Sign inSign up

sonatypecommunity/nancy

By sonatypecommunity

•Updated 4 months ago

Sonatype's Nancy, on Docker!

Image
Developer tools
1

1M+

sonatypecommunity/nancy repository overview

⁠Nancy

nancy is a tool to check for vulnerabilities in your Golang dependencies, powered by Sonatype OSS Index, and as well, works with Nexus IQ Server, allowing you a smooth experience as a Golang developer, using the best tools in the market!

nancy currently works for projects that use dep or go mod for dependencies.

⁠Usage

Usage details can be found at our GitHub repo⁠

⁠Docker usage

nancy now comes in a boat! For ease of use, we've dockerized nancy. To use our Dockerfile:

go list -m all | docker run -i sonatypecommunity/nancy:latest

We publish a few different flavors for convenience:

  • Latest if you want to be on the bleeding edge ex: latest
  • The full tag for those concerned with 100% reliability of underlying Nancy ex: v0.1.1
  • The major version (we respect semver) ex: v0
  • The major/minor version (seriously, we respect semver) ex: v0.1

⁠Acknowledgements

The nancy logo was created using a combo of Gopherize.me and good ole Photoshop. Thanks to the creators of Gopherize for an easy way to make a fun Gopher :)

Original Gopher designed by Renee French.

⁠The Fine Print

Remember:

This project is part of the Sonatype Nexus Community⁠ organization, which is not officially supported by Sonatype. Please review the latest pull requests, issues, and commits to understand this project's readiness for contribution and use.

  • File suggestions and requests on this repo through GitHub Issues, so that the community can pitch in
  • Use or contribute to this project according to your organization's policies and your own risk tolerance
  • Don't file Sonatype support tickets related to this project— it won't reach the right people that way

Last but not least of all - have fun!

Tag summary

Content type

Image

Digest

sha256:1906074b7…

Size

7 MB

Last updated

4 months ago

docker pull sonatypecommunity/nancy