Secure-Software-Supply-Chain

10 posts

Learn how Docker Hub and Docker Scout can help development teams ensure a more secure and compliant software supply chain.

Melissa Sussmann12/19/2024

Discover how Docker Scout integrates with secure container repositories to ensure vulnerability-free and compliant images in highly secure environments.

Jay Schmidt11/25/2024

The Docker team introduces Docker Scout health scores to help quickly evaluate image health and simplify software security for developers.

Tazin Progga7/30/2024

Docker Official Images are an important component of Docker's commitment to the security of both the software supply chain and open source software. We address three common misconceptions about Docker Official Images and outline seven ways they help secure the software supply chain.

David Dooling4/4/2024

Docker CTO Justin Cormack looks at what we can learn from malicious code in upstream tarballs of xz targeted at a subset of OpenSSH servers. "It is hard to overstate how lucky we were here, as there are no tools that will detect this vulnerability."

Justin Cormack4/1/2024

Docker is now providing a free Docker Scout Team subscription to all Docker-Sponsored Open Source (DSOS) program participants.

Ben Cotton1/25/2024

Learn how to use OpenPubkey to bind public keys to workload identities using GitHub Actions and Docker. And find out how Docker is using OpenPubkey with GitHub Actions to sign Docker Official Images and improve supply chain security.

Ethan Heilman12/21/2023

We show how Docker Scout policies enable teams to identify, prioritize, and fix their software quality issues at the point of creation.

Tazin Progga11/9/2023

We are excited to announce that Docker Scout General Availability (GA) now allows developers to continuously evaluate container images against a set of out-of-the-box policies, aligned with software supply chain best practices. These new capabilities also include a full suite of integrations enabling you to attain visibility from development into production. These updates strengthen Docker Scout’s position as integral to the software supply chain.

Docker Team10/4/2023

This post provides a quick introduction to the benefits of adopting a container-first model in your software development. Learn more by downloading our free Cracking the Code: Effectively Managing All of Those Applications whitepaper.

Ben Cotton8/14/2023