---
title: "QuenchWorks, 0-CVE Hardened Images &amp; Helm Charts"
author: "Mohammad Abu Mattar"
canonical: https://mkabumattar.com/projects/quenchworks-0-cve-hardened-images--helm-charts
---

[cd ../projects](/projects)

# QuenchWorks, 0-CVE Hardened Images & Helm Charts

A from-scratch, security-first replacement for the Bitnami catalog: container images and Helm charts built entirely from source on Wolfi, hardened under a strict 0-CVE build gate, cryptographically signed, and pinned by digest. Free, independent, and fully self-hostable.

10 tech·7 features· live

## // key features

-   150+ container images built from source on Wolfi, gated to zero fixable CVEs by comprehensive-mode Trivy
-   120+ production Helm charts on a shared quench-common library, each pinned to its image by digest
-   Every image cosign-signed (keyless) with SPDX SBOM and SLSA build-provenance attestations
-   ArtifactHub verified-publisher organization with per-chart metadata
-   Multi-arch (amd64 + arm64), nonroot, read-only root filesystem by default
-   Nightly Trivy rescans with an automatic self-heal rebuild loop as upstream ships fixes
-   Free and independent, no subscription, no registry pull limits, no vendor lock-in

## // stack

apkomelangeWolfiHelmKubernetesTrivyCosignSLSAGoAstroJS

## // links

[Explore QuenchWorks](https://quench-works.com/)[

Live Site](https://quench-works.com/)[

ArtifactHub (Verified Publisher)](https://artifacthub.io/orgs/quenchworks)[GitHub Organization](https://github.com/quenchworks)[Charts](https://github.com/quenchworks/charts)[Common (library chart)](https://github.com/quenchworks/common)[Website](https://github.com/quenchworks/website)

## // discussion

[next projectsysdesign, System Design Knowledge for AI Agents](/projects/sysdesign-system-design-knowledge-for-ai-agents)
