Tomoya Amachi is a CEO and seasoned developer with 14 years of experience building secure, production-grade software and leading an IT consulting firm from Yokohama. He is the author of Dockle, a popular container image linter, and a key maintainer/contributor to well-known open-source security tools like Vuls and Trivy, where he implemented core analyzers and CLI/DevOps features. Tomoya combines hands-on backend and security engineering with product leadership, having held roles from product director to team lead across gaming and startup environments. A regular speaker at security and Go conferences, he brings a practical focus on container and package vulnerability scanning and has a background that uniquely spans medicine (Hiroshima University) to nursing before transitioning into tech.
14 years of coding experience
6 years of employment as a software developer
Bachelor's degree, Medicine, Bachelor's degree, Medicine at Hiroshima University
Container Image Linter for Security, Helping build the Best-Practice Docker Image, Easy to start
Role in this project:
Back-end & DevOps Engineer
Contributions:64 releases, 20 reviews, 217 commits in 3 years 8 months
Contributions summary:Tomoya's contributions primarily centered on the implementation and maintenance of the command-line interface (CLI) functionality for the `dockle` tool. This included adding the main command, incorporating features for output formatting (normal, json), input file handling, exit code configuration, and cache management. Furthermore, the user was instrumental in integrating a version check mechanism and building out the foundation of the tool with logging capabilities and defining a scanning pipeline.
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
Role in this project:
Back-end Developer & Security Engineer
Contributions:1 release, 46 commits, 14 PRs in 2 years 2 months
Contributions summary:Tomoya contributed significantly to the `trivy` project by adding package analyzers for Alpine Linux (APK) and Debian-based systems (DPKG) and RPM based systems, showcasing a focus on vulnerability detection. These analyzers involved parsing package information to identify software versions and types. Furthermore, the user made modifications to integrate with GCR (Google Container Registry), indicating work on container security and image scanning.
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.