Secure-Software-Supply-Chain
10 postsLearn how Docker Hub and Docker Scout can help development teams ensure a more secure and compliant software supply chain.
Discover how Docker Scout integrates with secure container repositories to ensure vulnerability-free and compliant images in highly secure environments.
The Docker team introduces Docker Scout health scores to help quickly evaluate image health and simplify software security for developers.
Docker Official Images are an important component of Docker's commitment to the security of both the software supply chain and open source software. We address three common misconceptions about Docker Official Images and outline seven ways they help secure the software supply chain.
Docker CTO Justin Cormack looks at what we can learn from malicious code in upstream tarballs of xz targeted at a subset of OpenSSH servers. "It is hard to overstate how lucky we were here, as there are no tools that will detect this vulnerability."
Docker is now providing a free Docker Scout Team subscription to all Docker-Sponsored Open Source (DSOS) program participants.
Learn how to use OpenPubkey to bind public keys to workload identities using GitHub Actions and Docker. And find out how Docker is using OpenPubkey with GitHub Actions to sign Docker Official Images and improve supply chain security.
We show how Docker Scout policies enable teams to identify, prioritize, and fix their software quality issues at the point of creation.
We are excited to announce that Docker Scout General Availability (GA) now allows developers to continuously evaluate container images against a set of out-of-the-box policies, aligned with software supply chain best practices. These new capabilities also include a full suite of integrations enabling you to attain visibility from development into production. These updates strengthen Docker Scout’s position as integral to the software supply chain.
This post provides a quick introduction to the benefits of adopting a container-first model in your software development. Learn more by downloading our free Cracking the Code: Effectively Managing All of Those Applications whitepaper.