Skip to content

WatchTower

WatchTower is a self-hosted application vulnerability and lifecycle dashboard. It tracks the software you operate, maps installed versions to NVD CPE records, checks vendor and community security feeds, identifies CISA Known Exploited Vulnerabilities, and compares releases with endoflife.date lifecycle data.

WatchTower is designed for a lightweight, single-container deployment. Configuration, scan results, notification state, and operational logs remain in persistent file storage. No database or external scheduler is required.

See WatchTower

Fresh dark-mode screenshots from WatchTower 0.11.0 — Signal, using fictional applications, contacts, and assessment evidence. The application examples use dark mode. See Light Mode and Dark Mode for the theme switch and a comparison.

WatchTower 0.11.0 dark dashboard showing application status summaries and findings

Application details with version targets, ownership, risk context, and finding responses

WatchTower application inventory in dark mode

Explore the screenshot gallery or follow the user guide.

What WatchTower provides

  • Application inventory organized into reusable workspaces.
  • Guided CPE search, validation, and mapping tests against NVD data.
  • Searchable lifecycle mapping with installed-version and support-state checks.
  • NVD, CISA KEV, FIRST EPSS, OSV package, vendor feed, and GitHub advisory monitoring.
  • CycloneDX and SPDX SBOM imports, image inventories, and stable package finding history.
  • Explainable remediation priorities, workspace thresholds, and finding response filters.
  • Assessed application upgrade targets, including same-major alternatives and planned versions.
  • Release, end-of-life, and vulnerability status in one dashboard.
  • Targeted workspace email policies, concise alerts, reminders, and acknowledgement links.
  • OpenID Connect sign-in and delegated access control.
  • Separate system, feed, audit, and authentication logs available from the interface.
  • Versioned, signed container images published to Docker Hub.

WatchTower is a triage tool. Its results depend on correct product mappings and the data available from external sources. Always confirm affected versions and remediation guidance with the software vendor.

Documentation

Installation and maintenance

Using WatchTower

Project information

Container image

Public release images are published as devynn76/watchtowervi:<version>. Pin a specific version in production so upgrades are deliberate and reversible. The latest tag follows the newest successful release.

See Initial setup for a complete Docker deployment example.

License

Copyright 2026 Christopher Bentkowski.

WatchTower is licensed under the Apache License 2.0.

About

Self-hosted vulnerability monitoring dashboard that tracks application versions, vendor advisories, NVD CVEs, lifecycle status, and workspace alerts with OIDC, RBAC, and email notifications.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

3 stars

Watchers

0 watching

Forks

Releases

Sponsor this project

Packages

Used by

Contributors

Languages