wagoodman/dive
61.6
Adequate · 24 September 2026
7.2k
lines of production code
Go
primary language
5
measurements over time
What this system is
Dive is a command-line tool for analyzing Docker and Podman container images, supporting both live engine sources and local archive files. It provides deep inspection of image layers, file trees, and storage efficiency metrics. The system allows users to build images, evaluate them against configurable CI rules, and export analysis data as JSON.
Features
Add Podman image support for Linux and macOS
Users can now use Podman as an image source in addition to Docker. The tool invokes the external \podman\ binary to build, fetch, and extract image data on Linux and macOS platforms. On unsupported platforms (e.g., Windows), the Podman resolver remains present but returns an "unsupported platform" error. This change introduces new files (\build.go\, \cli.go\, \resolver.go\, and \resolver\_unsupported.go\) that implement the image resolver interface for Podman.
dive/image/podman · high confidence
Add support for building images and loading Docker archives
Users can now build images using the \dive build\ command, which supports both \Dockerfile\ and \Containerfile\ formats, and can load images from local archives via the new \docker-archive\ resolver. The \docker-engine\ resolver has been updated to support image extraction and automatic pulling, while the image archive parser now handles OCI-compatible formats (Docker 25+) with MIME sniffing for layers. Tests have been added for the new build and archive loading functionality.
dive/image/docker · high confidence
Added sample Dockerfiles and CI configuration for testing
New sample Dockerfiles (minimal, test-image, and example) and a CI configuration file (.dive-ci) were added to the .data directory. These files provide test cases and configuration for validating image efficiency and wasted space thresholds in CI environments.
.data · high confidence
Introduce file tree comparison, efficiency scoring, and sorting strategies
The filetree package now includes new capabilities for comparing file trees across layers, calculating storage efficiency scores, and sorting file nodes. A new Comparer component enables natural and aggregated layer comparisons, while an Efficiency module computes a score based on file duplication and removal across layers. Additionally, the file tree now supports alternative ordering strategies, allowing users to sort file nodes by name or by size in descending order.
dive/filetree · high confidence
New image analysis and layer representation
The dive/image package now introduces a structured approach to image analysis and layer handling. A new \Analysis\ struct and \Analyze\ function compute image efficiency, size, and wasted bytes by iterating through layers and file trees. The \Image\ struct is defined to hold requests, file trees, and layers. The \Layer\ struct is introduced with fields for ID, index, command, size, tree, names, and digest, along with methods for short ID generation and command previewing. A \Resolver\ interface is added to define how images are fetched or built, including content extraction capabilities.
dive/image · high confidence
Support for Docker archive image sources
The dive tool now supports resolving images from Docker archive files (tarballs) in addition to the existing Docker and Podman engine sources. This change introduces a new image source type, allowing users to analyze image layers directly from archive files, expanding the tool's flexibility for offline or pre-exported image analysis.
dive · high confidence
Behavioural changes
Refactor CLI command structure and add comprehensive CLI tests
The CLI command structure has been refactored, introducing a new \cli.go\ entry point that uses the \clio\ library to manage the root command, global flags, and subcommands. This change includes the addition of a \build\ command for building Docker images, a \ci\ module for evaluating image analysis against configurable rules (efficiency, wasted bytes, etc.), and an \export\ package for JSON serialization. To support this new structure, a suite of integration tests has been added across \cli\_build\_test.go\, \cli\_ci\_test.go\, \cli\_config\_test.go\, \cli\_json\_test.go\, \cli\_load\_test.go\, and \cli\_test.go\, covering scenarios such as implicit/explicit Dockerfile paths, CI rule evaluation, and image loading from various sources.
cmd, cmd/dive/cli/internal/ui/v1, internal · high confidence
Dependencies
Updated Go dependencies
The project's Go module dependencies have been updated, including bumping golang.org/x/net to v0.40.0, go.uber.org/atomic to v1.11.0, and github.com/spf13/viper to v1.20.1. Other dependencies such as github.com/docker/cli, github.com/docker/docker, and github.com/awesome-gocui/gocui have also been updated to their latest compatible versions.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 58 → 62 (+3.6)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 89 → 92 (+2.8)
- Architecture 100 → 97 (-3.4)
- Maturity 49 → 49 (-0.1)
- Readiness 68 → 77 (+9.0)
- Security 53 → 61 (+8.8)
Resolved (50)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (11 lines × 2) (cmd/dive/cli/internal/ui/v1/view/filetree.go)
- Duplicated block (13 lines × 2) (dive/filetree/comparer.go)
- Duplicated block (15 lines × 2) (internal/bus/event/parser/parsers.go)
- Duplicated block (23 lines × 2) (cmd/dive/cli/internal/ui/v1/view/image_details.go)
- Duplicated block (5 lines × 2) (cmd/dive/cli/internal/ui/v1/view/debug.go)
- Duplicated block (6 lines × 2) (dive/image/docker/cli.go)
- Duplicated block (9 lines × 2) (cmd/dive/cli/internal/ui/v1/viewmodel/filetree.go)
- High CVE: [GHSA redacted] (go.mod)
- High CVE: [GHSA redacted] (go.mod)
- High CVE: [GHSA redacted] (go.mod)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 30 more
New (103)
- Dependency pinned to a stale untagged commit: github.com/awesome-gocui/keybinding
- Dependency pinned to a stale untagged commit: github.com/google/shlex
- Dependency pinned to a stale untagged commit: github.com/phayes/permbits
- Dependency pinned to a stale untagged commit: github.com/wagoodman/go-partybus
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (10 lines × 2) (dive/image/docker/cli.go)
- Duplicated block (11 lines × 2) (cmd/dive/cli/internal/ui/v1/view/filetree.go)
- Duplicated block (12 lines × 2) (cmd/dive/cli/internal/ui/v1/view/debug.go)
- Duplicated block (14–15 lines × 2) (dive/filetree/comparer.go)
- Duplicated block (16 lines × 2) (internal/bus/event/parser/parsers.go)
- Duplicated block (31–39 lines × 2) (cmd/dive/cli/internal/ui/v1/view/image_details.go)
- Duplicated block (6 lines × 2) (cmd/dive/cli/internal/ui/v1/view/image_details.go)
- Duplicated block (6 lines × 2) (cmd/dive/cli/internal/ui/v1/view/image_details.go)
- Duplicated block (6 lines × 2) (dive/image/docker/cli.go)
- Duplicated block (8 lines × 2) (cmd/dive/cli/internal/ui/v1/view/debug.go)
- Duplicated block (8 lines × 2) (cmd/dive/cli/internal/ui/v1/viewmodel/filetree.go)
- Duplicated block (9 lines × 2) (cmd/dive/cli/internal/command/build.go)
- High CVE: [GHSA redacted] (go.mod)
- High CVE: [GHSA redacted] (go.mod)
- …and 83 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
wagoodman/dive was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit d6c691947f8fda635c952a17ee3b7555379d58f0 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-923689c465cf.