- ✓ Automated patch recommendations
- ✓ Base image update detection
- ✓ Zero-day vulnerability response
HarborGuard is a unified security scanning platform that provides deep vulnerability analysis and visualization for Docker images using industry-leading security tools.
Get started with:
docker run -p 3000:3000 ghcr.io/harborguard/harborguard:latest
Automatically identify and remediate vulnerabilities with smart patching recommendations and automated container image rebuilding.
Reduce your attack surface by automatically identifying fixable CVEs and providing actionable remediation steps for your container images.
HarborGuard integrates industry-leading security scanners to provide comprehensive vulnerability detection and analysis for your container images.
Get complete visibility into your container security posture with detailed vulnerability reports and remediation guidance.
Track and manage vulnerabilities across your entire container image inventory with a unified database that aggregates findings from all security scanners.
Gain complete visibility into your security posture with a comprehensive database that tracks every vulnerability across all your container images in one centralized location.
Start with our free open source edition or unlock enterprise features
Perfect for individuals and small teams
Advanced features for organizations
Gain deep insights into your container security posture
Vulnerability scatterplots and severity tracking
Detailed layer-by-layer image exploration
Trusted by the contributors around the world
High-performance scanning capability enabling fast response
HarborGuard integrates six industry-leading security tools: Trivy for comprehensive vulnerability scanning, Grype for vulnerability matching, Syft for SBOM generation, Dockle for best practices checking, OSV Scanner for open source vulnerabilities, and Dive for layer analysis.
HarborGuard can be deployed using Docker with a simple command: docker run -p 3000:3000 harborguard/harborguard:latest. It supports various configuration options via environment variables and can be deployed in multiple environments including cloud platforms and on-premises infrastructure.
HarborGuard requires Docker to be installed on your system. It needs a PostgreSQL database for storing scan results and metadata. The platform supports concurrent scans with configurable timeout settings (5-180 minutes). Recommended minimum: 4GB RAM and 2 CPU cores for optimal performance.