A current inventory
Track supported Dockerfiles, Compose files, devcontainer definitions and conventional Helm values. Start with visibility, then introduce policy in stages.
Base image management platform
See where base images are used. Set the approved path forward. Get the fix into your teams’ normal workflow.
The governance loop
Updating one image is simple. Keeping every base image current across an organization is not. BIMP closes the operational gap between security, platform and development teams.
Find base-image references across the repositories and branches you choose.
Apply published policy and identify the approved destination for each image.
Show the health, policy and remediation state behind every decision.
Open or update a reviewable pull or merge request in the team's workflow.
Capture time-bound snooze requests with context, review and expiry.
Retain who decided what, why it changed and what happened next.
The organization view
See organizational health, active security work, pending decisions and unmanaged images together—so each team can move from posture to action.
What to expect
BIMP puts policy and remediation into the tools and delivery controls your organization already trusts.
Track supported Dockerfiles, Compose files, devcontainer definitions and conventional Helm values. Start with visibility, then introduce policy in stages.
Create versioned Policy Groups, scope them to the right repositories and branches, and preview their impact before publishing.
Deliver the approved replacement through GitHub pull requests or GitLab merge requests, with the rationale and review metadata teams need.
Turn delays into explicit, expiring decisions—not context that disappears into chat or an untracked ticket.
Follow repository health, ownership, incidents and remediation progress, backed by an audit record of every decision.
Clear boundaries
BIMP is a base-image governance and remediation platform that works with the image providers, registries, code hosts and delivery controls you choose.
BIMP is not a vulnerability scanner, base-image provider, or replacement for security review, CI, testing, approval or deployment.
Make remediation business as usual
Without creating another queue for developers to watch.
Join the closed beta