Clair

C
C tier on Container Image Scanning ToolsScore 6.8 · #8 of 28
Android app
Not listed
Free plan
Yes
Runs on
api, Linux, self-hosted
github.com
The Clair homepage

Summary

Clair is a free, open-source project for finding vulnerabilities in application container images, including OCI and Docker images. It performs static analysis: clients send image manifests to the Clair API, which indexes image layers, scans their contents and returns a persisted IndexReport. It does not analyze runtime behavior. Content-addressed OCI manifests and layers help limit repeated indexing work. Clair continually ingests security information, and matcher requests provide current vulnerability analysis for an IndexReport. Its notifier checks whether newly identified vulnerabilities affect indexed manifests and responds according to its configuration. The documented support matrix includes Ubuntu, Debian, RHEL, SUSE, Oracle, Alpine, AWS Linux, VMware Photon and Python base containers. Clair v4 uses ClairCore to examine image contents and report vulnerabilities. Release notes for v4.9.0 describe NVD 2.0 JSON feeds for CVSS enrichment and support for encoding index reports as SPDX 2.3 documents. Clair is licensed under Apache 2.0 and deployed self-hosted. The README warns that the main branch may be unstable or broken and points users to releases for stable binaries. Community contact options include a mailing list, IRC channel and GitHub issues.

Who it is for

Clair is for teams that need self-hosted static vulnerability analysis for container images. Its API workflow and documented image support are relevant to users managing OCI or Docker images.

What is good

  • Free and licensed under Apache 2.0.
  • Scans image layers through a static analysis workflow.
  • Content-addressed layers help reduce duplicate indexing.
  • Supports SPDX 2.3 index report encoding.
  • Community support includes GitHub issues.

What to know first

  • Analysis covers image contents, not runtime behavior.
  • The main branch may be unstable or broken.
  • Stable binaries are directed to project releases.

Verdict

Clair offers self-hosted container image analysis with an API-based indexing workflow and ongoing vulnerability data ingestion. Users seeking stable binaries should follow the project's release guidance rather than assume the main branch is stable.

Clair plans and pricing

All plans
Clair Free Open source · self-hosted container vulnerability analysis github.com · 4 Oct 2026

Compared on container image scanning tools

Free plan
Yesgithub.com
Deployment model
self_hostedgithub.com
Registry scanning
Yesgithub.com
SBOM generation
Yesgithub.com

Facts

Purpose
Clair is an open source project for static analysis of vulnerabilities in application containers, including OCI and Docker images.github.com · 4 Oct 2026
Analysis mode
Clair parses image contents and reports vulnerabilities using static analysis rather than runtime analysis.quay.github.io · 4 Oct 2026
Workflow
Clients submit container image manifests to the Clair API for indexing and vulnerability matching.github.com · 4 Oct 2026
Indexing
Clair fetches image layers, scans their contents, and returns a persisted IndexReport.quay.github.io · 4 Oct 2026
Deduplication
Clair uses content-addressed OCI manifests and layers to reduce duplicated indexing work.quay.github.io · 4 Oct 2026
Current vulnerability data
Clair continually ingests security data, and matcher requests provide up-to-date vulnerability analysis for an IndexReport.quay.github.io · 4 Oct 2026
Notifications
The notifier checks whether newly discovered vulnerabilities affect indexed manifests and acts according to its configuration.quay.github.io · 4 Oct 2026
Supported image contents
The documented support matrix lists Ubuntu, Debian, RHEL, SUSE, Oracle, Alpine, AWS Linux, VMware Photon, and Python base containers.quay.github.io · 4 Oct 2026
Engine
Clair v4 uses the ClairCore library as its engine for examining image contents and reporting vulnerabilities.quay.github.io · 4 Oct 2026
Security data update
The v4.9.0 release notes state that ClairCore switched to NVD 2.0 JSON feeds for CVSS enrichment data.github.com · 4 Oct 2026
Output format
The v4.9.0 release notes state that ClairCore can encode index reports as SPDX 2.3 documents.github.com · 4 Oct 2026
License
The project is licensed under Apache 2.0.github.com · 4 Oct 2026
Support
The project README lists a mailing list, an IRC channel, and GitHub issues as community contact options.github.com · 4 Oct 2026
Stable builds
The README warns that the main branch may be unstable or broken and directs users to releases for stable binaries.github.com · 4 Oct 2026

Best Clair alternatives

See all 20

Where it ranks on Everything Xiaomi

Is Clair yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources