> Markdown version of [/events/world-congress-2026-europe/sessions/1266-beyond-sboms-the](https://www.wearedevelopers.com/events/world-congress-2026-europe/sessions/1266-beyond-sboms-the). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Beyond SBOMs: The Future of Container Supply Chain Security - **Date:** Friday, Jul 10, 2026 - **Time:** 11:00–11:30 (30 min) - **Room:** Stage 8 - powered by Red Hat - **Event:** World Congress 2026 Europe ## Recording [Watch recording](https://www.wearedevelopers.com/videos/100235-beyond-sboms-the-future-of-container-supply-chain-security) ## Description When a single phished NPM maintainer led to 18 compromised libraries—including Chalk and Debug, downloaded billions of times weekly—it proved one thing: SBOMs alone aren't enough. In this talk, Docker Captain Mohammad-Ali A'râbi explores how modern supply-chain attacks unfold and how the next generation of tools—attestations, provenance, and signing—can prevent a repeat of the September 2025 NPM breach. You'll learn how to build verifiable, trusted pipelines using Docker Scout, Syft, Cosign, and Rekor, and how to extend SBOMs with build-phase attestations. The session combines deep technical demos with hard-won lessons from the largest NPM attack ever—and insights from Mohammad-Ali's book "Docker and Kubernetes Security"—turning supply-chain horror stories into actionable DevSecOps practices. What you'll learn: - 🧠 Understand how the 2025 NPM supply-chain attack happened—and why traditional SBOMs couldn't stop it. - 📦 Pin & lock dependencies to prevent malicious updates from sneaking in. - 🧱 Generate, sign, and verify attestations using Docker Scout + Cosign + Rekor. - 🔒 Adopt zero-trust build pipelines with SLSA levels + OCI 1.1 referrers. - 🧰 Defend proactively with seven practical strategies: block lifecycle scripts, use hardware keys, and continuously scan with Snyk / Trivy / Scout. - 🚀 Turn compliance into confidence by making your entire container lifecycle verifiable. ## Speaker ### [Mohammad-Ali A'râbi](https://www.wearedevelopers.com/@mohammad-ali-a-rabi) Senior Software Engineer at JobRad ## Related talks at this congress - [Dockerize Java Securely: SBOMs + Attestations + Bake](https://www.wearedevelopers.com/events/world-congress-2026-europe/sessions/1337-dockerize-java) — Mohammad-Ali A'râbi - [From Build to Breach: Hacking Kubernetes Through the Supply Chain](https://www.wearedevelopers.com/events/world-congress-2026-europe/sessions/1210-from-build-to-breach) — Ali Alp - [Defending the Modern Supply Chain: Hands-On Vulnerability Remediation](https://www.wearedevelopers.com/events/world-congress-2026-europe/sessions/995-defending-the-modern) — Boy Baukema, Patrick Feige - [Building a Better Tomorrow: Tips and Tricks for Docker Builds](https://www.wearedevelopers.com/events/world-congress-2026-europe/sessions/1000-building-a-better) — Daniel Bodky