The Sentinel Docker image provides a portable and isolated environment to run security scans on your projects (supporting Python, JavaScript/TypeScript, HTML, CSS, and dependencies) without installing dependencies on your host machine.
You can run Sentinel using Docker by mounting your project directory into the container.
docker run --rm -v $(pwd):/app ghcr.io/ronaldgosso/sentinel:latest scan .To enable AI enrichment and automated explanations, specify your preferred vendor and pass credentials via environment variables or CLI options:
OpenAI:
docker run --rm \
-v $(pwd):/app \
-e OPENAI_API_KEY="sk-..." \
ghcr.io/ronaldgosso/sentinel:latest scan . --ai-vendor openaiAnthropic Claude:
docker run --rm \
-v $(pwd):/app \
-e ANTHROPIC_API_KEY="sk-ant-..." \
ghcr.io/ronaldgosso/sentinel:latest scan . --ai-vendor anthropicMistral AI:
docker run --rm \
-v $(pwd):/app \
-e MISTRAL_API_KEY="your-api-key" \
ghcr.io/ronaldgosso/sentinel:latest scan . --ai-vendor mistralOr pass API keys directly via CLI arguments:
docker run --rm \
-v $(pwd):/app \
ghcr.io/ronaldgosso/sentinel:latest scan . --ai-vendor openai --ai-api-key "sk-..."Sentinel supports exporting findings in JSON, SARIF, HTML, and Markdown (for GitHub Action PR summaries and comments).
# Export Markdown report
docker run --rm \
-v $(pwd):/app \
ghcr.io/ronaldgosso/sentinel:latest scan . --output-format markdown --output-file /app/sentinel-report.md
# Export SARIF for GitHub Code Scanning
docker run --rm \
-v $(pwd):/app \
ghcr.io/ronaldgosso/sentinel:latest scan . --output-format sarif --output-file /app/sentinel-report.sarif- Base Image: python:3.10-slim
- Working Directory: /app
- Default Entrypoint: The container automatically delegates commands to the sentinel CLI. If no command is provided, it defaults to scan.