Project reference ↗

Clair helps a registry or build system identify known vulnerabilities in container images. It first works out which supported software packages an image contains, then matches that inventory against vulnerability information. An integration can query those results before distributing or deploying the image. It is useful as a scanning service shared by other tools, but it does not watch running containers for attacks or prove that an application is safe.

Deployment and operating notes

Clair’s current project documentation describes static analysis of image contents through separate indexing, matching and notification responsibilities, built on ClairCore. The recovered CoreOS chart link and appc-era description are historical. A scanner service is not a runtime intrusion detector, and supported package ecosystems must be checked against Clair’s actual support matrix.

Before replacing an old Clair deployment, identify the API version used by the registry or client and the schema and ownership of its database. Plan vulnerability-feed access, update monitoring, authentication and image-layer access separately. Validate known images whose package inventories are understood, then compare indexing failures and matched vulnerabilities rather than only total finding counts. A new database may require re-indexing images; preserve the original until the registry integration and operational recovery are proven. Do not treat a successful scan with no findings as proof that every language package or unsupported distribution was analyzed. No Clair installation or cross-version database upgrade was exercised here.

Historical upstream link check · 2026-10-09

The recorded upstream address returned HTTP 404 on 2026-10-09; that URL was unavailable in this check. GitHub does not mark quay/clair archived or disabled; this does not establish active maintenance, support or compatibility. GitHub resolves the old repository identity to quay/clair. Link availability does not certify the historical installation instructions or current security support. The GitHub API verifies the linked repository's current location. Its repository overview is provided because the old subpage is unavailable; this is not a replacement installation guide.

Source for this check ↗

Website availability is separate from project, chart and image support. Use the current guidance and primary sources on this page to assess the distribution.

The original record

Historical Kubedex content

Preserved for context. Commands, versions, prices and results below reflect the original research.

Clair is an open source project for the static analysis of vulnerabilities in application containers (currently including appc and docker).

  1. In regular intervals, Clair ingests vulnerability metadata from a configured set of sources and stores it in the database.
  2. Clients use the Clair API to index their container images; this creates a list of features present in the image and stores them in the database.
  3. Clients use the Clair API to query the database for vulnerabilities of a particular image; correlating vulnerabilities and features is done for each request, avoiding the need to rescan images.
  4. When updates to vulnerability metadata occur, a notification can be sent to alert systems that a change has occur

 

Sources & further reading

  1. Clair v4 architecture and supported contents
  2. Recovered historical source (Common Crawl index)

Spotted something that needs another look?

Help improve this page →