- What: Docker security scanner uses AI to explain and fix vulnerabilities
- Impact: Developers can better understand and prioritize security issues
Application security , Container security Docker security scanner uses AI to help explain, fix vulnerabilities June 12, 2026 Share By Stephen Weigand (Adobe Stock) Frustrated by vulnerability scanners that routinely return hundreds of common vulnerabilities and exposures (CVEs), Advait Patel created DockSec, an AI-powered tool designed to help developers understand and prioritize security issues in plain English. Patel, who has a background in cloud security , container security and DevSecOps, said he noticed that developers often struggle to make sense of the overwhelming volume of findings generated by security tools scanning cloud environments, containers, Kubernetes deployments and other infrastructure. While those tools excel at identifying vulnerabilities, they often leave developers to sort through hundreds of CVEs on their own and determine which flaws pose the greatest risk. “That’s the gap we saw in the industry, and that’s where DockSec came from,” Patel said. DockSec builds on existing vulnerability-scanning tools such as Trivy, Hadolint and Docker Scout, which Patel said already do a good job of identifying security issues. The difference is that DockSec uses a large language model (LLM) to summarize findings, prioritize risk and explain remediation steps in a more accessible format. The platform can also generate reports in HTML, PDF, JSON and Markdown formats. Patel noted that only scan metadata is sent to the LLM, while container image contents remain local. What began as a personal project shared through GitHub has since gained broader recognition. Earlier this year, DockSec was accepted into the Open Worldwide Application Security Project’s (OWASP) incubator program, a milestone Patel said helped validate the project within the security community. DockSec has also been invited to appear at multiple international conferences, including the upcoming OWASP Global AppSec EU 2026 event. The project has attracted roughly 17,000 downloads on PyPI and 187 GitHub stars, and is now used by several companies. According to Patel, many of those users are startups that lack dedicated security teams and need help making vulnerability management more approachable. One example of a startup that integrated DockSec into their CI/CD pipelines shared with Patel that the number of CVEs reaching production fell from about 22 a month to roughly five, a 78% reduction, while the average time spent triaging a scan report went from about 45 minutes per image to roughly 6 minutes. Patel said OWASP’s decision to adopt DockSec as an incubator project was particularly important because it provided a level of community trust and credibility. Ultimately, he said, DockSec is not intended to replace existing security tools. Instead, its goal is to help developers and security teams work together more effectively by turning vulnerability remediation into a practical process rather than an overwhelming one. For more information on DockSec, please find Advait Patel on GitHub , the DockSec project on GitHub and the OWASP project page . Stephen Weigand Stephen Weigand is managing editor and production manager for SC Media. He has worked for news media in Washington, D.C., covering military and defense issues, as well as federal IT. He is based in the Seattle area. Related AI/ML Guardrails for agents: How to secure AI at runtime Paul Wagenseil June 8, 2026 Here's how identity security is becoming the enforcement layer for agentic AI. DevSecOps Why writing software has become dangerous today Zaid Al Hamami June 5, 2026 There’s just more code than ever and developers can’t verify everything – we need to make all that code understandable. Application security OWASP launches FinBot to help developers secure AI agents OWASP GenAI Security Project Team May 28, 2026 OWASP’s FinBot gives developers hands-on training to secure AI agents. Related Events Cybercast Bridging the Gap from CISO-Developed Tools to Black Hat Hype: What AI Security Leaders Should Watch Next Thu Jul 9 Cybercast Protecting Application User Data for Better Privacy, Governance, and Compliance On-Demand Event Cybercast The Next Evolution of Application Security: AI- Accelerated DevSecOps On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Active Content Banner Browser Cache Cramming Common Gateway Interface (CGI) Client Cookie DLL Injection Dynamic Link Library You can skip this ad in 5 seconds