Skip to content

Vulnerability notifications for Docker images

KestreLynx is a lightweight, open-source agent that scans the images currently running on a Docker host and reports changes in vulnerabilities that require attention.

Instead of sending the same complete scan results every day, KestreLynx highlights new findings, resolved findings, changes in fix availability, and priority escalations. It combines Trivy scan results with CISA KEV and EPSS data to separate urgent problems from noise.

Early release

KestreLynx is currently an MVP focused on CVE notifications for Docker hosts.