- mkdir anchore-ce;cd anchore-ce
- curl https://docs.anchore.com/current/docs/engine/quickstart/docker-compose.yaml > docker-compose.yaml
- docker-compose up -d
Download vuln libs.
- docker-compose exec api anchore-cli system status
- docker-compose exec api anchore-cli system feeds list
- docker-compose exec api anchore-cli system wait
Not required for public registries.
docker run -d -p 5000:5000 --restart=always --name registry registry:2
cd <path/to/image targets/docker-compose.yaml
docker-compose up -d
docker tag docker.io/<something> localhost:5000/<something>
docker push localhost:5000/<something>
For any public docker hub images simply use docker.io/library/<image>:<tag>
replacing the <something>
tags below.
docker-compose exec api anchore-cli image add <something>
docker-compose exec api anchore-cli image wait <something>
docker-compose exec api anchore-cli image content <something> os
docker-compose exec api anchore-cli image vuln <something> all
docker-compose exec api anchore-cli evaluate check <something>
NOTE: If you are adding from a private registry use your external IP NOT localhost
or 127.0.0.1
en lieu of docker.io
docker container stop registry