Docker Scout

Scanning BookNest's Image with Docker Scout

Docker Scout 514 is Docker 514 's image analysis service: it builds an SBOM of an image, matches it against advisory databases and recommends base-image updates (docker scout quickview, cves, recommendations, compare). The CLI plugin downloads freely from github.com/docker/scout-cli (https://github.com/docker/scout-cli 455 ), but every command needs a Docker login, and continuous monitoring is per "Scout-enabled repository", one of which comes with the free Personal plan. Installed into a separate client configuration, it stops at the login:

Installing the Scout plugin and trying it without an accountShell
export DOCKER_CONFIG=$PWD/scoutcfg; mkdir -p scoutcfg/cli-plugins
REL=https://github.com/docker/scout-cli/releases
V=$(curl -sI $REL/latest | grep -i ^location | sed 's#.*/v##' | tr -d '\r')
curl -sSfL "$REL/download/v$V/docker-scout_${V}_linux_amd64.tar.gz" \
  | tar -xz -C scoutcfg/cli-plugins docker-scout
docker scout version | grep ^version
docker scout quickview l3-booknest-api:latest 2>&1 | head -1
unset DOCKER_CONFIG
Output
version: v1.24.0 (go1.26.3 - linux/amd64)
Log in with your Docker ID or email address to use docker scout.

With a login, quickview prints the image's vulnerability counts by severity beside those of its base image and a recommended newer base, and docker scout cves --only-fixed lists what an update would fix (not run here). Scout suits teams that already have Docker accounts; the open-source scanners of the next subsection need none.