World Congress 2026 Europe Jul 10, 2026 Session details

Beyond SBOMs: The Future of Container Supply Chain Security

Mohammad-Ali A'râbi

Basic SBOMs can no longer stop self-propagating CI worms. Master advanced zero-trust pipelines and hardened image strategies to achieve ironclad container resilience.

Pause
Mute Enter Fullscreen
#1 about 3 min

Understanding software vulnerabilities and prominent exploits

How widespread vulnerabilities like Log4Shell and React2Shell drive the need for security improvements.

#2 about 3 min

Generating software bill of materials for container images

Using CLI tools like Syft to generate machine-readable SBOMs that list all structural dependencies of an application.

#3 about 1 min

Scanning Docker images for vulnerabilities with Docker Scout

Checking final container images for embedded vulnerabilities that originate from the base operating system.

#4 about 4 min

Creating SBOM attestations for multi-stage Docker builds

Attaching build-phase SBOMs to capture vulnerable dependencies that are discarded in the final image layer.

#5 about 6 min

Reducing vulnerability footprints with hardened Docker images

Dropping tools like package managers and shells to create base images with minimal initial vulnerabilities.

#6 about 2 min

Filtering unexploitable vulnerabilities using VEX attestations

Silencing irrelevant vulnerability alerts by creating records that mark specific issues as non-exploitable.

#7 about 2 min

Signing container images to prevent pipeline tampering

Using Cosign and OCI referrers to generate signatures that guarantee the integrity of production images.

#8 about 2 min

Continuous scanning for zero-day vulnerabilities in containers

Retrospectively checking existing SBOM attestations to catch newly discovered vulnerabilities in older base images.

#9 about 2 min

Securing build pipelines with the SLSA framework

Generating provenance metadata to track the build environment and history of a container image.

#10 about 4 min

Defending against automated supply chain worms

Identifying and mitigating malware families that infect maintainer environments to spread through package registries.

#11 about 3 min

A practical checklist for DevSecOps and container security

Implementing proactive strategies like version pinning, cool-down periods, and execution sandboxes to defend CI pipelines.

#12 about 2 min

Addressing zero-day exploits and alternative hardened images

Insights on managing exposure windows during active breaches and comparing different proprietary hardened image providers.

Matching moments

3:09 min

Practical mitigation strategies for modern software supply chains

Adrian Mouat Adrian Mouat · WWC Europe 2026

6:33 min

Integrating SAST and container security into developer workflows

Mathias Tausig · LIVE

2:46 min

Mapping the complete software supply chain attack surface

Matthew Brady Matthew Brady · WWC Europe 2026

1:55 min

Addressing base image vulnerabilities in application containers

Reinhard Kugler · LIVE

5:59 min

Live demonstration of vulnerability exploitation and zero trust mitigation

Jan Peer Stöcklmair Jan Peer Stöcklmair · WWC Europe 2026

4:02 min

Applying tactical security configurations to Docker container layers

Madhu Akula · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

rm -rf: Horror Stories From Unsandboxed AI Agents (and How Docker Fixes This)

Rishab Kumar

Staff Developer Evangelist @ Twilio

Rishab Kumar
Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

Your Threat Model Is Lying to You: Why Modeling the Design Isn’t Enough in 2026

Farshad Abasi

CEO/Founder, Eureka DevSecOps + Forward Security

Farshad Abasi
Open session

World Congress 2026 North America

Practical Threat Modeling for Software Developers

Mudassir Syed

Lead Security Software Engineer

Mudassir Syed
Open session

World Congress 2026 North America

Red Teaming Your LLM App -- A Hands-On Threat Model You Can Reuse

Saloni Garg

Senior ML Engineer at Adobe

Saloni Garg