io
CIS, NIST, and FedRAMP in Containerized Environments - Minimus
Understand how CIS, NIST, and FedRAMP work together to secure containerized environments, reduce risk, and support compliance requirements.
000
Minimus @minimus.io · 19/06/2026
CISA's new BOD 26-04 marks a major shift in vulnerability management: prioritizing remediation based on real-world risk, not just CVSS scores. Learn about the new 3-day remediation timeline and what organizations need to do to operationalize SSVC-based prioritization:
minimus.io
Understanding CISA BOD 26-04 - Minimus
CISA BOD 26-04 shifts vulnerability management toward risk-based prioritization. Here's what changed and what it means in practice.
010
Minimus @minimus.io · 12/06/2026
Open source dependencies are one of the biggest software supply chain risks. Security teams need more than vulnerability data. They need ways to evaluate trust before packages enter their environments.
minimus.io
Minimus Supply Chain Protection - Minimus
Learn how Minimus Supply Chain Protection helps reduce open source dependency risk with policy-based package controls.
120
Minimus @minimus.io · 09/06/2026
We're honored to be named a 2026 Intellyx Digital Innovator Award winner. At Minimus, we're focused on helping organizations reduce container risk with secure, minimal images that fit into existing development workflows. Congratulations to the other innovators recognized: buff.ly/DXG5qJ2
000
Minimus @minimus.io · 06/06/2026
Most teams manage infrastructure and application code through Git-based workflows. Why should container images be any different? minicli lets you manage image recipes as YAML, version control them in Git, and integrate image management into existing CI/CD workflows.
minimus.io
Manage Custom Container Images as Code with MiniCLI - Minimus
Manage custom container images as code with minicli. Export YAML image recipes, version them in Git, automate builds, and integrate image management into CI/CD
100
Minimus @minimus.io · 05/06/2026
As AI makes vulnerability research faster and more scalable, security teams will need better ways to consume fixes, reduce attack surface, and keep pace with change. Check out the full webinar: buff.ly/ml7sBtf
000
Minimus @minimus.io · 31/05/2026
A lot of container security work is really just ongoing maintenance work. Minimus eliminates as much of that operational burden as possible, so teams spend less time building images, patching vulnerabilities, preparing for audits, and coordinating fixes. Learn more:
minimus.io
How Minimus Saves Time on Container Security and Compliance - Minimus
Reduce container security and compliance overhead with hardened Minimus images that automate patching, hardening, attestations, and updates.
010
Minimus @minimus.io · 30/05/2026
Platform teams spend a surprising amount of time managing container image maintenance instead of building infrastructure that moves the business forward. This blog breaks down 3 ways hardened images help platform teams save time across engineering, security, and compliance:
minimus.io
3 Ways Hardened Container Images Save Platform Teams Time - Minimus
Managing container images is time-consuming and repetitive. Minimal, hardened images reduce vulnerabilities and free teams to focus on higher-value work.
000
Minimus @minimus.io · 29/05/2026
The EU Cyber Resilience Act has a detail that catches a lot of teams off guard: scope is determined by where your customers are. If EU customers download or deploy your software, you're in scope. Learn more: buff.ly/gFnddzw #CyberResilience #ContainerSecurity #CRA #DevSecOps #SoftwareSupplyChain
buff.ly
EU Cyber Resilience Act for Container Teams - Minimus
The EU Cyber Resilience Act applies to any company shipping software to EU customers. See how Minimus container images map to CRA requirements.
000
Minimus @minimus.io · 23/05/2026
What security controls should every organization have in place for their containerized environments? Keep watching: buff.ly/kP1USUo
010
Minimus @minimus.io · 22/05/2026
The best metrics for your container security program depend on why you're moving into a containerized workload environment. Watch the full video here, where we break down how to plan and run a container security program: buff.ly/jmREXYL
011
Minimus @minimus.io · 20/05/2026
What happens when AI can autonomously chain zero-days across major operating systems and browsers? Join us for a technical discussion on what Anthropic’s Claude Mythos preview means for defenders, attackers, and the future of application security. 🎟️ Save your spot: buff.ly/srlUQA7
000
Minimus @minimus.io · 13/05/2026
Historically, some vulnerabilities were so difficult to find that only nation-state level attackers could realistically exploit them. John Morello and Bruce Schneier discuss whether AI could fundamentally change that and how we can defend against it. Watch the full video: buff.ly/Ckn237P
000
Reposted by Minimus
Edera @edera.dev · 11/05/2026
Good sessions end at 5. Good conferences don't. 😉 Edera + @minimus.io are hosting Sprout & Sip at Minneapolis' Flora Room, May 19, 6:30 PM. Drinks, bites, real conversations. Space is limited. edera.link/sprout-sip
edera.link
Sprout & Sip Happy Hour
Edera and Minimus are throwing open the doors at Minneapolis' iconic Flora Room for an evening of drinks, bites, and the kind of conversations that matter.
021
Minimus @minimus.io · 11/05/2026
When will AI's ability to fix vulnerabilities catch up to its ability to find vulnerabilities? Chenxi Wang and John Morello talk about the limits of AI when it comes to fixing vulnerabilities. Watch the full video: buff.ly/kDV6XW4
000
Minimus @minimus.io · 10/05/2026
Containers are not a security boundary by definition. In this clip, Neil Carpenter breaks down the differences between containers and virtual machines and why configuration management matters in containerized environments. Watch the full video: youtu.be/CDy-QEeJJic?...
000
Minimus @minimus.io · 09/05/2026
Public images often take months, or even years, to remediate known vulnerabilities. Minimus images reduce that window to days, helping teams spend less time patching & more time shipping secure software. Learn how MTTR impacts container security and why faster remediation matters:
minimus.io
Using Mean Time to Remediation to Evaluate Image Security - Minimus
Learn how MTTR impacts container security and why Minimus images dramatically reduce remediation time compared to public images.
000
Minimus @minimus.io · 08/05/2026
Good drinks, better company. We're co-hosting Sprout & Sip with our friends at Edera on May 19 in Minneapolis. Join us at the Flora Room for an evening of cocktails and open source convos. 🌸 Register: buff.ly/1nlIfi5 #OpenSourceSummitNA #OpenSource
luma.com
Sprout & Sip Happy Hour · Luma
The best ideas grow in good company. Edera and Minimus are throwing open the doors at Minneapolis' iconic Flora Room for an evening of drinks, bites, and the…
010
Minimus @minimus.io · 07/05/2026
Your scanner flagged 847 vulnerabilities. Now what? Most teams are drowning in vulnerability reports, but few understand how those findings are actually generated. Join us on May 14 to learn how container scanners work, how to read CVE bulletins, and how to validate results. :
platformengineering.org
How to watch the watcher: Investigating vulnerability scanner reports 101
While teams are overwhelmed by vulnerability assessments, they rarely understand how popular vulnerability scanners arrive at these determinations.  Using popular container scanning tools for…
000
Minimus @minimus.io · 01/05/2026
John Morello and Bruce Schneier sat down last week to talk about AI, the rise of "instant software", and how tools like Claude Mythos are changing vulnerability discovery. Watch the full video: buff.ly/zzqvIMX Read Bruce’s original essay that inspired this conversation: buff.ly/O0NOGkh
000
Minimus @minimus.io · 28/04/2026
In a post-Mythos era, AI can now chain exploits in hours rather than weeks. You can’t keep up by patching. The only scalable answer is to start with without. ZERO IS A HERO. buff.ly/JckEQz9
minimus.io
000
Minimus @minimus.io · 25/04/2026
Minimus images are OCI compliant, built from upstream source, drop-in replacements for the container images you're using today - with 97% fewer CVEs, out of the box. Watch the full video: buff.ly/6Hd6RRh
000
Minimus @minimus.io · 24/04/2026
People always ask about our 98% CVE reduction number. Here's how we actually do it. Full video: buff.ly/rcjPPY3
000
Minimus @minimus.io · 21/04/2026
AI is accelerating vulnerability discovery, but the real problem hasn’t changed: volume. Neil breaks down the reality behind AI-driven vulnerability discovery and what defenders should do when they can't patch everything: buff.ly/vdbuGCq @neilcar.bsky.social
010
Minimus @minimus.io · 18/04/2026
Building a CIS compliant container image isn’t the hard part. Maintaining compliance across container environments as dependencies grow, base images change, and new CVEs emerge is where most teams struggle. Here's what continuous CIS hardening looks like, and how Minimus helps: buff.ly/BPWXGM1
minimus.io
Implementing CIS Hardening Across Container Pipelines - Minimus
Learn how to scale CIS hardening with automation, SBOMs, and minimal images across container environments.
000
Minimus @minimus.io · 18/04/2026
John Morello explains how Minimus works with Merge Ready. Swap your base image, drop your CVE count - it's as simple as that. Full video: buff.ly/fSH3aW1
000
Minimus @minimus.io · 17/04/2026
Open source powers everything, and securing it is a shared responsibility. Kat Cosgrove talks about why giving back isn’t optional, and how we’re doing our part with free access to Minimus hardened images for eligible projects: buff.ly/FJv0Y2M Watch the full video: buff.ly/bux07Dt @kat.lol
030
Minimus @minimus.io · 11/04/2026
A lot of security gaps come down to lack of visibility. The Minimus Activity Log gives teams a clear audit trail of platform access, token changes, and custom image activity, making it easier to investigate issues, maintain accountability, and stay ahead of risk:
minimus.io
Activity Log: Operational Visibility for Hardened Images - Minimus
Monitor platform access, token changes, and custom image activity with the Minimus Activity Log. Built-in visibility and auditability for hardened images.
020
Minimus @minimus.io · 10/04/2026
We break down container runtimes, static vs. dynamic binaries, and how to avoid runtime failures before they hit production:
minimus.io
Understanding Container Runtimes - Minimus
Learn how container runtimes work, why static vs dynamic binaries matter, and how runtime isolation affects container security and reliability.
000
Minimus @minimus.io · 03/04/2026
A lot's happened since trivy v0.69.4 last week: 🗓️ Mar 22: malicious v0.69.5 + v0.69.6 pushed to docker hub 🗓️ Mar 22: teamPCP defaced all 44 repos in aqua's github org 🗓️ Mar 23: Checkmarx KICS GitHub Actions and few OpenVSXPlugins were affected 🗓️ Mar 24: LiteLLM compromised on PyPI 👇
minimus.io
Trivy Supply Chain Attack - What You Need To Know - Minimus
Trivy v0.69.4 supply chain attack explained. Learn what happened, how to tell if you're impacted, and what steps to take to protect your data.
110
Minimus @minimus.io · 31/03/2026
Most teams don't know what's actually in their container images. Minimus shows you how many packages are in your image and what vulnerabilities they're carrying. 📦️ public node image = 500+ packages. 📦️ Minimus node = 15. = 97% package reduction, 100% fewer CVEs. Full breakdown: buff.ly/sEVwkny
020
Minimus @minimus.io · 27/03/2026
One week. Two events. A lot of great conversations. Thanks to everyone who stopped by, said hi, and took a shot at the dart board 🎯 We’ll see you at the next one! #Minimus #KubeConEU #RSAC
110
Minimus @minimus.io · 26/03/2026
📸 Tiny prints, big week. That's a wrap on KubeCon EU - we had a great time! If you’re at RSAC, today’s your last chance to come by booth # S-1061. The Mini Cooper is still up for grabs! Stop by to beat our current DART high score 🎯🚗 #RSAC #RSAC2026
010
Minimus @minimus.io · 25/03/2026
We actually can be in two places at once… Can you guess which is our RSAC booth and which is our KubeCon booth? If you’re at either event, come find us: 📍 RSAC: Booth # S-1061 📍 KubeCon: Booth # 940 + 🎯 Space # 340 #KubeConEU #RSAC #ContainerSecurity #Cybersecurity
000
Minimus @minimus.io · 24/03/2026
Step 1: Focus 🎯 Step 2: Trust yourself Step 3: Win a Mini Cooper 🚗 The previous competition winner makes it look easy. Catch us at KubeCon EU booth # 340 + RSAC # S-1061 to take your shot. #KubeConEU #RSAC #Minimus
011
Minimus @minimus.io · 24/03/2026
Minimus has two booths at #KubeCon - Come say hi! 📍 Booth # 940 - Hang out and talk container security and minimal, hardened images. 🎯 Activation Zone # 340 - Play our DART Challenge: Winner takes home a brand new car!
010
Reposted by Minimus
kat cosgrove @kat.lol · 24/03/2026
If you are at Kubecon and think farts are funny, I have a VERY limited number of @minimus.io whoopie cushions available!
A photo of a small pink whoopie cushion with the Minimus logo on it in black, resting in my hand.
3545
Minimus @minimus.io · 24/03/2026
If you maintain an open source project, we want to support you. We’re excited to launch our Open Source Program, providing access to our secure, minimal images free of charge to eligible projects. Apply or get more information here: buff.ly/dbV6OQm #OpenSource #ContainerSecurity @kat.lol
0184
Minimus @minimus.io · 23/03/2026
Had a great time at Open Source Security Con today! Come see us tomorrow at KubeCon - Booth # 940
021
Minimus @minimus.io · 23/03/2026
It’s a big week for Minimus! We won 3 Global InfoSec Awards 🏆 🏅 Market Leader: Container Security 🏅 Market Disruptor: Cybersecurity Startup 🏅 Editor’s Choice: Software Supply Chain Security We’re grateful for the recognition and for the teams building with us!
030
Minimus @minimus.io · 23/03/2026
Using Trivy? v0.69.4 was compromised in a supply chain attack. We break down what happened and what to do if you’re affected: buff.ly/3Pr1qjF
minimus.io
Trivy Supply Chain Attack - What You Need To Know - Minimus
Trivy v0.69.4 supply chain attack explained. Learn what happened, how to tell if you're impacted, and what steps to take to protect your data.
010
Minimus @minimus.io · 20/03/2026
Another event, another Mini Cooper giveaway! That's right - we're bringing the Minimus DART Challenge to KubeCon AND RSAC next week, and someone's leaving with a car! Come see us at RSAC booth S-1061 / KubeCon booth 940 🎯 🚙 #KubeCon #RSAC #Cybersecurity #ContainerSecurity #CloudSecurity
000