{"repo":"CodesWhat/drydock","free":true,"listed":false,"github":"https://github.com/CodesWhat/drydock","clone":"git clone https://github.com/CodesWhat/drydock.git","description":"Open source container update monitoring — 23 registries, 20 notification triggers, audit log, OIDC auth, Prometheus metrics, and a modern dashboard.","language":"TypeScript","stars":216,"topics":["containers","devops","docker","docker-compose","homelab","monitoring","notifications","prometheus","self-hosted","typescript"],"license":"AGPL-3.0","category":"deployment-docker-iac","readme_excerpt":"English · Español · Polski · 简体中文 · Deutsch · Français · Português (Brasil) drydock Container image update watcher — 23 registries, 20 notification and action providers. [!WARNING] Updating from an older release? Read the upgrade notes first. Three security-hardening fixes first shipped in 1.4.6 and run through the entire 1.5 line, so anyone updating from a release older than 1.4.6 is affected whatever version they land on (1.4.6, any 1.5.x, or later). They are not deprecations and have no grace period: OIDC now requires authorization endpoint in your provider's discovery metadata, unauthenticated rate-limiting keys on the TCP peer address (shared bucket behind a reverse proxy), and HTTP-trigger proxy URLs must use http(s):// . See UPGRADE-NOTES.md before updating. [!WARNING] Updating to 1.6.0-rc.3 or later? More security-hardening fixes land with no grace period. An instance with no authentication configured — or with anonymous auth enabled but unconfirmed — now fails closed on upgrade, exactly like a fresh install: the container runs; protected API requests return 401 ; authentication discovery/status routes remain public; and /health returns 503 . The SPA shell may still load, but it cannot read protected application data. Set DD ANONYMOUS AUTH CONFIRM=true or configure DD AUTH BASIC /OIDC before upgrading. The session cookie is renamed connect.sid → drydock.sid , signing every existing user out once. HTTP notification triggers (plus the Hass webhook and registry icon fetc","default_branch":null,"files":null,"tree":[],"storefront":"/r/CodesWhat","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/CodesWhat/drydock/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}