Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Advanced

    Vulnerability scanning

    Trivy, Grype, or both, run against the image on the host that owns it — and offline if that is where you are.

    MangoDock does not implement CVE-database ingestion or image-layer parsing. It runs the real scanner binary, pointed at the host you are scanning, through the same proxy it already established for docker compose. Findings come back as structured results you can read in the UI or export as SARIF.

    Both scanners will silently scan the wrong image if you let them

    Trivy's default image-source order is docker, containerd, podman, remote — so if it cannot reach the daemon it falls through to pulling the image fresh from a public registry instead of failing. Confirmed live: pointing DOCKER_HOST at an unreachable address still produced a successful scan, of an identical public tag pulled from Docker Hub, masking what should have been a hard error. Grype has the same trap under a different name. MangoDock pins the source on both, so an unreachable daemon is the loud failure it should be rather than a clean report on somebody else's image.

    Where the databases come from

    ModeBehaviour
    onlineThe scanners update themselves from the internet, as they normally would.
    mirrorThey update from your own copies — an OCI registry holding trivy-db, such as Harbor or a registry:2 mirror, and a Grype listing URL.
    offlineThey never update. You import the database by hand, exported from a connected MangoDock or downloaded on a connected machine, and its age is shown rather than used as a reason to refuse.

    That last mode exists because of what the scanners do by default on an isolated network: Trivy fails outright without a database, and Grype refuses to scan at all once its own is five days old. An enclave running online mode stops scanning within a week.

    Either way both databases live under MangoDock's data directory, so they survive an upgrade of the container and can be exported and imported.

    Air-gapped

    • Offline mode is the air-gapped path, and the offline install bundle can carry both databases with it.
    • Import a fresher database later from a newer bundle, or from the export buttons on a MangoDock that does have a connection.