Skip to main content

DockerDNA

Layer-by-Layer Container Security DNA Analysis

CI Python 3.11+ License: MIT CIS Docker Benchmark

DockerDNA is an open-source container security scanner focused on pre-build analysis: layer-by-layer Dockerfile attribution, docker-compose.yml auditing, CIS-mapped findings, dual-mode secret detection (regex + Shannon entropy), supply-chain risk scoring, SARIF, and CycloneDX output. It's designed to complement tools like OWASP DockSec, Trivy, and Hadolint, not replace them.


What Makes DockerDNA Unique

Verified against each project's public documentation, September 2026. Tools evolve quickly - always check upstream docs before relying on this. "not documented" means the capability could not be confirmed either way, not that it's absent.

Capability DockerDNA DockSec Trivy Hadolint
Dockerfile security scan YES YES partial (image/IaC scan) YES
docker-compose.yml scanner YES YES not documented NO
Secrets detection YES (regex + entropy) YES (via Trivy) YES (regex, built-in rules) NO
Entropy detection for unknown secrets YES not documented NO (regex-only) NO
CIS Docker Benchmark control-ID mapping YES not documented NO NO
SBOM (CycloneDX) YES YES YES NO
SARIF output YES YES YES NO
Supply chain image risk scoring YES not documented partial (CVE-based) NO
Multi-stage build secret leak detection YES not documented NO NO
CI/CD threshold gate YES (--threshold) YES (--fail-on) YES NO
AI-powered remediation YES (Claude) YES (multi-LLM) NO NO
Layer-by-layer attribution YES not documented NO NO

Core Differentiators

1. Secrets Detection (Regex + Shannon Entropy)

DockerDNA scans Dockerfiles, docker-compose.yml, .env files, and any project file for:

  • 20+ known secret formats (AWS keys, GitHub tokens, Google API keys, JWT, database URIs, ...)
  • High-entropy string analysis using Shannon entropy - catches unknown credential formats that regex misses
[CRITICAL] CIS-4.10 Dockerfile line 5: AWS Access Key ID detected (method: pattern)
[HIGH]     CIS-4.10 .env line 12: High-Entropy String detected (entropy: 5.21, method: entropy)

2. docker-compose.yml Security Scanner

Audits docker-compose files and maps every finding to a specific CIS Docker Benchmark control ID:

[CRITICAL] CIS-5.4  webapp: Privileged mode enabled
[CRITICAL] CIS-5.13 webapp: Docker socket mounted: /var/run/docker.sock
[HIGH]     CIS-5.9  webapp: network_mode: host
[HIGH]     CIS-5.3  webapp: Dangerous capabilities added: ['ALL']
[MEDIUM]   CIS-5.12 webapp: read_only not set to true

3. CIS Docker Benchmark v1.6 Compliance Report

Every finding is tagged with its CIS control ID. A full scorecard is generated:

CIS Controls: 14 passed / 8 failed / 2 not-checked
Compliance Score: 63.6%

4. Supply Chain Risk Scoring

Each FROM instruction receives a 0-100 risk score based on:

  • Registry trust (official vs community vs self-hosted)
  • Tag specificity (digest > version > :latest)
  • Docker Content Trust status
  • Known malicious image name patterns

5. SARIF Output for GitHub Security Tab

Findings appear as inline PR annotations in the GitHub Security tab - no additional integration needed.

6. CycloneDX SBOM Generation

Parses every package install instruction (apt-get, pip, npm, apk, yum) to produce a CycloneDX 1.5 SBOM with PURL identifiers and layer attribution.


Quick Start

# Not on PyPI yet — install from source for now
pip install git+https://github.com/sunilgentyala/DockerDNA.git

# Scan a Dockerfile
dockerdna Dockerfile

# Scan Dockerfile + docker-compose
dockerdna Dockerfile --compose docker-compose.yml

# Scan entire project directory
dockerdna --dir ./myapp

# All output formats
dockerdna Dockerfile --compose docker-compose.yml --format json html sarif sbom

# CI/CD gate: fail if any HIGH or above
dockerdna Dockerfile --threshold HIGH

# AI-powered remediation (requires ANTHROPIC_API_KEY)
dockerdna Dockerfile --compose docker-compose.yml --ai

Output is written to ./dockerdna-results/ by default.


GitHub Actions Integration

# .github/workflows/security.yml
name: Container Security

on: [push, pull_request]

jobs:
  dockerdna:
    runs-on: ubuntu-latest
    permissions:
      security-events: write

    steps:
      - uses: actions/checkout@v4
      - run: pip install git+https://github.com/sunilgentyala/DockerDNA.git

      - name: Run DockerDNA
        run: |
          dockerdna Dockerfile \
            --compose docker-compose.yml \
            --format sarif json \
            --threshold HIGH \
            --output dockerdna-results

      - name: Upload to GitHub Security tab
        uses: github/codeql-action/upload-sarif@v3
        if: always()
        with:
          sarif_file: dockerdna-results/report.sarif

Output Formats

Format File Description
json report.json Full structured report with all findings, compliance, and SBOM
html report.html Interactive dashboard with severity badges and CIS scorecard
sarif report.sarif SARIF 2.1.0 for GitHub Advanced Security integration
sbom sbom.cyclonedx.json CycloneDX 1.5 Software Bill of Materials

How It Works

┌────────────────────────────────────────────────────────┐
│                     DockerDNA Pipeline                  │
├──────────────┬──────────────┬─────────────┬────────────┤
│  Dockerfile  │   Compose    │   Secrets   │  Supply    │
│  Scanner     │   Scanner    │   Engine    │  Chain     │
│  (CIS 4.x)   │   (CIS 5.x)  │  Regex +    │  Scoring   │
│              │              │  Entropy    │            │
└──────┬───────┴──────┬───────┴──────┬──────┴─────┬──────┘
       │              │              │            │
       └──────────────┴──────────────┴────────────┘
                              │
                    ┌─────────▼─────────┐
                    │  CIS Compliance   │
                    │  Mapper           │
                    └─────────┬─────────┘
                              │
              ┌───────────────┼───────────────┐
              ▼               ▼               ▼
           JSON/HTML        SARIF           SBOM
           Reports      (GitHub Security)  (CycloneDX)
              │
              ▼ (optional)
        AI Remediation
        (Anthropic Claude)

Comparison with OWASP DockSec

DockSec wraps Trivy, Hadolint, and Docker Scout with multi-LLM AI explanations and automated patching, and (per its current docs, checked September 2026) also covers docker-compose scanning, SARIF, SBOM, and a --fail-on CI gate. DockerDNA focuses specifically on pre-build analysis with a few things not documented elsewhere:

  • Entropy-based secret detection. DockSec's secret handling isn't publicly documented beyond redaction; Trivy (which DockSec wraps) is regex-only. DockerDNA's dual-mode scanner (pattern + Shannon entropy) also catches custom or rotated credentials that match no known pattern.
  • CIS Docker Benchmark control-ID mapping. Every finding is tagged with its specific CIS v1.6 control ID and rolled into a pass/fail/not-checked compliance scorecard, not just a severity bucket.
  • Layer-by-layer attribution. Every finding traces back to the exact instruction and build stage that introduced it, including secrets that leak across multi-stage builds.

If you already use DockSec for its AI-powered explanations and automated Dockerfile patching, DockerDNA is a good complement for pre-build compose/secrets/compliance analysis, not a replacement.


Installation

# Core (no AI) — not on PyPI yet, install from source
pip install git+https://github.com/sunilgentyala/DockerDNA.git

# With AI remediation
pip install "dockerdna[ai] @ git+https://github.com/sunilgentyala/DockerDNA.git"

# Development
git clone https://github.com/sunilgentyala/DockerDNA.git
cd DockerDNA
pip install -e ".[dev]"
pytest

Environment Variables

Variable Description
ANTHROPIC_API_KEY Required for --ai flag (AI remediation)
DOCKER_CONTENT_TRUST Set to 1 to enable image signing verification

Contributing

See CONTRIBUTING.md to get set up, CHANGELOG.md for what's changed and what's on the roadmap, and SECURITY.md to report a vulnerability (please don't file those as a public issue). This project follows the Contributor Covenant.

License

MIT License. See LICENSE.

Author

Sunil Gentyala, Independent Researcher IEEE senior Member | Security Researcher

Release files for dockerdna 1.0.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for dockerdna 1.0.2
File Size Uploaded
dockerdna-1.0.2.tar.gz 37.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for dockerdna 1.0.2
File Interpreter ABI Platform
dockerdna-1.0.2-py3-none-any.whl Python 3 none any Details

Total release size: 74.1 kB

Release files / dockerdna-1.0.2.tar.gz

Download URL dockerdna-1.0.2.tar.gz
Size 37.0 kB
Tags Source
SHA-256 checksum
How to use checksums
fd515cc47baceb1e6f6ba245a23d4a73d98f96f487761d71bc2fed2ed9a963a3
BLAKE2b-256 checksum
How to use checksums
6320ccd79f776a06e4450a071e977394234515fd0824409f67427051ff0f2e06
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.

Transparency log

Release files / dockerdna-1.0.2-py3-none-any.whl

Download URL dockerdna-1.0.2-py3-none-any.whl
Size 37.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
286691232ba5d39b3d960e8122e6f0a9018960162cd5cfa6fb8102f25287046f
BLAKE2b-256 checksum
How to use checksums
67aaeaa532d9b5c65b84a5cc98790cdf78a29d7614fac03bb9106ced5a5d5067
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.

Transparency log

Release history Release notifications | RSS feed

1.0.6

2 release files

1.0.5

2 release files

1.0.4

2 release files

1.0.3

2 release files

This release

1.0.2 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page