Suggestions appear as you type. Use the up and down arrows to choose one and Enter to open it.

This page's audience real numbers from our own analytics — open to see them
–Visitors
–Page views
–Clicks to vendors
–Time on page
–Reading now
Clicks to vendors, by tool
  • –
Top countries
  • –
Devices
  • –

– · counted by iTechGuides's own first-party analytics, bots removed, every figure rounded down · how we count

Dockle

Free#23 of 26 in Container Security Software

Dockle: A focused CI auditor for Docker image practices, not a vulnerability scanner. Ranked #23 of 26 in Container Security Software by our editors (6.6/10); pricing: Free plan; best for CI teams auditing Docker image best practices.

6.6/10Editor score
Dockle6.6 Visit Dockle

At a glance

  • Editor score
    6.6 / 10
  • Pricing
    Free plan
  • Best for
    CI teams auditing Docker image best practices
  • Free plan
    Yes
  • Paid from
    None
  • Image scanning
    Yes
  • Facts checked
    22 Sep 2026
Dockle screenshot
  • Where it wins

    • Checks CIS Docker Benchmark and Docker best-practice requirements
    • Outputs JSON or SARIF with configurable CI exit codes
    • Supports registries, tar archives, and sensitive file detection
  • Where it doesn't

    • Does not scan for vulnerability patches
    • Does not provide runtime protection or Kubernetes security
    • Does not generate SBOMs or enforce admission control

Our verdict on Dockle

Dockle is an open-source command-line tool for auditing built container images against Docker best practices and CIS Docker Benchmark checkpoints. It suits CI teams that want repeatable checks on image configuration, sensitive files, and environment variables before deployment. Dockle runs locally, in a Docker container, or within continuous-integration workflows, and it analyzes images rather than Dockerfiles. Its self-hosted deployment model also fits teams that prefer to run checks within their own development and delivery environments.

Dockle’s strongest fit is automated policy checking in CI. Results can be emitted as list, JSON, or SARIF output, while configurable exit codes and alert levels help teams decide which findings should fail a pipeline. Ignore, accept, and reject rules provide control over individual checks and files. Integrations include GitHub Actions, Travis CI, CircleCI, Jenkins, and GitLab CI. For image access, Dockle supports Docker Hub, Amazon ECR, Google Container Registry, basic-authenticated self-hosted registries, and images saved as tar archives. These capabilities make it practical for teams auditing image hygiene across several delivery paths.

The scope is deliberately narrower than a full container security platform. Dockle does not support vulnerability patch scanning, runtime protection, Kubernetes security, admission control, or SBOM generation. The published guidance recommends Trivy for vulnerability scanning, so teams needing both configuration auditing and vulnerability analysis should pair Dockle with another tool or choose an alternative that covers both areas. Pick Dockle when CIS-oriented image checks and CI outputs are the priority; look elsewhere when runtime defenses, Kubernetes controls, or software inventory are core requirements.

Dockle pricing

Plans Free planFree Free to use — no paid tier required for the core job.
See plans on github.com

Dockle fact sheet

Free planYes
Paid fromNone
Image scanningYes
Runtime protectionNot verified
Kubernetes securityNot verified
Registry scanningNot verified
Admission controlNot verified
SBOM generationNot verified
Deployment modelSelf_hosted
DeploymentSelf-hosted
PlatformsWindows, macOS, Linux
SupportDocs
Built forSolo, Small business, Mid-market (editorial estimate)
Integrations4 integrations: Docker Hub, Amazon ECR, Google Container Registry, Self-hosted registries
PricingFree plan
Websitegithub.com
Facts checked22 Sep 2026

Dockle integrations

Dockle lists 4 integrations on its own site.

  • Docker Hub
  • Amazon ECR
  • Google Container Registry
  • Self-hosted registries

Alternatives to Dockle

See all Dockle alternatives →

Used Dockle? Be the first to review it

The editor score above is our own research. What this page doesn't have yet is a reader's view — what you used Dockle for, what worked and what didn't. No stars are seeded and no review is paid for; an editor reads every one before it appears.

Write a reviewTwo minutes · verified accounts only · read by an editor before it appears

Reviews come only from verified accounts. Sign in or create an account first — your e-mail is never shown.

Your rating

0 characters · at least 80, up to 3,000

Posted from your verified account. Reviews appear after an editor reads them, usually within two working days.

Featured on iTechGuides

Featured on iTechGuides — Dockle 6.6/10

Dockle is listed in our Container Security Software directory. Add the badge to your site — it links back to this page.

<a href="https://www.itechguides.com/products/dockle/"><img src="https://www.itechguides.com/best/badge/dockle.svg" alt="Featured on iTechGuides" width="230" height="46"></a>

Reviewed by iTechGuides Editors · Editorial team · Updated Oct 2026

Advertiser disclosure: iTechGuides is reader-supported. We may earn a commission when you click some links. How we rank.

Last updated · How we research and update