Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 17 additions & 5 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -155,10 +155,20 @@ docker run --rm -v "$PWD:/github/workspace" \
ghcr.io/owasp/docksec:latest
```

Published multi-arch (amd64 and arm64) on every release. Pin to a specific
version (`ghcr.io/owasp/docksec:2026.9.21`) or a minor series
(`ghcr.io/owasp/docksec:2026.9`) rather than `latest` in CI. Every image carries
a build provenance attestation:
Also published to Docker Hub as `owasp/docksec`:

```bash
docker run --rm -v "$PWD:/github/workspace" \
-e INPUT_DOCKERFILE=Dockerfile \
-e INPUT_SCAN_ONLY=true \
owasp/docksec:latest
```

Published multi-arch (amd64 and arm64) on every release, to both registries
from the same build. Pin to a specific version (`ghcr.io/owasp/docksec:2026.9.21`,
`owasp/docksec:2026.9.21`) or a minor series (`ghcr.io/owasp/docksec:2026.9`)
rather than `latest` in CI. Every GHCR image carries a build provenance
attestation:

```bash
gh attestation verify oci://ghcr.io/owasp/docksec:latest --repo OWASP/DockSec
Expand Down Expand Up @@ -488,12 +498,14 @@ directly on pull requests and in the Security tab:
with:
dockerfile: 'Dockerfile'
sarif: 'true'
output_dir: ${{ github.workspace }}/docksec-results

- name: Upload SARIF to GitHub Code Scanning
uses: github/codeql-action/upload-sarif@v3
if: always()
with:
sarif_file: ~/.docksec/results
sarif_file: docksec-results
category: docksec
```

> `if: always()` is important: without it, the upload step is skipped whenever
Expand Down
3 changes: 2 additions & 1 deletion website/docs/evaluation-guide.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,8 @@ docker run --rm -v "$PWD:/github/workspace" \
ghcr.io/owasp/docksec:latest
```

The image bundles pinned Trivy and Hadolint. If you prefer a local install:
Also available on Docker Hub as `owasp/docksec:latest`. The image bundles
pinned Trivy and Hadolint. If you prefer a local install:

```bash
pip install docksec
Expand Down
10 changes: 9 additions & 1 deletion website/docs/getting-started.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,8 @@ DockSec shells out to [Trivy](https://github.com/aquasecurity/trivy) and
python -m docksec.setup_external_tools
```

Prefer no install at all? The container bundles pinned versions of both:
Prefer no install at all? The container bundles pinned versions of both, and is
published to both GHCR and Docker Hub:

```bash
docker run --rm -v "$PWD:/github/workspace" \
Expand All @@ -31,6 +32,13 @@ docker run --rm -v "$PWD:/github/workspace" \
ghcr.io/owasp/docksec:2026.9.21
```

```bash
docker run --rm -v "$PWD:/github/workspace" \
-e INPUT_DOCKERFILE=Dockerfile \
-e INPUT_SCAN_ONLY=true \
owasp/docksec:2026.9.21
```

## First scan

```bash
Expand Down
Loading