Finds Docker Hub pulls in GitHub Actions, docker-compose, GitLab CI, Kubernetes and Dockerfiles that run without login — incl. service containers pulled before your docker/login-action step. Runs entirely in your browser — nothing is uploaded.
Same engine as the VS Code extension, byte for byte.
This page is the working piece. The full pack has everything below.
Finds every anonymous Docker Hub pull in GitHub Actions, compose, GitLab CI, Kubernetes and Dockerfiles, including the service containers your login step never covers. Docker Hub limit: 100
Docker Pro costs $9 per user per month billed yearly ($108 a year), and it only lifts the limit for pulls that log in; this lint costs $29 once.
Buy the full version — $29· ReadyStack
Real numbers from this tool, line by line.

Six anonymous Docker Hub pulls sat in one two-job GitHub Actions workflow we use as a sample (ci.yml), and for a CI engineer running Node tests against Postgres and Redis, three of them could not have been fixed by adding a login step.
Docker Hub's usage page (docs.docker.com/docker-hub/usage/pulls, checked 2026-09-27) sets the anonymous limit at 100 pulls per 6 hours per IPv4 address or IPv6 /64 subnet. A signed-in Personal account gets 200 pulls per 6 hours; Pro, Team and Business are unlimited. When the quota runs out, the pull fails with toomanyrequests and the job fails with it.
The usual advice is "add docker/login-action". That fixes part of the problem. Here is where the sample's six pulls happen:
A login step placed first in the lint job fixes items 4 and 6. It cannot reach items 1, 2, 3 and 5, because GitHub has pulled those images before step one runs. The job container and each service need their own credentials: block (username and password, usually a Docker Hub access token from secrets). The docker:// action is better rewritten as a docker run step after the login, or pointed at a mirror registry.
Docker Hub Pull Limit Lint checks exactly this. It decides whether each image resolves to Docker Hub (no registry host, or docker.io), then checks the position of the pull against the login:
Beyond GitHub Actions it covers docker-compose image: lines, GitLab CI image: lines without DOCKER_AUTH_CONFIG or a Dependency Proxy prefix, Kubernetes images with no imagePullSecrets, and Dockerfile FROM lines. That is 10 rules in total.
On the clean version of the same sample (credentials on the container and postgres, redis moved to public.ecr.aws/docker/library, docker/login-action before the run steps) the lint reports 0 findings. On a docker-compose file with postgres:16, redis:7-alpine and a ghcr.io app image it reports 2; the ghcr.io image does not count against Docker Hub. On a Kubernetes Deployment running nginx:1.27 with no imagePullSecrets it reports 1.
Why not just pay Docker? Docker Pro is $9 per user per month billed yearly ($108 a year) and Team is $15. A paid plan removes the limit only for pulls that authenticate. The service container with no credentials: block still pulls anonymously, and still hits the per-IP quota shared with every other job on that runner's address.
The free tier lints the open file in VS Code, or a pasted file on the web page, using all 10 rules, and shows each line and its fix. The licence adds a whole-workspace scan in one run and a Markdown pull inventory to attach to the CI ticket.
It reads a GitHub Actions workflow, docker-compose file, GitLab CI file, Kubernetes manifest or Dockerfile and flags every image that resolves to Docker Hub and is pulled without a login: service containers, job containers, docker:// actions, docker pull/run steps and FROM lines. Each finding gives the line, the image and the fix.
It is for DevOps and CI engineers, platform teams and open-source maintainers who run GitHub Actions, GitLab CI or self-hosted runners and have seen 429 toomanyrequests errors from Docker Hub. It suits teams whose runners share one NAT IP, because every anonymous pull from the fleet draws on the same per-IP quota.
GitHub Actions pulls service containers, the job container and docker:// action images during job setup, before any step runs, so a docker/login-action step cannot authenticate those pulls. They need credentials on the service or container itself. Generic YAML linters and chatbots do not flag this, which is why the lint checks each pull's position against the login.
Free: lint the open file in VS Code or paste it into the web page, and see every anonymous Docker Hub pull with its line and fix, using all 10 rules. The $29 licence adds a whole-workspace scan in one run and a Markdown pull-inventory report you can attach to the CI ticket. It is one payment with one licence key per person or team seat.
Docker Pro is $9 per user per month billed yearly, or $108 a year, and Team is $15 per user per month billed yearly. A paid plan lifts the limit only for pulls that actually log in, so service containers without credentials stay anonymous. The lint is $29 once and shows which lines to change first.
A general AI chat answers from training data with a cutoff date, cannot read your repository and names no rule version. Docker Hub Pull Limit Lint checks the file you open against 10 rules from a rule set dated 2026-09-27, and points at the exact line with the fix. For a filing, an audit or a client you need that dated result on your own files.
One question, answered by the person who built it. Your email only if you want the answer sent.