Clair logo

Clair

Static analysis for container image vulnerabilities, accessed through an API

Open Source Alternative to
Repository activity
  • Stars11k
  • Forks1.2k
  • Open Issues54
quay health score - Linux Foundation Insights
License

Apache-2.0

Languages
  • Go
  • jq
  • Makefile
Clair screenshot

About Clair

Clair performs static analysis of vulnerabilities in application containers, including OCI and Docker images. Teams can index container images and match them against known vulnerabilities before they reach production.

Clients submit images through the Clair API to index them and check for matching vulnerabilities. The goal is a more transparent view of the security of container-based infrastructure, with stable binaries provided through tagged releases.

Clair runs as a self-hosted service under the Apache 2.0 license. It fits into container security workflows and analyzes images on demand, giving teams an automated way to spot known CVEs in the layers they ship.

Key features

  • Static vulnerability analysis for OCI and Docker images
  • API to index container images and request matches
  • Matches indexed images against known vulnerabilities
  • Runs as a service for container security workflows

Details

First released
2015
Latest release
v4.9.0
Platforms
Docker · CLI
Deployment
Self-hosted service
Image types
OCI · Docker