# Your Containers Are Probably Full of Holes: Fixing Docker Security with AI Page: https://stenobird.com/podcast/isaca-podcast-599091/your-containers-are-probably-full-of-holes-fixing-docker-security-with-ai Text version: https://stenobird.com/podcast/isaca-podcast-599091/your-containers-are-probably-full-of-holes-fixing-docker-security-with-ai.md Podcast: [ISACA Podcast](https://stenobird.com/podcast/isaca-podcast-599091) Published: 2026-07-21T05:00:00+00:00 Episode link: https://isacapodcast.podbean.com/e/your-containers-are-probably-full-of-holes-fixing-docker-security-with-ai/ Audio file: https://mcdn.podbean.com/mf/web/gyvz4ncwjinmri5x/26_055_ISACA_Podcast_-_Advait_Patel_D19qnef.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/isaca-podcast-599091/episodes/your-containers-are-probably-full-of-holes-fixing-docker-security-with-ai Duration seconds: 1689 ## Resource Containers run much of the software we depend on, and many are shipped with security problems that no one noticed. Traditional container scanning tools can miss important vulnerabilities, insecure configurations, embedded secrets, and risky Dockerfile patterns before they reach production. In this episode, ISACA’s Adedayo Ojo, Principal, Emerging Technologies and Professional Practices, Research Development, speaks with Advait Patel, Senior Site Reliability Engineer at Broadcom, Docker Captain, and Google Developer Expert in Google Cloud, about why traditional container scanning misses so much and what it takes to identify the issues that matter most. Advait shares lessons from running containers at scale on a large cloud platform and explains how he built DockSec, an open-source tool that uses AI to identify insecure Dockerfile patterns, embedded secrets, and misconfigurations that signature-based scanners tend to overlook. The conversation offers practical guidance that developers and security teams can apply immediately, along with an honest look at where AI can strengthen container security—and where it cannot. Related Resources & Stay Connected Explore DockSec on GitHub: Review the open-source DockSec project, explore its features, and learn how it uses AI to identify insecure Dockerfile patterns, embedded secrets, and container misconfigurations.https://github.com/OWASP/DockSec Learn More About DockSec from OWASP: Discover more about the DockSec project, its approach to container security, and how it helps developers identify risks that traditional signature-based scanners may miss.https://owasp.org/DockSec/ Connect with Advait Patel on LinkedIn: Follow Advait for insights on container security, cloud infrastructure, site reliability engineering, Docker, and… ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/isaca-podcast-599091/episodes/your-containers-are-probably-full-of-holes-fixing-docker-security-with-ai/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/isaca-podcast-599091/your-containers-are-probably-full-of-holes-fixing-docker-security-with-ai.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.