Our great sponsors
|13 days ago||11 days ago|
|GNU General Public License v3.0 only||Apache License 2.0|
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
Checkmake: Experimental Linter/Analyzer for Makefiles
6 projects | news.ycombinator.com | 14 Aug 2022
Some discussion on that here:
The hadolint project does shell checking for Dockerfiles and it uses shellcheck:
So the approach is definitely feasible, but you do need a new project and probably it needs to be written in Haskell.
Dokter: the doctor for your Dockerfiles
2 projects | reddit.com/r/Python | 12 Aug 2022
how does this compare to something like hadolint?5 projects | reddit.com/r/docker | 12 Aug 2022
Also, have you run across Hadolint for linting? https://github.com/hadolint/hadolint
Are there tools that tell you if you can optimize your dockerfiles?
5 projects | reddit.com/r/docker | 8 Jul 2022
Wow that's a great tool and it has a ton of integrations https://github.com/hadolint/hadolint/blob/master/docs/INTEGRATION.md
Dhall: A Gateway Drug to Haskell
27 projects | news.ycombinator.com | 7 Jun 2022
can you recommend active Haskell open source projects?
16 projects | reddit.com/r/haskell | 30 Mar 2022
Just Say No To `:Latest`
3 projects | news.ycombinator.com | 6 Mar 2022
Worth noting that Hadolint raises warnings the issues mentioned in the article. Some examples of warnings:
- https://github.com/hadolint/hadolint/wiki/DL3007: Using latest is prone to errors if the image will ever update. Pin the version explicitly to a release tag.
Kubernetes Security Checklist 2021
28 projects | dev.to | 18 Oct 2021
Dockerfile should be checked during development by automated scanners (Kics, Hadolint, Conftest)
3 projects | reddit.com/r/u_sybrenbolandit | 31 Aug 2021
Linters are an effective way to catch (security) bugs early on in your development process. For most programming languages using linters is pretty standard. Hadolint is a linter for your Dockerfiles and is found on github here.
Best Practices for R with Docker
8 projects | dev.to | 31 May 2021
Best practices for writing Dockerfiles are being followed more and more often according to this paper after mining more than 10 million Dockerfiles on Docker Hub and GitHub. However, there is still room for improvement. This is where linters come in as useful tools for static code analysis. Hadolint lists lots of rules for Dockerfiles and is available as a VS Code extension.
What's your favourite Docker Image, and why?
15 projects | reddit.com/r/selfhosted | 4 Mar 2023
How to Secure Your Kubernetes Clusters With Best Practices
4 projects | dev.to | 2 Dec 2021
Use Docker Bench for Security to audit your container images
Container security best practices: Comprehensive guide
17 projects | dev.to | 16 Nov 2021
Other tools you can use are linux-bench, docker-bench, kube-bench, kube-hunter, kube-striker, Cloud Custodian, OVAL, and OS Query.
hardening my container: am i doing things right?
2 projects | reddit.com/r/docker | 26 Oct 2021
Docker Security Cheat Sheet
3 projects | news.ycombinator.com | 13 Mar 2021
CIS Docker benchmark is a very extensive rule set for assessing docker host, daemon, images and containers from the security perspective.
It comes with a very handy tool as well https://github.com/docker/docker-bench-security
What are some alternatives?
dockle - Container Image Linter for Security, Helping build the Best-Practice Docker Image, Easy to start
trivy - Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
kube-bench - Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark
stan - 🕵️ Haskell STatic ANalyser
ormolu - A formatter for Haskell source code
grype - A vulnerability scanner for container images and filesystems
hlint - Haskell source code suggestions
leksah - Haskell IDE
podman - Podman: A tool for managing OCI containers and pods.
ShellCheck - ShellCheck, a static analysis tool for shell scripts
bisect-binary - Tool to determine relevant parts of binary data
syft - CLI tool and library for generating a Software Bill of Materials from container images and filesystems