Ross ROSS = Recommend OSS · open-source software intelligence for agents

cr0hn/dockerscan

The Most Comprehensive Docker Security Scanner observed · 2026-08-28

github.com/cr0hn/dockerscan · Go · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

93/100

  • Activity 99
  • Release rhythm 81
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 41
  • age_days: 3494
  • days_rel: 51
  • days_push: 7
  • n_releases_24m: 4

Full methodology

Adoption not part of the score

1710 stars · 248 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

DockerScan is a comprehensive Docker security scanner written in Go that scans containers, images, and registries using multiple techniques based on CIS Benchmarks, NIST SP 800-190, and recent supply chain attack research. It supports SARIF output and exit codes for CI/CD integration, plus a plugin architecture for extensibility.

Use cases

  • scan docker images for vulnerabilities and misconfigurations
  • audit a docker registry for security issues
  • check containers against CIS benchmark and NIST SP 800-190
  • find package CVEs in container images
  • integrate container security scanning into CI/CD pipelines
  • detect docker supply chain attack patterns
  • generate SARIF reports from container scans

When to choose

  • you need a single tool combining multiple Docker security scanning techniques
  • you want SARIF output and automation-friendly exit codes for CI/CD
  • you need registry and image scanning based on CIS/NIST standards
  • you prefer a fast, concurrent scanner written in Go

When to avoid

  • you need a permissively licensed tool, since the license is proprietary
  • you rely on package CVE detection in versions 2.0.6 or earlier, which silently report zero CVEs
  • you need mature ecosystem support like Trivy or Grype with broad vulnerability database coverage

Facets

cli-tool · maturity active

security vulnerability-scanning penetration-testing cli security developer-tools windows cli docker-security container-scanning image-scanning registry-scanning cis-benchmark sarif supply-chain-security containers devops linux macos docker

1 source

Member repositories

RepositoryRoleHealth v2
cr0hn/dockerscanmain93

For agents

markdown · JSON · MCP: product_card(name="cr0hn/dockerscan")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem