WatchTower is a self-hosted application vulnerability and lifecycle dashboard. It tracks the software you operate, maps installed versions to NVD CPE records, checks vendor and community security feeds, identifies CISA Known Exploited Vulnerabilities, and compares releases with endoflife.date lifecycle data.
WatchTower is designed for a lightweight, single-container deployment. Configuration, scan results, notification state, and operational logs remain in persistent file storage. No database or external scheduler is required.
Fresh dark-mode screenshots from WatchTower 0.11.0 — Signal, using fictional applications, contacts, and assessment evidence. The application examples use dark mode. See Light Mode and Dark Mode for the theme switch and a comparison.
Explore the screenshot gallery or follow the user guide.
- Application inventory organized into reusable workspaces.
- Guided CPE search, validation, and mapping tests against NVD data.
- Searchable lifecycle mapping with installed-version and support-state checks.
- NVD, CISA KEV, FIRST EPSS, OSV package, vendor feed, and GitHub advisory monitoring.
- CycloneDX and SPDX SBOM imports, image inventories, and stable package finding history.
- Explainable remediation priorities, workspace thresholds, and finding response filters.
- Assessed application upgrade targets, including same-major alternatives and planned versions.
- Release, end-of-life, and vulnerability status in one dashboard.
- Targeted workspace email policies, concise alerts, reminders, and acknowledgement links.
- OpenID Connect sign-in and delegated access control.
- Separate system, feed, audit, and authentication logs available from the interface.
- Versioned, signed container images published to Docker Hub.
WatchTower is a triage tool. Its results depend on correct product mappings and the data available from external sources. Always confirm affected versions and remediation guidance with the software vendor.
- Initial setup
- Container requirements
- Persistent storage
- OpenID Connect setup
- TLS and reverse proxies
- Upgrading WatchTower
- Backup and rollback
- Container troubleshooting
- First sign-in
- Dashboard and status
- Applications
- CPE vulnerability mappings
- Lifecycle mappings
- Workspaces
- Vendor and advisory feeds
- Email notifications
- General settings
- Access control
- Logs and troubleshooting
- Roadmap
- 0.11.1 security patch release notes
- Signal release notes
- Changelog
- Contributing
- Code of conduct
- Support
- Security policy
- License
Public release images are published as devynn76/watchtowervi:<version>. Pin a specific version in production so upgrades are deliberate and reversible. The latest tag follows the newest successful release.
See Initial setup for a complete Docker deployment example.
Copyright 2026 Christopher Bentkowski.
WatchTower is licensed under the Apache License 2.0.


