Release v1.0.0
Introducing OpenClarity
We are excited to announce the release of OpenClarity, a new open-source project designed to streamline security scanning and management of your cloud and on-premise infrastucture.
Why OpenClarity?
OpenClarity is the next evolution in our commitment to enhancing software supply chain security. By integrating the functionalities of KubeClarity and VMClarity, OpenClarity provides a unified interface that simplifies and strengthens the detection and management of Software Bill of Materials (SBOM) and security threats across various environments.
Key Features
🚀 Unified Scanning Capabilities:
- OpenClarity merges KubeClarity's ability to scan Docker containers and images in Kubernetes clusters with VMClarity's capacity to scan virtual machines in AWS, Azure, and GCP.
🔄 Flexible Usage Options:
- Entire Stack: Run the full OpenClarity stack with an intuitive UI to manage scans and explore results.
- CLI Usage: Execute scans with a given configuration, with results saved in a file or printed in the terminal.
- Scanner Go Module: Import the Scanner module into other applications to leverage its broad range of scanning capabilities.
⏰ Scheduled and Ad Hoc Scans:
- Run scans on-demand or schedule them to occur daily, weekly, or at custom intervals.
🔍 Asset Discovery and Management:
- Discover and scan assets like Docker containers, Docker images, and Virtual Machines for security threats. Supported environments include AWS, Azure, GCP, Docker, and Kubernetes.
🎨 Comprehensive UI:
- View an overview of security threats in your infrastructure, including the riskiest assets, findings trends over time, and detailed lists of assets and findings.
- Explore asset and finding details effortlessly.
🔌 Extensibility:
- Plug in your own scanners using provided SDKs in Python and Golang for quick development of custom scanner plugins.
Transitioning to OpenClarity
With OpenClarity now supporting all use cases covered by KubeClarity and VMClarity, these projects will no longer be supported. Please note the following important points:
- Unification of User Experience: Enjoy a seamless and enhanced user experience with OpenClarity.
- Fresh Install Required: Due to the lack of backwards compatibility, data from previous installations of KubeClarity and VMClarity cannot be migrated. A fresh installation of OpenClarity is necessary, please find the deployment guides here.
We are confident that OpenClarity will provide a more robust and user-friendly solution for managing your infrastructure's security. We encourage you to explore OpenClarity and join our community in making software supply chain security stronger and more efficient.
For more information, please visit our GitHub repository and our Documentation website. You can also join OpenClarity's Slack channel to hear about the latest announcements.
Thank you for your continued support and contributions.
The OpenClarity Team