- mkdir anchore-ce;cd anchore-ce
- curl https://docs.anchore.com/current/docs/engine/quickstart/docker-compose.yaml > docker-compose.yaml
- docker-compose up -d
Download vuln libs.
- docker-compose exec api anchore-cli system status
- docker-compose exec api anchore-cli system feeds list
- docker-compose exec api anchore-cli system wait
Not required for public registries.
docker run -d -p 5000:5000 --restart=always --name registry registry:2cd <path/to/image targets/docker-compose.yamldocker-compose up -ddocker tag docker.io/<something> localhost:5000/<something>docker push localhost:5000/<something>
For any public docker hub images simply use docker.io/library/<image>:<tag> replacing the <something> tags below.
docker-compose exec api anchore-cli image add <something>docker-compose exec api anchore-cli image wait <something>docker-compose exec api anchore-cli image content <something> osdocker-compose exec api anchore-cli image vuln <something> alldocker-compose exec api anchore-cli evaluate check <something>
NOTE: If you are adding from a private registry use your external IP NOT localhost or 127.0.0.1 en lieu of docker.io
docker container stop registry