Supply ChainContainer Registries

Scan Docker Hub Images with cnspec

Scan Docker Hub container images for security vulnerabilities and misconfigurations with cnspec.

Docker Hub is the most widely-used public container registry. To learn the basics, read the Docker Hub Get Started Guide.

Scanning a registry is part of securing your supply chain with cnspec. If you're new to cnspec, start with the Quickstart.

If you install cnspec on machines that can't download and install updates (because they're air-gapped or don't give cnspec write access), you must deploy cnspec providers. To learn more, read Manage cnspec Providers.

Prerequisites

Install the Docker CLI and log in to the registry:

docker login

Scan Docker Hub

Scan a specific repository:

cnspec scan container registry index.docker.io/<org>/<image>

cnspec resolves the available image tags, applies the OS security policies that match each image's platform, and reports vulnerabilities and misconfigurations:

→ discover related assets for 1 asset(s)

Asset: (Alpine Linux v3.19) index.docker.io/lunalectric/luna-web@6baf43584bcb
-----------------------------------------------------------------------------

Passing:
✓ Ensure no duplicate UIDs exist
✓ Ensure secure permissions on /etc/passwd are set
✓ Ensure system accounts are non-login

Scanned 1 asset

Alpine Linux v3.19
  LOW (0):      index.docker.io/lunalectric/luna-web@6baf43584bcb

Scan a specific tagged image with cnspec scan docker:

cnspec scan docker mondoo/cnspec:latest

Learn more

On this page