Clair
Note: The main
branch may be in an unstable or even broken state during development.
Please use releases instead of the main
branch in order to get stable binaries.
Clair is an open source project for the static analysis of vulnerabilities in
application containers (currently including OCI and docker).
Clients use the Clair API to index their container images and can then match it against known vulnerabilities.
Our goal is to enable a more transparent view of the security of container-based infrastructure.
Thus, the project was named Clair
after the French term which translates to clear, bright, transparent.
The book contains all the documentation on Clair's architecture and operation.
Contributing
See CONTRIBUTING for details on submitting patches and the contribution workflow.
License
Clair is under the Apache 2.0 license. See the LICENSE file for details.