Open source container scanning tool to find vulnerabilities and suggest best practice improvements?

This page summarizes the projects mentioned and recommended in the original post on /r/selfhosted

Our great sponsors
  • WorkOS - The modern identity platform for B2B SaaS
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • SaaSHub - Software Alternatives and Reviews
  • trivy

    Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

  • https://github.com/aquasecurity/trivy 17k stars, updated 11 hours ago

  • grype

    A vulnerability scanner for container images and filesystems

  • https://github.com/anchore/grype 5.6k stars, updated 3 days ago

  • WorkOS

    The modern identity platform for B2B SaaS. The APIs are flexible and easy-to-use, supporting authentication, user identity, and complex enterprise features like SSO and SCIM provisioning.

    WorkOS logo
  • vimp

    Compare data from multiple vulnerability scanners to get a more complete picture of potential exposures. (by mchmarny)

  • Something I saw recently was https://github.com/mchmarny/vimp which does vulnerability checking via multiple different tools; haven't used it too much yet but could be quite handy.

  • clair

    Vulnerability Static Analysis for Containers

  • https://github.com/quay/clair 9.4k stars, updated 17 hours ago

  • grafeas

    Artifact Metadata API

  • https://github.com/grafeas/grafeas 1.4k stars, updated last week

  • dagda

    a tool to perform static analysis of known vulnerabilities, trojans, viruses, malware & other malicious threats in docker images/containers and to monitor the docker daemon and running docker containers for detecting anomalous activities

  • https://github.com/eliasgranderubio/dagda 1k stars, updated July 27th, 2021

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts