awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
goodwithtech avatar

goodwithtech/dockle

0
View on GitHub↗
3,264 stars·163 forks·Go·Apache-2.0·6 viewscontainers.goodwith.tech↗

Dockle

Container Image Linter for Security, Helping build the Best-Practice Docker Image, Easy to start

Features

  • Container Security - Linter for Docker images to ensure security best practices.
  • Infrastructure and Configuration - Linter for Docker images to ensure security best practices.

Star history

Star history chart for goodwithtech/dockleStar history chart for goodwithtech/dockle

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does goodwithtech/dockle do?

Container Image Linter for Security, Helping build the Best-Practice Docker Image, Easy to start

What are the main features of goodwithtech/dockle?

The main features of goodwithtech/dockle are: Container Security, Infrastructure and Configuration.

What are some open-source alternatives to goodwithtech/dockle?

Open-source alternatives to goodwithtech/dockle include: lukasmartinelli/hadolint — Hadolint is a Dockerfile linter and Haskell-based static analysis tool. It analyzes container image configuration… coreos/clair — Clair is a container vulnerability scanner that performs static analysis of container images to identify known… anchore/grype — Grype is a command-line security scanner designed to identify known vulnerabilities within container images,… aquasecurity/trivy — Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container… cesar-rodriguez/terrascan — Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud… awslabs/cfn-python-lint — CloudFormation Linter.

Open-source alternatives to Dockle

Similar open-source projects, ranked by how many features they share with Dockle.
  • coreos/claircoreos avatar

    coreos/clair

    11,011View on GitHub↗

    Clair is a container vulnerability scanner that performs static analysis of container images to identify known security vulnerabilities. It functions as an analyzer for OCI and Docker images, indexing their contents to detect security risks and outdated packages without requiring the containers to be running. The tool identifies vulnerabilities by matching indexed container components against security databases to find common vulnerabilities and exposures. This process involves analyzing filesystem layers to track the provenance and versioning of packages across the image hierarchy. The proj

    Go
    View on GitHub↗11,011
  • lukasmartinelli/hadolintlukasmartinelli avatar

    lukasmartinelli/hadolint

    12,225View on GitHub↗

    Hadolint is a Dockerfile linter and Haskell-based static analysis tool. It analyzes container image configuration files against a set of rules to ensure valid syntax and adherence to best practices. The tool functions as a wrapper for shell checkers to inspect inline shell commands and scripts within build instructions, identifying scripting errors and bugs. It also includes security auditing capabilities to warn when images are pulled from registries not explicitly listed as trusted. The analysis engine covers quality assurance through label schema validation, syntax pattern verification, a

    Haskell
    View on GitHub↗12,225
  • anchore/grypeanchore avatar

    anchore/grype

    12,423View on GitHub↗

    Grype is a command-line security scanner designed to identify known vulnerabilities within container images, filesystems, and software manifests. It functions as a software composition analysis tool that detects security flaws in application components and open-source libraries to support supply chain security. The tool distinguishes itself by reconstructing the final state of container images through layered filesystem inspection and normalizing diverse package formats into a unified dependency graph. It maintains a local cache of security advisories synchronized from multiple upstream sourc

    Gocontainer-imagecontainerscyclonedx
    View on GitHub↗12,423
  • aquasecurity/trivyaquasecurity avatar

    aquasecurity/trivy

    36,462View on GitHub↗

    Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container images, filesystems, and infrastructure as code files. It functions as a software composition analysis tool and an infrastructure security scanner, providing automated checks for CI/CD pipelines and cloud environments to ensure the integrity of the software supply chain. The tool distinguishes itself through a modular, plugin-based architecture that allows for the independent inspection of diverse targets. It utilizes a declarative policy engine to evaluate configurations agai

    Gocontainersdevsecopsdocker
    View on GitHub↗36,462
  • See all 30 alternatives to Dockle→