ce.rodeo
One job, one question: which Docker image should I pull?
What ce.rodeo does
You decide to self-host something — Mautic, Postgres, Immich, Chatwoot, OpenSearch, Caddy. You go looking for a Docker image. Docker Hub has eight plausible candidates. One is the project's official image. One is Bitnami's. One is from LinuxServer. One is Chainguard's zero-CVE build. Which one do you actually run?
ce.rodeo answers that for 128 open-source projects. Every CE image we track gets scanned hourly against the latest Grype CVE database, every grade decomposes to arithmetic you can audit on /about/grades, and the whole index is community-signed with upvotes, reviews, and favorites so you can see what operators who've actually run the thing think.
What "CE" means here
Community Edition — OSI-approved or FSF-approved license at the version this image contains, no paywalled features, no source-available-but-restricted licenses (BSL, SSPL, Confluent Community License, Elastic License v2). When a project changes license (Redis → BSL/SSPL at 7.4, Terraform → BSL at 1.6, MongoDB → SSPL in 2018), we filter it out and point you at the OSI-licensed fork (Valkey, OpenTofu, FerretDB). The direct page for the removed project explains why and links to the successor.
The signals
- A Scout
- Security grade for this image right now. Ten-rule rubric from Grype CVE scan + manifest config + cosign attestations. Published formula at /about/grades.
- A Pulse
- Project health — is the maintainer still around? Composite of GitHub commits + stars + HN story velocity. See the formula.
- role:crm Tags
- Namespaced labels for discovery.
role:*for function,alt:*for SaaS replacement (alt:salesforce,alt:hubspot),stack:*,lic:*,status:*. - ↑ Upvotes
- Operators who've shipped the image to prod and want to vouch for it.
- ★ Barn
- Your private shortlist of images you've vetted. Public on your profile. Nobody has to pin an email to use it.
The infrastructure
- Astro + Svelte Islands + View Transitions on Cloudflare Pages
- Hono API on a DigitalOcean droplet, backed by Postgres
- Grype + syft + cosign in a systemd scanner that re-matches every image hourly against the fresh CVE DB
- Content-dedupe write path: 95% of hourly scans find no change and write a pointer, not a copy
- github.com/c0inz/cerodeo — the source (private, for now)
The mascot
A green frog in a brown cowboy hat with a cattleman crease, a leather band, and a gold buckle. Wrangling images is the job; the frog does the wrangling. Generated by FLUX-schnell on Cloudflare Workers AI (Apache-2.0 open-source model), hand-tuned by background-fill in Python.
Who built this
John Davenport (Exceed.io) and Claude (Anthropic). First commit was day-one, the thing you're reading is still day-one — expect rough edges while we fill in Trending, Scout Watch, and real profile pages.
On the way
Collections: curated bundles of CE images for common operator shapes (homelab, media stack, databases, dev
platform) that export to a docker-compose.yml you can pull and run. Public
by default, upvotable, composable. Ships once we have enough comment + fave data for the recommender to be useful; until then
the Barn on your profile is your private shortlist.
Issues, suggestions, "your grade formula is wrong because X" — all welcome at github.com/c0inz/cerodeo/issues.