Skip to main content

DockerDNA

Layer-by-Layer Container Security DNA Analysis

CI Python 3.11+ License: MIT CIS Docker Benchmark

DockerDNA is an open-source container security scanner focused on pre-build analysis: layer-by-layer Dockerfile attribution, docker-compose.yml auditing, CIS-mapped findings, dual-mode secret detection (regex + Shannon entropy), supply-chain risk scoring, SARIF, and CycloneDX output. It's designed to complement tools like OWASP DockSec, Trivy, and Hadolint, not replace them.


What Makes DockerDNA Unique

Verified against each project's public documentation, September 2026. Tools evolve quickly - always check upstream docs before relying on this. "not documented" means the capability could not be confirmed either way, not that it's absent.

Capability DockerDNA DockSec Trivy Hadolint
Dockerfile security scan YES YES partial (image/IaC scan) YES
docker-compose.yml scanner YES YES not documented NO
Secrets detection YES (regex + entropy) YES (via Trivy) YES (regex, built-in rules) NO
Entropy detection for unknown secrets YES not documented NO (regex-only) NO
CIS Docker Benchmark control-ID mapping YES not documented NO NO
SBOM (CycloneDX) YES YES YES NO
SARIF output YES YES YES NO
Supply chain image risk scoring YES not documented partial (CVE-based) NO
Multi-stage build secret leak detection YES not documented NO NO
CI/CD threshold gate YES (--threshold) YES (--fail-on) YES NO
AI-powered remediation YES (Claude) YES (multi-LLM) NO NO
Layer-by-layer attribution YES not documented NO NO

Core Differentiators

1. Secrets Detection (Regex + Shannon Entropy)

DockerDNA scans Dockerfiles, docker-compose.yml, .env files, and any project file for:

  • 20+ known secret formats (AWS keys, GitHub tokens, Google API keys, JWT, database URIs, ...)
  • High-entropy string analysis using Shannon entropy - catches unknown credential formats that regex misses
[CRITICAL] CIS-4.10 Dockerfile line 5: AWS Access Key ID detected (method: pattern)
[HIGH]     CIS-4.10 .env line 12: High-Entropy String detected (entropy: 5.21, method: entropy)

2. docker-compose.yml Security Scanner

Audits docker-compose files and maps every finding to a specific CIS Docker Benchmark control ID:

[CRITICAL] CIS-5.4  webapp: Privileged mode enabled
[CRITICAL] CIS-5.13 webapp: Docker socket mounted: /var/run/docker.sock
[HIGH]     CIS-5.9  webapp: network_mode: host
[HIGH]     CIS-5.3  webapp: Dangerous capabilities added: ['ALL']
[MEDIUM]   CIS-5.12 webapp: read_only not set to true

3. CIS Docker Benchmark v1.6 Compliance Report

Every finding is tagged with its CIS control ID. A full scorecard is generated — real output from examples/Dockerfile.secure + examples/docker-compose.secure.yml:

CIS Controls: 19 passed / 1 failed / 4 not-checked
Compliance Score: 95.0%

4. Supply Chain Risk Scoring

Each FROM instruction receives a 0-100 risk score based on:

  • Registry trust (official vs community vs self-hosted)
  • Tag specificity (digest > version > :latest)
  • Docker Content Trust status
  • Known malicious image name patterns

5. SARIF Output for GitHub Security Tab

Findings appear as inline PR annotations in the GitHub Security tab - no additional integration needed.

6. CycloneDX SBOM Generation

Parses every package install instruction (apt-get, pip, npm, apk, yum) to produce a CycloneDX 1.5 SBOM with PURL identifiers and layer attribution.


Quick Start

pip install dockerdna

# Scan a Dockerfile
dockerdna Dockerfile

# Scan Dockerfile + docker-compose
dockerdna Dockerfile --compose docker-compose.yml

# Scan entire project directory
dockerdna --dir ./myapp

# All output formats
dockerdna Dockerfile --compose docker-compose.yml --format json html sarif sbom

# CI/CD gate: fail if any HIGH or above
dockerdna Dockerfile --threshold HIGH

# AI-powered remediation (requires ANTHROPIC_API_KEY)
dockerdna Dockerfile --compose docker-compose.yml --ai

Output is written to ./dockerdna-results/ by default.


GitHub Actions Integration

# .github/workflows/security.yml
name: Container Security

on: [push, pull_request]

jobs:
  dockerdna:
    runs-on: ubuntu-latest
    permissions:
      security-events: write

    steps:
      - uses: actions/checkout@v4
      - run: pip install dockerdna

      - name: Run DockerDNA
        run: |
          dockerdna Dockerfile \
            --compose docker-compose.yml \
            --format sarif json \
            --threshold HIGH \
            --output dockerdna-results

      - name: Upload to GitHub Security tab
        uses: github/codeql-action/upload-sarif@v3
        if: always()
        with:
          sarif_file: dockerdna-results/report.sarif

Output Formats

Format File Description
json report.json Full structured report with all findings, compliance, and SBOM
html report.html Interactive dashboard with severity badges and CIS scorecard
sarif report.sarif SARIF 2.1.0 for GitHub Advanced Security integration
sbom sbom.cyclonedx.json CycloneDX 1.5 Software Bill of Materials

How It Works

┌────────────────────────────────────────────────────────┐
│                     DockerDNA Pipeline                  │
├──────────────┬──────────────┬─────────────┬────────────┤
│  Dockerfile  │   Compose    │   Secrets   │  Supply    │
│  Scanner     │   Scanner    │   Engine    │  Chain     │
│  (CIS 4.x)   │   (CIS 5.x)  │  Regex +    │  Scoring   │
│              │              │  Entropy    │            │
└──────┬───────┴──────┬───────┴──────┬──────┴─────┬──────┘
       │              │              │            │
       └──────────────┴──────────────┴────────────┘
                              │
                    ┌─────────▼─────────┐
                    │  CIS Compliance   │
                    │  Mapper           │
                    └─────────┬─────────┘
                              │
              ┌───────────────┼───────────────┐
              ▼               ▼               ▼
           JSON/HTML        SARIF           SBOM
           Reports      (GitHub Security)  (CycloneDX)
              │
              ▼ (optional)
        AI Remediation
        (Anthropic Claude)

Comparison with OWASP DockSec

DockSec wraps Trivy, Hadolint, and Docker Scout with multi-LLM AI explanations and automated patching, and (per its current docs, checked September 2026) also covers docker-compose scanning, SARIF, SBOM, and a --fail-on CI gate. DockerDNA focuses specifically on pre-build analysis with a few things not documented elsewhere:

  • Entropy-based secret detection. DockSec's secret handling isn't publicly documented beyond redaction; Trivy (which DockSec wraps) is regex-only. DockerDNA's dual-mode scanner (pattern + Shannon entropy) also catches custom or rotated credentials that match no known pattern.
  • CIS Docker Benchmark control-ID mapping. Every finding is tagged with its specific CIS v1.6 control ID and rolled into a pass/fail/not-checked compliance scorecard, not just a severity bucket.
  • Layer-by-layer attribution. Every finding traces back to the exact instruction and build stage that introduced it, including secrets that leak across multi-stage builds.

If you already use DockSec for its AI-powered explanations and automated Dockerfile patching, DockerDNA is a good complement for pre-build compose/secrets/compliance analysis, not a replacement.


Installation

# Core (no AI)
pip install dockerdna

# With AI remediation
pip install "dockerdna[ai]"

# Development
git clone https://github.com/sunilgentyala/DockerDNA.git
cd DockerDNA
pip install -e ".[dev]"
pytest

Environment Variables

Variable Description
ANTHROPIC_API_KEY Required for --ai flag (AI remediation)
DOCKER_CONTENT_TRUST Set to 1 to enable image signing verification

Contributing

See CONTRIBUTING.md to get set up, CHANGELOG.md for what's changed and what's on the roadmap, and SECURITY.md to report a vulnerability (please don't file those as a public issue). This project follows the Contributor Covenant.

License

MIT License. See LICENSE.

Author

Sunil Gentyala, Independent Researcher IEEE senior Member | Security Researcher

Release files for dockerdna 1.0.4

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for dockerdna 1.0.4
File Size Uploaded
dockerdna-1.0.4.tar.gz 37.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for dockerdna 1.0.4
File Interpreter ABI Platform
dockerdna-1.0.4-py3-none-any.whl Python 3 none any Details

Total release size: 74.1 kB

Release files / dockerdna-1.0.4.tar.gz

Download URL dockerdna-1.0.4.tar.gz
Size 37.0 kB
Tags Source
SHA-256 checksum
How to use checksums
45acc1930516a16c2e9a193705216c2b9ed4ece0d94709800c99a123b24991e0
BLAKE2b-256 checksum
How to use checksums
73708662d2050b3fa854e65121722765b096b562feaf3c75f17f4e3914da6a8c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.

Transparency log

Release files / dockerdna-1.0.4-py3-none-any.whl

Download URL dockerdna-1.0.4-py3-none-any.whl
Size 37.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
250b930c36a0bdf3a87fb70f89ec985d928c22f854d927ee3fa691ece92580b9
BLAKE2b-256 checksum
How to use checksums
b8e653c5e1cb87245f1f4813094830a009d70bbb892294fa3ad94b4fbe068595
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.

Transparency log

Release history Release notifications | RSS feed

1.0.6

2 release files

1.0.5

2 release files

This release

1.0.4 This release

2 release files

1.0.3

2 release files

1.0.2

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page