ShadowArcanist/sonar

A vulnerability scanner for Docker images that scans both local Docker images and remote self-hosted container registries.

★ 0Forks 0TypeScriptGitHub ↗Compare

README

Sonar

A vulnerability scanner for Docker images that scans both local Docker images and remote self-hosted container registries.

Features

  • Scan local Docker images from the Docker daemon
  • Scan remote selfhosted container registries (only supports public images)
  • Detect vulnerabilities with severity levels (critical, high, medium, low)
  • View detailed vulnerability information including CVSS scores
  • Search and filter scanned images
  • SQLite database for persistent storage

More aren't planned but feel free to add them yourself.

Architecture

  • Backend: Go with SQLite database
  • Frontend: Next.js with React, Tailwind CSS, and Radix UI
  • Scanner: Trivy for vulnerability detection

Deployment

You can deploy this application using the provided Docker Compose file or through Coolify.

Deploy Using Docker Compose
  1. Create a docker-compose.yaml file on your server and paste the contents of the docker-compose.yaml from this repo.
  2. Run docker compose up.
Deploy Using Coolify
  1. Add a new resource in Coolify → "Docker Compose Empty."
  2. Paste the contents of the coolify-compose.yaml from the repo into the input field.
  3. Click "Deploy".

Environment Variables

  • REGISTRY_URL: The URL of the remote Docker registry to scan (optional)

Configuration

Scanning Local Images

Mount the Docker socket to enable scanning of local images:

volumes:
  - /var/run/docker.sock:/var/run/docker.sock:ro

Scanning a Selfhosted Remote Registry

Set the REGISTRY_URL environment variable:

environment:
  - REGISTRY_URL=https://registry.example.com

Note: only supports public images

Running Without a Registry

If you only want to scan local images, omit the REGISTRY_URL environment variable and mount the Docker socket.

Database

Scan results are stored in a SQLite database at /app/data/scans.db inside the container. This directory is mounted as a volume to persist data across restarts.

Notes

  1. This project was entirely created using AI, but the application has been thoroughly tested.
  2. This project was built primarily for my personal use, so I will not be merging pull requests or adding new features unless I need them myself. If you want to make changes or add features, feel free to fork this repository. It’s open-sourced so others can learn from it, use it as a base for their own projects, or even run the application as-is.

Contributors

ShadowArcanist

Issues