Skip to content

Image Scanning

Docker Built-in Image Scanning

Docker provides a native CLI tool for scanning images for known vulnerabilities. It uses Trivy as the default scanner, but you can also integrate Clair and Harbor for additional scanning capabilities. Below are detailed workflows for each tool.

Using Trivy (Docker's Default Scanner)

Command syntax:

docker image scan [OPTIONS] IMAGE

Example:

docker image scan --format="{{.Repository}}/{{.Tag}}: {{.Severity}} {{.Vulnerability}} ({{.ID}})" nginx:latest

Output:

nginx:latest: medium CVE-2023-1234 (CVE-2034-1234)
nginx:latest: high CVE-2023-5678 (CVE-2023-5678)

Options:
- --format: Customize output format using Go templates.
- --skip-verify: Skip SSL certificate verification for private registries.
- --debug: Enable verbose logging for troubleshooting.

Note: Docker's scanning is limited to vulnerabilities in the base image and runtime dependencies. For deeper analysis, use third-party tools like Clair or Harbor.


Using Clair for Vulnerability Scanning

Clair is a lightweight, open-source vulnerability scanner for container images. To use it with Docker:

  1. Install Clair:

    docker run -d -p 6060:6060 --name clair quay.io/coreos Clair
    

  2. Scan an Image:
    Use the Clair CLI or API to scan an image. Example with the CLI:

    clair scan --image nginx:latest --output json
    

  3. Integrate with Docker:
    Run Clair alongside Docker containers to scan images in real-time. For example, use Clair's API to trigger scans during CI/CD pipelines.

Key Features:
- Lightweight and fast.
- Supports multiple image formats (OCI, Docker).
- Integrates with Kubernetes and CI/CD tools.


Using Harbor for Vulnerability Scanning

Harbor is a container registry that includes a built-in vulnerability scanner. To use it:

  1. Enable the Scanner:
  2. Log in to your Harbor instance.
  3. Navigate to Project Settings > Security and enable the vulnerability scanner.

  4. Scan an Image:

  5. Push an image to Harbor:
    docker push harbor.example.com/myproject/nginx:latest
    
  6. Harbor automatically scans the image and reports vulnerabilities via the UI.

  7. Use the Harbor CLI:
    Scan an image locally using the Harbor CLI:

    harbor-cli scan --image nginx:latest
    

  8. Integrate with Docker:
    Configure Docker to use Harbor's scanner by setting the registry URL in your Docker daemon configuration (/etc/docker/daemon.json).

Key Features:
- Centralized registry with built-in security.
- Supports policy-based scanning and alerts.
- Integrates with Kubernetes and DevOps workflows.


Note: For maximum security, combine Docker's native tools with Clair and Harbor for comprehensive vulnerability detection.