Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
dockle — Container Image Linter for Security, Helping build the Best-Practice Docker Image, Easy to start | Kitploit
Tools/GitHubGitHub/goodwithtech/dockle
Vulnerability ScannersContainer SecurityConfiguration AuditingDevSecOps
GitHubgoodwithtech/dockle

dockle

Container Image Linter for Security, Helping build the Best-Practice Docker Image, Easy to start

View Repository
3.3k166172 months agoReviewed by Kitploit
Website

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Financial Contributors on Open Collective GitHub release CircleCI Go Report Card License: AGPL v3

Dockle - Container Image Linter for Security, Helping build the Best-Practice Docker Image, Easy to start

Dockle helps you:

  1. Build Best Practice Docker images
  2. Build secure Docker images
    • Checkpoints includes CIS Benchmarks
$ brew untap goodwithtech/dockle # who use 0.1.16 or older version
$ brew install goodwithtech/r/dockle
$ dockle [YOUR_IMAGE_NAME]

See Installation and Common Examples

Checkpoints Comparison

TOC

  • Features
  • Comparison
  • Installation
    • Homebrew (Mac OS X / Linux and WSL)
    • RHEL/CentOS
    • Debian/Ubuntu
    • Arch Linux
    • Windows
    • Microsoft PowerShell 7
    • Binary
    • asdf
    • mise
    • From source
    • Use Docker
  • Quick Start
    • Basic
    • Docker
  • Checkpoint Summary
  • Common Examples
    • Scan an image
    • Scan an image file
    • Get or Save the results as JSON
    • Get or Save the results as SARIF
    • Specify exit code
    • Specify exit level
    • Ignore the specified checkpoints
    • Accept suspicious environment variables / files / file extensions
    • Reject suspicious environment variables / files / file extensions
  • Continuous Integration
    • GitHub Action
    • Travis CI
    • CircleCI
    • GitLab CI
    • Authorization for Private Docker Registry
      • Docker Hub
      • Amazon ECR (Elastic Container Registry)
      • GCR (Google Container Registry)
      • Self Hosted Registry (BasicAuth)
  • Contributors
    • Code Contributors
    • Financial Contributors
      • Individuals
      • Organizations
  • License
  • Author

Features

  • Detect container's vulnerabilities
  • Helping build best-practice Dockerfile
  • Simple usage
    • Specify only the image name
    • See Quick Start and Common Examples
  • CIS Benchmarks Support
    • High accuracy
  • DevSecOps
    • Suitable for CI such as Travis CI, CircleCI, Jenkins, etc.
    • See CI Example

Comparison

 DockleHadolintDocker Bench for SecurityClair
TargetImageDockerfileHost
Docker Daemon
Image
Container Runtime
Image
How to runBinaryBinaryShellScriptBinary
DependencyNoNoSome dependenciesNo
CI Suitable✓✓xx
PurposeSecurity Audit
Dockerfile Lint
Dockerfile LintSecurity Audit
Dockerfile Lint
Scan Vulnerabilities

Installation

Homebrew (Mac OS X / Linux and WSL)

You can use Homebrew on Mac OS X or Linux and WSL (Windows Subsystem for Linux).

$ brew install goodwithtech/r/dockle

RHEL/CentOS

VERSION=$(
 curl --silent "https://api.github.com/repos/goodwithtech/dockle/releases/latest" | \
 grep '"tag_name":' | \
 sed -E 's/.*"v([^"]+)".*/\1/' \
) && rpm -ivh https://github.com/goodwithtech/dockle/releases/download/v${VERSION}/dockle_${VERSION}_Linux-64bit.rpm

Debian/Ubuntu

VERSION=$(
 curl --silent "https://api.github.com/repos/goodwithtech/dockle/releases/latest" | \
 grep '"tag_name":' | \
 sed -E 's/.*"v([^"]+)".*/\1/' \
) && curl -L -o dockle.deb https://github.com/goodwithtech/dockle/releases/download/v${VERSION}/dockle_${VERSION}_Linux-64bit.deb
$ sudo dpkg -i dockle.deb && rm dockle.deb

Arch Linux

dockle can be installed from the Arch User Repository using dockle or dockle-bin package.

git clone https://aur.archlinux.org/dockle-bin.git
cd dockle-bin
makepkg -sri

Windows

VERSION=$(
 curl --silent "https://api.github.com/repos/goodwithtech/dockle/releases/latest" | \
 grep '"tag_name":' | \
 sed -E 's/.*"v([^"]+)".*/\1/' \
) && curl -L -o dockle.zip https://github.com/goodwithtech/dockle/releases/download/v${VERSION}/dockle_${VERSION}_Windows-64bit.zip
$ unzip dockle.zip && rm dockle.zip
$ ./dockle.exe [IMAGE_NAME]

Microsoft PowerShell 7

if (((Invoke-WebRequest "https://api.github.com/repos/goodwithtech/dockle/releases/latest").Content) -match '"tag_name":"v(?<ver>[^"]+)"') {
$VERSION=$Matches.ver &&
Invoke-WebRequest "https://github.com/goodwithtech/dockle/releases/download/v${VERSION}/dockle_${VERSION}_Windows-64bit.zip" -OutFile dockle.zip &&
Expand-Archive dockle.zip && Remove-Item dockle.zip }

Binary

You can get the latest version binary from releases page.

Download the archive file for your operating system/architecture. Unpack the archive, and put the binary somewhere in your $PATH (on UNIX-y systems, /usr/local/bin or the like).

  • NOTE: Make sure that it's execution bits turned on. (chmod +x dockle)

asdf

You can install dockle with the asdf version manager with this plugin, which automates the process of installing (and switching between) various versions of github release binaries. With asdf already installed, run these commands to install dockle:

# Add dockle plugin
asdf plugin add dockle

# Show all installable versions
asdf list-all dockle

# Install specific version
asdf install dockle latest

# Set a version globally (on your ~/.tool-versions file)
asdf global dockle latest

# Now dockle commands are available
dockle --version

mise

Download Tool