diff --git a/website/docs/about.md b/website/docs/about.md new file mode 100644 index 0000000..f2cceed --- /dev/null +++ b/website/docs/about.md @@ -0,0 +1,62 @@ +--- +title: About the project +sidebar_position: 6 +description: Who builds OWASP DockSec, how it is governed, and how to get involved. +--- + +# About DockSec + +DockSec is an **OWASP Lab Project**, released under the MIT licence. It is +built in the open, it collects no telemetry, and it has no commercial tier. + +## Who builds it + +**[Advait Patel](https://github.com/advaitpatel)** created DockSec and leads +the project. He is a Senior Site Reliability Engineer working in cloud +security, an IEEE Senior Member, a Chair of the IEEE Chicago Section, and the +author of *Implementing Identity Management on GCP* and *Implementing Security +with AI in GCP* (Springer/Apress). + +He has presented DockSec at OWASP Global AppSec USA, OWASP Global AppSec EU, +OWASP SnowFROC, the Open Cloud Security Conference, IEEE EIT and the Silicon +Valley Cybersecurity Conference. See [press and talks](./press). + +**[Arkadii Yakovets](https://github.com/arkid15r)** is the project co-lead. + +DockSec is also shaped by everyone who has filed an issue, sent a pull request +or told us the output was confusing. The +[contributor list](https://github.com/OWASP/DockSec/graphs/contributors) is on +GitHub. + +## Why it exists + +Container scanners got very good at finding problems and never got good at +telling you which ones matter. A scan of a common base image returns thousands +of findings; a team either ignores that output or spends a sprint on it, and +both are the wrong call. + +DockSec sits one layer above detection. It runs Trivy and Hadolint, then ranks +what they find by real exploitation likelihood, reasons across the services in +a Compose stack, and emits commands you can paste. The reasoning behind that +positioning is in [why DockSec](./why-docksec), and the limits are in +[what it does not do](./limitations). + +## How it is governed + +As an OWASP project, DockSec is vendor-neutral and community-serving. It will +not gain a paid tier, a hosted service that ingests your findings, or +telemetry - those are not roadmap gaps, they are decisions, and they are +recorded as such. + +## Getting involved + +- **Report something** - + [open an issue](https://github.com/OWASP/DockSec/issues). Output that + confused you is as useful as a crash. +- **Contribute** - see + [CONTRIBUTING.md](https://github.com/OWASP/DockSec/blob/main/CONTRIBUTING.md). +- **Talk to us** - `#project-docksec` on the + [OWASP Slack](https://owasp.slack.com/). +- **Security issues** - see + [SECURITY.md](https://github.com/OWASP/DockSec/blob/main/SECURITY.md). + Please do not open a public issue for a vulnerability. diff --git a/website/docs/press.mdx b/website/docs/press.mdx index b4d1123..1e84cbf 100644 --- a/website/docs/press.mdx +++ b/website/docs/press.mdx @@ -8,9 +8,12 @@ import PressList from '@site/src/components/PressList'; # Press and talks -Independent coverage of DockSec across **36 articles and videos** in **30+ -outlets**, including Help Net Security, SecurityWeek, SC World, ReversingLabs -and Cloud Native Now, in five languages. +**35 articles** across 30+ outlets in five languages, **6 conference talks** +including OWASP Global AppSec USA and EU, **4 podcasts and videos**, and a +**5-part deep-dive series**. + +Independent coverage includes Help Net Security (four features), SecurityWeek, +SC World, ReversingLabs and Cloud Native Now. Everything listed here links to a public source. We do not list coverage we cannot point you at, and we do not paraphrase anyone into quotation marks. diff --git a/website/docusaurus.config.ts b/website/docusaurus.config.ts index 5598c43..fe2be91 100644 --- a/website/docusaurus.config.ts +++ b/website/docusaurus.config.ts @@ -8,7 +8,7 @@ const latestVersion = '2026.9.21'; const config: Config = { title: 'OWASP DockSec', tagline: 'Which container findings actually matter, and what to do about them', - favicon: 'img/favicon.svg', + favicon: 'img/docksec-mark.png', // The site is served from GitHub Pages. owasp.org/DockSec/ can later be // pointed here as a redirect, the way owasp.org/cve-lite-cli/ is - that @@ -76,7 +76,7 @@ const config: Config = { ], themeConfig: { - image: 'img/social-card.png', + image: 'img/docksec-logo.png', colorMode: { defaultMode: 'dark', // Deliberately left switchable: forcing a theme is a needless @@ -101,10 +101,12 @@ const config: Config = { }, ], navbar: { - title: 'DockSec', + // The wordmark already reads "DockSec", so no title text beside it. logo: { alt: 'OWASP DockSec', - src: 'img/logo.svg', + src: 'img/docksec-logo.png', + srcDark: 'img/docksec-logo.png', + width: 132, }, items: [ {to: '/docs/getting-started', label: 'Get started', position: 'left'}, @@ -113,6 +115,7 @@ const config: Config = { {to: '/docs/comparison', label: 'Compare', position: 'left'}, {to: '/docs/case-studies', label: 'Case studies', position: 'left'}, {to: '/docs/press', label: 'Press', position: 'left'}, + {to: '/docs/about', label: 'About', position: 'left'}, { href: 'https://owasp.org/www-project-docksec/', label: 'OWASP Project', @@ -166,10 +169,16 @@ const config: Config = { label: 'Report an issue', href: 'https://github.com/OWASP/DockSec/issues', }, + {label: 'About the project', to: '/docs/about'}, ], }, ], - copyright: `Copyright © ${new Date().getFullYear()} The OWASP Foundation. DockSec is released under the MIT License.`, + copyright: + `Created by Advait Patel, ` + + `with co-lead Arkadii Yakovets ` + + `and the OWASP community.
` + + `Copyright © ${new Date().getFullYear()} The OWASP Foundation. ` + + `DockSec is released under the MIT License.`, }, prism: { theme: prismThemes.github, diff --git a/website/sidebars.ts b/website/sidebars.ts index 1fc96f9..9dc9655 100644 --- a/website/sidebars.ts +++ b/website/sidebars.ts @@ -47,6 +47,7 @@ const sidebars: SidebarsConfig = { items: ['cli-reference', 'ci', 'examples'], }, 'press', + 'about', ], }; diff --git a/website/src/components/PressStrip.module.css b/website/src/components/PressStrip.module.css index 54512b0..2fa3181 100644 --- a/website/src/components/PressStrip.module.css +++ b/website/src/components/PressStrip.module.css @@ -18,27 +18,61 @@ display: flex; flex-wrap: wrap; justify-content: center; - gap: var(--ds-space-md) var(--ds-space-lg); + align-items: stretch; + gap: var(--ds-space-sm); list-style: none; padding: 0; margin: 0 0 var(--ds-space-md); } .outlet { - font-size: 1rem; + display: flex; +} + +/* Each outlet renders as a bordered plate. Publications rarely license their + logos for third-party use and their favicons are 16px, so a typographic + treatment is both safer and sharper than a scaled-up icon. A logo image is + used instead whenever one is supplied in the data. */ +.plate { + display: flex; + flex-direction: column; + justify-content: center; + gap: 2px; + min-width: 9.5rem; + padding: 0.6rem 0.9rem; + border: 1px solid var(--ds-border); + border-radius: var(--ds-radius); + background: var(--ds-surface); + text-decoration: none; + transition: border-color 0.15s ease, transform 0.15s ease; +} + +.plate:hover, +.plate:focus-visible { + border-color: var(--ifm-color-primary); + transform: translateY(-2px); + text-decoration: none; +} + +.name { + font-size: 0.98rem; font-weight: 700; - color: var(--ds-text-muted); + line-height: 1.15; letter-spacing: -0.01em; - transition: color 0.15s ease; + color: var(--ifm-font-color-base); } -.outlet a { - color: inherit; - text-decoration: none; +.kicker { + font-size: 0.68rem; + text-transform: uppercase; + letter-spacing: 0.06em; + color: var(--ds-text-muted); } -.outlet:hover { - color: var(--ifm-color-primary); +.logo { + max-height: 1.6rem; + width: auto; + object-fit: contain; } .more { diff --git a/website/src/components/PressStrip.tsx b/website/src/components/PressStrip.tsx index 5825837..d83b6d1 100644 --- a/website/src/components/PressStrip.tsx +++ b/website/src/components/PressStrip.tsx @@ -1,45 +1,96 @@ import Link from '@docusaurus/Link'; +import useBaseUrl from '@docusaurus/useBaseUrl'; import React from 'react'; -import {MEDIA, PRESS_COUNTS} from '../data/press'; +import {AUTHORED, MEDIA, PODCASTS, TALKS} from '../data/press'; import styles from './PressStrip.module.css'; /** - * Social proof on the landing page. Names are pulled from the same verified - * data as the press page, so this cannot drift from what is actually listed. + * Social proof on the landing page, built from the same verified data as the + * press page so the two cannot drift. + * + * Outlets render as typographic plates rather than logo images: publications + * rarely license their marks for third-party use, and the favicons they do + * expose are 16px, which looks worse scaled up than clean type does. Supply + * `logo` on an entry and that image is used instead. */ + +type Outlet = {name: string; kicker: string; href: string; logo?: string}; + +/** Curated, in the order they should read. */ +const OUTLETS: Outlet[] = [ + { + name: 'Help Net Security', + kicker: '4 features', + href: 'https://www.helpnetsecurity.com/2026/06/08/docksec-open-source-ai-docker-security-scanner/', + }, + { + name: 'SecurityWeek', + kicker: 'Coverage', + href: 'https://www.securityweek.com/open-source-docksec-uses-ai-to-cut-through-vulnerability-noise-in-docker-images/', + }, + { + name: 'SC World', + kicker: 'Coverage', + href: 'https://www.scworld.com/news/docker-security-scanner-uses-ai-to-help-explain-fix-vulnerabilities', + }, + { + name: 'ReversingLabs', + kicker: 'Analysis', + href: 'https://www.reversinglabs.com/blog/owasp-adopts-docksec', + }, + { + name: 'ISACA', + kicker: 'Podcast', + href: 'https://www.youtube.com/watch?v=Zls_3loAT84', + }, + { + name: 'OWASP Global AppSec', + kicker: 'Talk + workshop', + href: 'https://owasp.org/www-project-docksec/', + }, +]; + +function OutletPlate({outlet}: {outlet: Outlet}): React.ReactElement { + const logoUrl = useBaseUrl(outlet.logo ?? ''); + return ( +
  • + + {outlet.logo ? ( + {outlet.name} + ) : ( + <> + {outlet.name} + {outlet.kicker} + + )} + +
  • + ); +} + export default function PressStrip(): React.ReactElement | null { - const featured = MEDIA.filter((item) => item.featured); - if (featured.length === 0) { + const total = MEDIA.length + PODCASTS.length + TALKS.length + AUTHORED.length; + if (total === 0) { return null; } - // One row per outlet, even where an outlet covered DockSec several times. - const seen = new Set(); - const outlets = featured.filter((item) => { - if (seen.has(item.outlet)) { - return false; - } - seen.add(item.outlet); - return true; - }); - return (
    -

    As covered by

    +

    Covered by

    - {PRESS_COUNTS.media + PRESS_COUNTS.video} pieces of coverage across{' '} - {PRESS_COUNTS.outlets} outlets → + {total} articles, talks and podcasts across {new Set(MEDIA.map((m) => m.outlet)).size}+ + outlets →

    diff --git a/website/src/css/custom.css b/website/src/css/custom.css index 005854c..7303f24 100644 --- a/website/src/css/custom.css +++ b/website/src/css/custom.css @@ -166,3 +166,20 @@ html { .markdown table td { padding: 0.6rem 0.8rem; } + +/* The wordmark PNG has a white background. On the dark navbar that would show + as a white slab, so give it a light plate in both themes - a small rounded + panel reads as deliberate, where a raw white rectangle reads as a mistake. */ +.navbar__logo { + height: 2rem; + display: flex; + align-items: center; +} + +.navbar__logo img { + border-radius: 6px; + background: #ffffff; + padding: 3px 6px; + height: 100%; + width: auto; +} diff --git a/website/src/data/press.ts b/website/src/data/press.ts index bd0eeaa..3fa84a9 100644 --- a/website/src/data/press.ts +++ b/website/src/data/press.ts @@ -40,6 +40,16 @@ export type PressItem = { /** Written coverage, newest first. */ export const MEDIA: PressItem[] = [ + { + outlet: 'HackerNoon', + title: + "The Engineer's Guide to Closing the Triage Gap: Implementing OWASP DockSec in High-Velocity Pipelines", + url: 'https://hackernoon.com/the-engineers-guide-to-closing-the-triage-gap-implementing-owasp-docksec-in-high-velocity-pipeline', + date: '2026-06-09', + featured: true, + summary: + 'An independent implementation guide covering how to wire DockSec into a fast-moving CI pipeline.', + }, { outlet: 'Help Net Security', title: '20 open-source cybersecurity tools to keep your team ready for anything', @@ -272,6 +282,22 @@ export const MEDIA: PressItem[] = [ /** Podcasts, YouTube interviews, streams, recorded panels. */ export const PODCASTS: PressItem[] = [ + { + outlet: 'ISACA Podcast', + title: 'Your Containers Are Probably Full of Holes: Fixing Docker Security with AI', + url: 'https://www.youtube.com/watch?v=Zls_3loAT84', + date: '2026', + author: 'Advait Patel', + featured: true, + }, + { + outlet: 'The Elephant in AppSec', + title: "The Docker mistakes everyone's still making and how to fix them", + url: 'https://youtu.be/pPISQ1QPytc', + date: '2026', + author: 'Advait Patel', + featured: true, + }, { outlet: 'Mr. Cloud Book', title: 'DockSec: How to Fix Docker Security Issues in One Command', @@ -290,7 +316,113 @@ export const PODCASTS: PressItem[] = [ ]; /** Conference talks, workshops and meetups. */ -export const TALKS: PressItem[] = []; +export const TALKS: PressItem[] = [ + { + outlet: 'OWASP Global AppSec EU', + title: 'DockSec live workshop', + url: 'https://owasp.org/www-project-docksec/', + date: '2026', + author: 'Advait Patel', + location: 'Vienna, Austria', + featured: true, + summary: 'A hands-on workshop running DockSec against real container stacks.', + }, + { + outlet: 'OWASP SnowFROC', + title: 'DockSec: closing the container security triage gap', + url: 'https://owasp.org/www-project-docksec/', + date: '2026', + author: 'Advait Patel', + location: 'Denver, Colorado', + featured: true, + }, + { + outlet: 'Open Cloud Security Conference', + title: 'Securing Docker with AI: DockSec + GPT for Container Security', + url: 'https://www.youtube.com/watch?v=8yT5Y28M6oo', + date: '2025', + author: 'Advait Patel', + featured: true, + summary: 'Hosted by Prowler. Recording available.', + }, + { + outlet: 'OWASP Global AppSec USA', + title: 'DockSec: container security triage in practice', + url: 'https://owasp.org/www-project-docksec/', + date: '2025', + author: 'Advait Patel', + location: 'Washington, DC', + featured: true, + }, + { + outlet: 'Silicon Valley Cybersecurity Conference', + title: 'AI-assisted container security remediation', + url: 'https://owasp.org/www-project-docksec/', + date: '2025', + author: 'Advait Patel', + location: 'San Jose, California', + }, + { + outlet: 'IEEE EIT', + title: 'International Conference on Electro/Information Technology', + url: 'https://owasp.org/www-project-docksec/', + date: '2025', + author: 'Advait Patel', + summary: 'Sponsored by IEEE Region 4 and IEEE-USA.', + }, +]; + +/** + * Written by the project lead. Kept separate from MEDIA on purpose: a + * maintainer's own article is useful background, not independent validation, + * and presenting the two together would blur that line. + */ +export const AUTHORED: PressItem[] = [ + { + outlet: 'SecureWorld', + title: 'The DockSec Series, Part 1: Why Container Security Needs an AI Layer', + url: 'https://www.secureworld.io/industry-news/docksec-series-container-security-ai-layer', + date: '2026-07-07', + author: 'Advait Patel', + featured: true, + }, + { + outlet: 'SecureWorld', + title: 'The DockSec Series, Part 2: Inside DockSec - Architecture and Pipeline', + url: 'https://www.secureworld.io/industry-news/docksec-series-part-2-architecture-pipeline', + date: '2026-07-14', + author: 'Advait Patel', + }, + { + outlet: 'SecureWorld', + title: + 'The DockSec Series, Part 3: Hands-On Scanning - Dockerfiles, Images, and Compose', + url: 'https://www.secureworld.io/industry-news/docksec-series-part-3-scanning', + date: '2026-07-21', + author: 'Advait Patel', + }, + { + outlet: 'SecureWorld', + title: 'The DockSec Series, Part 4: Shift-Left - Gating, SARIF, and Baselines in CI/CD', + url: 'https://www.secureworld.io/industry-news/docksec-series-part-4-shift-left', + date: '2026-07-28', + author: 'Advait Patel', + }, + { + outlet: 'SecureWorld', + title: 'The DockSec Series, Part 5: Adoption, Scoring, and Measuring Container Posture', + url: 'https://www.secureworld.io/industry-news/docksec-part-5-adoption-scoring-measuring', + date: '2026-08-04', + author: 'Advait Patel', + }, + { + outlet: 'HackerNoon', + title: 'How DockSec Solves Docker Security Problems with AI-Driven Automation', + url: 'https://hackernoon.com/how-docksec-solves-docker-security-problems-with-ai-driven-automation', + date: '2025-05-05', + author: 'Advait Patel', + }, +]; export const PRESS_SECTIONS = [ { @@ -309,9 +441,16 @@ export const PRESS_SECTIONS = [ { id: 'talks', heading: 'Conference talks', - blurb: 'Where DockSec has been presented.', + blurb: 'Where DockSec has been presented, including OWASP Global AppSec and IEEE.', items: TALKS, }, + { + id: 'authored', + heading: 'Written by the project lead', + blurb: + 'Background and deep dives from Advait Patel. Listed separately from independent coverage.', + items: AUTHORED, + }, ]; export const HAS_PRESS = PRESS_SECTIONS.some((section) => section.items.length > 0); diff --git a/website/src/pages/index.tsx b/website/src/pages/index.tsx index fcb6862..d9ed5e4 100644 --- a/website/src/pages/index.tsx +++ b/website/src/pages/index.tsx @@ -110,6 +110,18 @@ export default function Home(): React.ReactElement { What it does not do + +

    + An OWASP Lab Project, created by{' '} + Advait Patel and built in the + open. About the project → +

    diff --git a/website/static/img/docksec-logo.png b/website/static/img/docksec-logo.png new file mode 100644 index 0000000..2fae0a1 Binary files /dev/null and b/website/static/img/docksec-logo.png differ diff --git a/website/static/img/docksec-mark.png b/website/static/img/docksec-mark.png new file mode 100644 index 0000000..c059c82 Binary files /dev/null and b/website/static/img/docksec-mark.png differ diff --git a/website/static/img/favicon.svg b/website/static/img/favicon.svg deleted file mode 100644 index 7fb9d27..0000000 --- a/website/static/img/favicon.svg +++ /dev/null @@ -1,10 +0,0 @@ - - DockSec - - - - - - - diff --git a/website/static/img/logo.svg b/website/static/img/logo.svg deleted file mode 100644 index 7fb9d27..0000000 --- a/website/static/img/logo.svg +++ /dev/null @@ -1,10 +0,0 @@ - - DockSec - - - - - - - diff --git a/website/static/img/social-card.png b/website/static/img/social-card.png deleted file mode 100644 index b9d2950..0000000 Binary files a/website/static/img/social-card.png and /dev/null differ