Skip to main content
Advait Patel

Advait Patel

Aug 4, 2026

4:02
So how did you actually like? To get started, how did you actually decide to open source what you've been working on?
4:10
Sure.
4:10
So whatever you shared about the project is exactly the correct point and exactly what it does and how it does.
4:18
But let me tell you, let me give you some context and background.
4:21
So actually, to be honest, DocSec was created out of frustration because I have been into the engineering side.
4:29
I mean, software development side.
4:32
And then all of a sudden we had an engineer who was looking at the security stuff.

11 MINS LATER

15:14
You don't have the same point of reference, but for developers, why do you think developers should kind of trust AI to recommend the security fixes or help them with scoring when kind of security teams themselves are a bit wary of even AI generated code?
3:16
Um, and just to understand more on a broader scale, uh, around specific, uh, um, use case, uh, what are some of the most common insecure Dockerfile, uh, patterns, uh, or embedded secrets and, uh, misconfiguration mistakes you've encountered over the years during your, uh, professional career, and why are they so, uh, frequently overlooked?
3:38
Sure.
3:39
So this is a very good question.
3:41
This is the very basic question that I get, uh, I, I, I... like, people ask me every time whenever I go to conferences.
3:48
Uh, doesn't matter if it is an industry or academic conferences, but this is the question I or anyone, uh, would frequently hear, right? So, uh, as a Docker Captain, uh, myself, and also being in this, working with this Docker technology for past couple of maybe, uh, past three to four years, uh, these are some of the things that I have seen which are very common and which are, like, for example, out of hundred Docker files or out of do- doc- hundred Docker images, if you scan, doesn't matter which tool that you are using, doesn't matter if it is, uh, AI-powered tool or non-AI powered tool, right? But for example, containers, uh, most majority of the containers are running as root.
4:29
So you are literally giving a key to your container so that it can, it can do anything.
4:36
Just imagine s- uh, something, an attacker comes into the picture and taking advantage of this root privilege escalation, right? So you're, now you are giving your container free hand, and if it goes to an attacker hand, then it can, they can do anything.

13 MINS LATER

18:18
Uh, where do you see AI genuinely improving security outcomes today, and what limitations should security leaders and practitioners keep in mind, uh, when adopting AI-powered security tools?

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.