OWASP DockSec - AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.
## Common commands
```bash
# Scan a Dockerfile and its image
docksec Dockerfile -i myapp:latest
# Scan a Docker Compose file and all its services
docksec --compose docker-compose.yml
# Scan only an image
docksec --image-only -i myapp:latest
# Include medium-severity findings (default is CRITICAL,HIGH)
docksec -i myapp:latest --image-only --severity CRITICAL,HIGH,MEDIUM
# Choose report formats and output folder
docksec Dockerfile --scan-only --format json,html --output-dir ./reports
# Generate a CycloneDX SBOM of an image
docksec --image-only -i myapp:latest --sbom
# Fully offline scan: local Trivy database, no network, no AI
docksec --image-only -i myapp:latest --offline
```
## Managing findings over time
```bash
# Save today's findings as a baseline
docksec -i myapp:latest --image-only --baseline .docksec-baseline.json --update-baseline
# Later, fail only on new HIGH or above findings
docksec -i myapp:latest --image-only --baseline .docksec-baseline.json --fail-on high
# Suppress triaged findings with an auditable ignore file
docksec -i myapp:latest --image-only --ignore-file .docksec-ignore.yml
```
Waiver entries carry a reason and an expiry date, so accepted risks stay reviewable instead of being forgotten.
## Report formats
HTML, PDF, JSON, CSV, SARIF and CycloneDX SBOM.
## GitHub Action
```yaml
- name: Run DockSec
uses: OWASP/DockSec@v2026.8.19
with:
dockerfile: 'Dockerfile'
openai_api_key: ${{ secrets.OPENAI_API_KEY }}
```
## Gate your builds
DockSec uses CI-friendly exit codes. Exit code 0 means no findings at or above your threshold. Exit code 1 means findings at or above the --fail-on threshold.
```bash
# Fail the build on any HIGH or CRITICAL finding
docksec -i myapp:latest --image-only --fail-on high
# JSON to stdout for scripts and pipelines
docksec -i myapp:latest --image-only --json
# SARIF for GitHub Code Scanning
docksec Dockerfile --scan-only --sarif
```
## One policy for the whole team
Commit a .docksec.yml to the root of your repository so every developer and every CI job scans under the same rules:
```yaml
severity: CRITICAL,HIGH
fail_on: HIGH
formats: [json, html]
output_dir: ./security-reports
```
Ready-made templates for Jenkins, GitLab CI and Azure Pipelines are on the roadmap.
## Near term
- Scan images directly from registries (Artifactory, Harbor, ECR, Docker Hub) without a local Docker daemon
- Hadolint results as structured findings that work with --fail-on, JSON, SARIF and reports
- CI templates for Jenkins, GitLab CI and Azure Pipelines
- Official multi-arch container image with Trivy and Hadolint included
- Line-anchored AI findings for SARIF regions and pull request annotations
- Versioned JSON output with a published schema
- Parallel scanning of Compose services
## Later
- Kubernetes manifest and Helm chart scanning
- Policy packs mapped to the CIS Docker Benchmark and NIST SP 800-190
- Score and finding trends over time
- Pull request comment mode for the GitHub Action
- SPDX SBOM export
- Bundled offline vulnerability database for air-gapped installs
Priorities are shaped by user feedback. Full roadmap: https://github.com/OWASP/DockSec/blob/main/ROADMAP.md
Recently shipped work: https://github.com/OWASP/DockSec/blob/main/CHANGELOG.md
## Conference talks
- OWASP Global AppSec EU 2026, Vienna, June 26, 2026: "Hack Your Own Dockerfiles (Before Someone Else Does): Hands-On Container Security with OWASP DockSec" (workshop)
- OWASP Global AppSec USA 2026, San Francisco, November 2026: "DockSec: Closing the Gap Between What Your Scanner Finds and What You Actually Fix"
## Coverage
- SecurityWeek, May 26, 2026: "Open Source DockSec Uses AI to Cut Through Vulnerability Noise in Docker Images"
- Open Source For You, May 2026: "OWASP-Backed Open Source DockSec Uses LLMs To Fix Docker Vulnerabilities Faster"
- Help Net Security, June 2026: "DockSec: Open-source AI-powered Docker security scanner"
- 4sysops, June 2026: "DockSec combines AI with open-source scanners to automate Docker remediation"
- ISACA Podcast, July 30, 2026: "Your Containers Are Probably Full of Holes: Fixing Docker Security with AI"
## Research
- Zhang et al., "Repairing Docker Smells with Large Language Models," Applied Sciences (MDPI), vol. 16, no. 13, article 6805, July 2026
Project Creator & Lead
Advait Patel is the creator and project leader of OWASP DockSec. He is a Senior Site Reliability Engineer at Broadcom with nine years of experience in cloud infrastructure security, container security, and reliability engineering. He is a Docker Captain, a Google Developer Expert for Google Cloud, an IEEE Senior Member, and a founding member of the OWASP AI Vulnerability Scoring System (AIVSS). He is the author of two books on Google Cloud security published by Apress (Springer Nature) and speaks regularly at security conferences, including OWASP Global AppSec.