Clair
- Android app
- Not listed
- Free plan
- Yes
- Runs on
- api, Linux, self-hosted

Summary
Clair is a free, open-source project for finding vulnerabilities in application container images, including OCI and Docker images. It performs static analysis: clients send image manifests to the Clair API, which indexes image layers, scans their contents and returns a persisted IndexReport. It does not analyze runtime behavior. Content-addressed OCI manifests and layers help limit repeated indexing work. Clair continually ingests security information, and matcher requests provide current vulnerability analysis for an IndexReport. Its notifier checks whether newly identified vulnerabilities affect indexed manifests and responds according to its configuration. The documented support matrix includes Ubuntu, Debian, RHEL, SUSE, Oracle, Alpine, AWS Linux, VMware Photon and Python base containers. Clair v4 uses ClairCore to examine image contents and report vulnerabilities. Release notes for v4.9.0 describe NVD 2.0 JSON feeds for CVSS enrichment and support for encoding index reports as SPDX 2.3 documents. Clair is licensed under Apache 2.0 and deployed self-hosted. The README warns that the main branch may be unstable or broken and points users to releases for stable binaries. Community contact options include a mailing list, IRC channel and GitHub issues.
Who it is for
Clair is for teams that need self-hosted static vulnerability analysis for container images. Its API workflow and documented image support are relevant to users managing OCI or Docker images.
What is good
- Free and licensed under Apache 2.0.
- Scans image layers through a static analysis workflow.
- Content-addressed layers help reduce duplicate indexing.
- Supports SPDX 2.3 index report encoding.
- Community support includes GitHub issues.
What to know first
- Analysis covers image contents, not runtime behavior.
- The main branch may be unstable or broken.
- Stable binaries are directed to project releases.
Verdict
Clair offers self-hosted container image analysis with an API-based indexing workflow and ongoing vulnerability data ingestion. Users seeking stable binaries should follow the project's release guidance rather than assume the main branch is stable.
Clair plans and pricing
All plansCompared on container image scanning tools
- Free plan
- Yesgithub.com
- Deployment model
- self_hostedgithub.com
- Registry scanning
- Yesgithub.com
- SBOM generation
- Yesgithub.com
Facts
- Purpose
- Clair is an open source project for static analysis of vulnerabilities in application containers, including OCI and Docker images.github.com · 4 Oct 2026
- Analysis mode
- Clair parses image contents and reports vulnerabilities using static analysis rather than runtime analysis.quay.github.io · 4 Oct 2026
- Workflow
- Clients submit container image manifests to the Clair API for indexing and vulnerability matching.github.com · 4 Oct 2026
- Indexing
- Clair fetches image layers, scans their contents, and returns a persisted IndexReport.quay.github.io · 4 Oct 2026
- Deduplication
- Clair uses content-addressed OCI manifests and layers to reduce duplicated indexing work.quay.github.io · 4 Oct 2026
- Current vulnerability data
- Clair continually ingests security data, and matcher requests provide up-to-date vulnerability analysis for an IndexReport.quay.github.io · 4 Oct 2026
- Notifications
- The notifier checks whether newly discovered vulnerabilities affect indexed manifests and acts according to its configuration.quay.github.io · 4 Oct 2026
- Supported image contents
- The documented support matrix lists Ubuntu, Debian, RHEL, SUSE, Oracle, Alpine, AWS Linux, VMware Photon, and Python base containers.quay.github.io · 4 Oct 2026
- Engine
- Clair v4 uses the ClairCore library as its engine for examining image contents and reporting vulnerabilities.quay.github.io · 4 Oct 2026
- Security data update
- The v4.9.0 release notes state that ClairCore switched to NVD 2.0 JSON feeds for CVSS enrichment data.github.com · 4 Oct 2026
- Output format
- The v4.9.0 release notes state that ClairCore can encode index reports as SPDX 2.3 documents.github.com · 4 Oct 2026
- License
- The project is licensed under Apache 2.0.github.com · 4 Oct 2026
- Support
- The project README lists a mailing list, an IRC channel, and GitHub issues as community contact options.github.com · 4 Oct 2026
- Stable builds
- The README warns that the main branch may be unstable or broken and directs users to releases for stable binaries.github.com · 4 Oct 2026
Best Clair alternatives
See all 20Where it ranks on Everything Xiaomi
Is Clair yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- github.com/quay/clair· checked 4 Oct 2026
- quay.github.io/clair/· checked 4 Oct 2026
- github.com/quay/clair/releases· checked 4 Oct 2026



