An OWASP incubator project is trying to turn crowded Docker-image vulnerability output into plain-English fixes and concrete Dockerfile changes.