Dockerfile Security Hardening Advisor

Audits Dockerfiles for security vulnerabilities using Hadolint and Trivy container scanner. Recommends hardening steps based on CIS Docker Benchmark and Snyk container advisories.

agentskillexchange Updated 28 repo stars

File contents

Dockerfile Security Hardening Advisor

Audits Dockerfiles for security vulnerabilities using Hadolint and Trivy container scanner. Recommends hardening steps based on CIS Docker Benchmark and Snyk container advisories.

Installation

Use the upstream install or setup path that matches your environment:

  • Docker comes to the rescue, providing an easy way how to run hadolint on most
  • docker run --rm -i hadolint/hadolint < Dockerfile
  • docker run --rm -i ghcr.io/hadolint/hadolint < Dockerfile
  • brew install hadolint

Requirements and caveats from upstream:

  • [![Docker pulls][docker-img]][docker]
  • A smarter Dockerfile linter that helps you build [best practice][] Docker
  • Just pipe your Dockerfile to docker run:

Basic usage or getting-started notes:

Source

agentskillexchange/skills/tree/main/skills/dockerfile-security-hardening-advisor commit a7fc26e866

Frequently asked questions

npx skillmds@latest add agentskillexchange/dockerfile-security-hardening-advisor