Kennel
100% Free • No Login or Registration Required

Guard Your Containers. Instant Clarity in One Click.

On-demand container image security: SBOM generation, OSV vulnerability scans, and EOL checks — no pipeline setup, no sign-up.
Interactive search bar and container image input
Interactive search bar and container image input
Visibility

Complete Image Visibility, Instantly Linked

Every scan delivers an immediate, unified snapshot of your container at a single point in time.
SBOM Deep-Dive
Extract multi-generator CycloneDX SBOMs on demand. Map dependency trees, audit licenses, and trace components straight to vulnerabilities.
Vulnerability Threat Radar
Catch threats before deployment. Filter OSV findings by severity with actionable paths to remediation.
EOL & Support Status
Check support windows and end-of-life dates for components in the image.
Container image
Reconstruct build history from image layers — instructions as a timeline, copyable as a build script.
Share reports
Copy a full report link for the interactive report — or a summary snapshot with the key findings that lives entirely in the link.
PDF export
Download an SBOM report as PDF — with packages, license overview, and vulnerabilities at scan time.
Slice-n-dice analytics dashboard and heatmap
Slice-n-dice analytics dashboard and heatmap
Tooling

Analysis flow

Kennel picks the best generators for what it finds in the image, then checks packages against open databases. First it builds SBOMs; from there it runs an OSV match and EOL resolution — both based on those SBOM results.
SBOM
Best-of SBOM generators for the detected environment or programming language

Depending on interpreters and package managers in the image, Kennel selects matching SBOM generators and returns CycloneDX SBOMs per discovered path.

OSV
Open Source Vulnerabilities database

Packages from the SBOMs are matched against Google's OSV database — an open vulnerability corpus covering many ecosystems.

EOL
End-of-life resolver

Kennel resolves support status and end-of-life dates for components found in the image.

Security

Hosted in Germany • Privacy by Design

Your Container image and infrastructure security remain strictly protected:
  • German Infrastructure
    Hosted 100% in secure German data centers bound by strict European data sovereignty laws.
  • Zero Persistent Storage
    Container rootfs images are extracted in-memory, analyzed, and never saved to persistent disk.
  • Temporary Caching Only
    Scan metadata is cached strictly to deliver your shareable report URL, then automatically purged.
  • Ephemeral Credentials
    Private registry pull secrets are evaluated strictly in-memory during retrieval and never logged or stored.
  • No Marketing Cookies
    No advertising or marketing tracking — we do not set marketing cookies and do not build user profiles.
  • No AI Training
    Your scan data and container contents are never used to train AI models — neither by us nor by third parties.
Use cases

Ship with Unshakable Confidence

For teams that need to know what is actually inside the image before rollout — not just the base tag in the container image.
  • Pre-Flight Security
    Inspect container images manually before rollout and prioritize findings by fixability.
  • Supply Chain Truth
    Cross-verify dependencies and licenses across multiple industry-standard generators rather than trusting a single tool export.
  • EOL checks
    See which components are still supported and which have reached end of life.
Pipeline

Precision Execution Engine

Paste your registry URL, hit scan, and watch Kennel execute a real-time deep inspection:
Phase 1
Secure Pull
Your image is pulled securely (including private registries) and the rootfs is unpacked.
Phase 2
Smart Discovery
Instantly pinpoints interpreters, software packages, and optimal scanners.
Phase 3
Multi-Tool SBOM
Builds targeted CycloneDX SBOMs with the generators that fit the discovered environments.
Phase 4
OSV Threat Check
Cross-references every package against Google's open-source OSV database.
FAQ

Common questions

The points that usually come up before the first scan.

Scan an image now

Registry URL, tag, and architecture are enough to start. Add credentials when you need them.