OWASP DockSec v2026.9.21 Released
By SecBurg
DockSec is an OWASP Lab Project combining scanners like Trivy, Hadolint, and Docker Scout with multi-LLM support to turn Docker security scan results into actionable, plain-English fixes.
v2026.9.21 is a quick follow-up to yesterday’s big v2026.9.20 release, which shipped the deterministic core, AI correlation and --fix command. This one mops up defects found while end-to-end testing that release and rounds out test coverage.
Fixes
Defects found by end-to-end testing of 2026.9.20
Compose service scan failure surfacing (per-service summary)
Connection-string password masking in redacted output
Compose exit codes, config formats, path validation
Additions
Golden-file tests, ten worked examples, case studies
PR comment mode
CodeQL scanning added to CI, hardened example pins refreshed
Full release notes and complete changelog: v2026.9.21
Happy scanning! :-)