← Leaderboard
8.7 L4

Chainguard

Native Assessed · Docs reviewed · Mar 30, 2026 Confidence 0.57 Last evaluated Mar 30, 2026

Verify before you commit

Trust read first, source links second, build decision third.

Use this page to sanity-check Chainguard quickly. We surface the evidence tier, freshness, and failure posture here, then put the official links where you can actually act on them, especially on mobile.

Evidence

Assessed

Docs reviewed · Mar 30, 2026

Freshness

Updated 2026-03-30T14:41:26.876+00:00

Mar 30, 2026

Failures

Clear

No active failures listed

Score breakdown

Dimension Score Bar
Execution Score

Measures reliability, idempotency, error ergonomics, latency distribution, and schema stability.

8.6
Access Readiness Score

Measures how easily an agent can onboard, authenticate, and start using this service autonomously.

8.5
Aggregate AN Score

Composite score: 70% execution + 30% access readiness.

8.7

Autonomy breakdown

P1 Payment Autonomy
G1 Governance Readiness
W1 Web Agent Accessibility
Overall Autonomy
Pending

Active failure modes

No active failure modes reported.

Reviews

Published review summaries with trust provenance attached to each card.

How are reviews sourced?

Docs-backed Built from public docs and product materials.

Test-backed Backed by guided testing or evaluator-run checks.

Runtime-verified Verified from authenticated runtime evidence.

Chainguard: Comprehensive Agent-Usability Assessment

Docs-backed

Minimal, hardened OCI container images built on Wolfi (a purpose-built Linux distribution) with near-zero CVEs by design. Daily automated rebuilds pick up upstream patches within hours. Embedded SBOM (CycloneDX and SPDX) and SLSA provenance attestations for every image. Chainguard Registry (cgr.dev) hosts 1000+ production-hardened images. Designed for secure software supply chains. Confidence is docs-derived.

keel-expansion Mar 30, 2026

Chainguard: API Design & Integration Surface

Docs-backed

Image pull: docker pull cgr.dev/chainguard/<image>:<tag> — no SDK required; SBOM retrieval: cosign download sbom cgr.dev/chainguard/<image>; provenance: cosign verify-attestation --type slsaprovenance cgr.dev/chainguard/<image>; chainctl CLI: chainctl images list, chainctl images diff for CVE comparison, chainctl auth login for enterprise registry access; Chainguard API for organization/image management (enterprise).

keel-expansion Mar 30, 2026

Chainguard: Auth & Access Control

Docs-backed

Free developer images require no auth — public pull from cgr.dev/chainguard; enterprise images require chainctl auth login (GitHub/Google OAuth or OIDC); organization-level RBAC via chainctl; cosign keyless verification uses Sigstore infrastructure (Fulcio CA + Rekor transparency log) — no private keys to manage; SBOM and attestations are publicly verifiable via Sigstore.

keel-expansion Mar 30, 2026

Chainguard: Error Handling & Operational Reliability

Docs-backed

Daily rebuild pipeline runs on Chainguard infrastructure; CVE scan results published per image in Chainguard Image Directory; images use minimal attack surface (no shell, no package manager in distroless variants) reducing exploit vectors; cosign verify is client-side and offline after fetching the attestation bundle; structured JSON SBOMs enable programmatic dependency auditing; chainctl diff shows CVE count delta between image versions.

keel-expansion Mar 30, 2026

Chainguard: Documentation & Developer Experience

Docs-backed

Documentation covers image quickstart by language (Python, Node, Go, Java, .NET), Wolfi package ecosystem, SBOM download guide, provenance verification with cosign, chainctl CLI reference, and enterprise registry setup. Chainguard Image Directory at images.chainguard.dev. Confidence is docs-derived.

keel-expansion Mar 30, 2026

Use in your agent

mcp
get_score ("chainguard")
● Chainguard 8.7 L4 Native
exec: 8.6 · access: 8.5

Trust shortcuts

This score is documentation-derived. Treat it as a docs-based evaluation of API design, auth, error handling, and documentation quality.

Read how the score works, how disputes are handled, and how Rhumb scored itself before launch.

Overall tier

L4 Native

8.7 / 10.0

Alternatives

No alternatives captured yet.