cr0hn/dockerscan
The Most Comprehensive Docker Security Scanner observed · 2026-08-28
Health v2 · maintenance only
93/100
- Activity 99
- Release rhythm 81
- Longevity 100
Flags: no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 41
- age_days: 3494
- days_rel: 51
- days_push: 7
- n_releases_24m: 4
Adoption not part of the score
1710 stars · 248 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
DockerScan is a comprehensive Docker security scanner written in Go that scans containers, images, and registries using multiple techniques based on CIS Benchmarks, NIST SP 800-190, and recent supply chain attack research. It supports SARIF output and exit codes for CI/CD integration, plus a plugin architecture for extensibility.
Use cases
- scan docker images for vulnerabilities and misconfigurations
- audit a docker registry for security issues
- check containers against CIS benchmark and NIST SP 800-190
- find package CVEs in container images
- integrate container security scanning into CI/CD pipelines
- detect docker supply chain attack patterns
- generate SARIF reports from container scans
When to choose
- you need a single tool combining multiple Docker security scanning techniques
- you want SARIF output and automation-friendly exit codes for CI/CD
- you need registry and image scanning based on CIS/NIST standards
- you prefer a fast, concurrent scanner written in Go
When to avoid
- you need a permissively licensed tool, since the license is proprietary
- you rely on package CVE detection in versions 2.0.6 or earlier, which silently report zero CVEs
- you need mature ecosystem support like Trivy or Grype with broad vulnerability database coverage
Facets
cli-tool · maturity active
security vulnerability-scanning penetration-testing cli security developer-tools windows cli docker-security container-scanning image-scanning registry-scanning cis-benchmark sarif supply-chain-security containers devops linux macos docker
1 source
- readme: https://github.com/cr0hn/dockerscan · fetched 2026-08-28 · 55e790836da3
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| cr0hn/dockerscan | main | 93 |
For agents
markdown · JSON · MCP: product_card(name="cr0hn/dockerscan")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem