World Congress 2026 Europe Jul 10, 2026 Session details

Beyond SBOMs: The Future of Container Supply Chain Security

Mohammad-Ali A'râbi

Basic SBOMs can no longer stop self-propagating CI worms. Master advanced zero-trust pipelines and hardened image strategies to achieve ironclad container resilience.

Pause
Mute Enter Fullscreen
#1 about 3 min

Understanding software vulnerabilities and prominent exploits

How widespread vulnerabilities like Log4Shell and React2Shell drive the need for security improvements.

#2 about 3 min

Generating software bill of materials for container images

Using CLI tools like Syft to generate machine-readable SBOMs that list all structural dependencies of an application.

#3 about 1 min

Scanning Docker images for vulnerabilities with Docker Scout

Checking final container images for embedded vulnerabilities that originate from the base operating system.

#4 about 4 min

Creating SBOM attestations for multi-stage Docker builds

Attaching build-phase SBOMs to capture vulnerable dependencies that are discarded in the final image layer.

#5 about 6 min

Reducing vulnerability footprints with hardened Docker images

Dropping tools like package managers and shells to create base images with minimal initial vulnerabilities.

#6 about 2 min

Filtering unexploitable vulnerabilities using VEX attestations

Silencing irrelevant vulnerability alerts by creating records that mark specific issues as non-exploitable.

#7 about 2 min

Signing container images to prevent pipeline tampering

Using Cosign and OCI referrers to generate signatures that guarantee the integrity of production images.

#8 about 2 min

Continuous scanning for zero-day vulnerabilities in containers

Retrospectively checking existing SBOM attestations to catch newly discovered vulnerabilities in older base images.

#9 about 2 min

Securing build pipelines with the SLSA framework

Generating provenance metadata to track the build environment and history of a container image.

#10 about 4 min

Defending against automated supply chain worms

Identifying and mitigating malware families that infect maintainer environments to spread through package registries.

#11 about 3 min

A practical checklist for DevSecOps and container security

Implementing proactive strategies like version pinning, cool-down periods, and execution sandboxes to defend CI pipelines.

#12 about 2 min

Addressing zero-day exploits and alternative hardened images

Insights on managing exposure windows during active breaches and comparing different proprietary hardened image providers.

Matching moments

3:09 min

Practical mitigation strategies for modern software supply chains

Adrian Mouat Adrian Mouat · World Congress 2026 Europe

6:33 min

Integrating SAST and container security into developer workflows

Mathias Tausig · LIVE

2:46 min

Mapping the complete software supply chain attack surface

Matthew Brady Matthew Brady · World Congress 2026 Europe

1:55 min

Addressing base image vulnerabilities in application containers

Reinhard Kugler · LIVE

5:59 min

Live demonstration of vulnerability exploitation and zero trust mitigation

Jan Peer Stöcklmair Jan Peer Stöcklmair · World Congress 2026 Europe

4:02 min

Applying tactical security configurations to Docker container layers

Madhu Akula · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 25, 2026 · 09:40–10:10

Stage 4

Your registry can't stop a valid login. What happens then?

Khushboo Verma

Systems Engineer at Cloudflare

Khushboo Verma
Open session

World Congress 2026 North America

September 24, 2026 · 11:40–12:10

Stage 3

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

September 23, 2026 · 15:45–17:45

Stage 10

Securing the Agentic Stack: Docker Hardened Images and Supply Chain Security

Ajeet Raina

Developer Advocate at Docker

Ajeet Raina
Open session

World Congress 2026 North America

September 25, 2026 · 12:30–14:30

Stage 13

Docker sandboxes: protect your secrets, tokens, and personal data from AI agent mistakes

Kristiyan Velkov

Developer Relations Engineer at Zerops.io

Kristiyan Velkov
Open session

World Congress 2026 North America

September 25, 2026 · 10:20–10:50

Stage 4

rm -rf: Horror Stories From Unsandboxed AI Agents (and How Docker Fixes This)

Rishab Kumar

Staff Developer Evangelist @ Twilio

Rishab Kumar
Open session

World Congress 2026 North America

September 23, 2026 · 11:00–11:30

Stage 1

Docker does that? Five Docker capabilities you did not know about

Ajeet Raina, Kristiyan Velkov

Ajeet Raina
Kristiyan Velkov