Blog

Latest insights on container security, SBOMs, and DevSecOps best practices.

Docker Security Dispatch — Issue 2: From JCON to Zurich 🏔️

Recapping JCON Europe, the Mini Shai-Hulud attack, an interview with Baruch Sadogursky, the 'Whispering JAR' in JAVAPRO, Foojay.io debut, Docker Sandboxes, and upcoming talks.

Featured
Mini Shai-Hulud: The Next Evolution of NPM Supply Chain Worms

A deep dive into the Mini Shai-Hulud attack, a sophisticated NPM worm that uses the Bun runtime to bypass security and targets developer agents for persistence.

Generating SBOM with Docker Scout
3 min read

Generating SBOM with Docker Scout

Am I vulnerable? That's the first question a CTO might ask in the case of a new CVE. To answer it, you need to know what's inside your container. SBOM is the word of the day. Especially, since EU Resilience Act makes it mandatory.

Docker Security Dispatch — Issue 1: Docker Turns 13 🎂

The first issue of Docker Security Dispatch: Docker's 13th birthday, the launch of Black Forest Shadow, a workshop at Rabobank, a JavaPro article, the best Docker book quarter in years, and what's next at JCON.

Featured
Dockerizing a Java 26 Project with Docker Init

Java 26 just landed. Here's how to Dockerize a Spring Boot project from scratch using Docker Init—the first move in the Docker Commandos playbook.

Featured
Docker Commandos v1.5: Asgard Mission
27 min read

Docker Commandos v1.5: Asgard Mission

Hands-on workshop materials for the 10 Docker Commandos at Rabobank, covering SBOM generation, CVE scanning, hardened images, VEX exemptions, Docker Bake, Cosign signing, and zero-day defense.

Featured
The Complete Docker Read List: Q1 2026 Edition

A curated reading list of the best books on Docker and Kubernetes for the first quarter of 2026, featuring releases from Docker Captains and industry experts.

Black Forest Commandos: The Rebranding of a Security Workshop
Updated 6 min read

Black Forest Commandos: The Rebranding of a Security Workshop

How Docker Commandos evolved into Black Forest Commandos, connecting the narrative-driven security workshop with the origin story in the Black Forest Shadows universe.

The Largest NPM Supply Chain Attack Ever and How to Defend Against It

Learn how to implement security best practices in multi-stage Docker builds, from source code to production images.

Docker Hardened Images are Free
2 min read

Docker Hardened Images are Free

Docker Hardened Images are now open-source under Apache 2.0 license and free to use in your projects.