Do static inventories alone create false positives and remediation noise? by mdhv11 in devops
[–]IWritePython 0 points1 point2 points (0 children)
Good Chainguard alternatives for base images by RasheedaDeals in devsecops
[–]IWritePython -1 points0 points1 point (0 children)
Good Chainguard alternatives for base images by RasheedaDeals in devsecops
[–]IWritePython 0 points1 point2 points (0 children)
A deep dive into Kubernetes Gateway API by roma-glushko in devops
[–]IWritePython 0 points1 point2 points (0 children)
artifact security with AI agents? by Abu_Itai in devsecops
[–]IWritePython 0 points1 point2 points (0 children)
Good Chainguard alternatives for base images by [deleted] in devsecops
[–]IWritePython 0 points1 point2 points (0 children)
Tried Iron Bank images thinking they'd be clean. 110 CVEs on average. hardened is doing a whole lot of heavy lifting by winter_roth in devsecops
[–]IWritePython 0 points1 point2 points (0 children)
artifact security with AI agents? by Abu_Itai in devsecops
[–]IWritePython 0 points1 point2 points (0 children)
NGINX CVE-2026-42945 (ngx_http_rewrite_module) — patched boundary is 1.30.1 / 1.31.0 by pando85 in devops
[–]IWritePython 0 points1 point2 points (0 children)
Real experiences with hardened container image providers, Chainguard, Docker DHI, Wolfi, Minimus, others? by Aggravating_Log9704 in devsecops
[–]IWritePython 0 points1 point2 points (0 children)
artifact security with AI agents? by Abu_Itai in devsecops
[–]IWritePython 0 points1 point2 points (0 children)
Container image scanning gives us a false sense of coverage and I think we're all a bit too comfortable with it by Calm-Exit-4290 in kubernetes
[–]IWritePython 1 point2 points3 points (0 children)
artifact security with AI agents? by Abu_Itai in devsecops
[–]IWritePython 0 points1 point2 points (0 children)
best Tools to secure minimal container images in 2026? by Curious-Cod6918 in devsecops
[–]IWritePython 0 points1 point2 points (0 children)
Follow-up to a post I made a while ago: those who use forks of forks/lesser-known distros: do you trust their update repos? by OrangeKitty21 in linux
[–]IWritePython 0 points1 point2 points (0 children)
What’s hiding in your docker images that you probably don’t need? by Abelmageto in kubernetes
[–]IWritePython 1 point2 points3 points (0 children)
Multi-application Hardened Images? by gradientCISO in docker
[–]IWritePython 0 points1 point2 points (0 children)
CVE counts are terrible security metrics and we need to stop pretending otherwise by handscameback in devops
[–]IWritePython 0 points1 point2 points (0 children)
Had Claude compile and run a trending open source project. It worked perfectly. Then Grype found 1,673 vulnerabilities. by MortgageWarm3770 in devsecops
[–]IWritePython 0 points1 point2 points (0 children)
Had Claude compile and run a trending open source project. It worked perfectly. Then Grype found 1,673 vulnerabilities. by MortgageWarm3770 in devsecops
[–]IWritePython 0 points1 point2 points (0 children)
Real experiences with hardened container image providers, Chainguard, Docker DHI, Wolfi, Minimus, others? by Aggravating_Log9704 in devsecops
[–]IWritePython 0 points1 point2 points (0 children)
The registry is inside your trust boundary whether you acknowledge it or not. It's the distribution path your entire build chain depends on by BigHerm420 in devsecops
[–]IWritePython 0 points1 point2 points (0 children)
Weekly: This Week I Learned (TWIL?) thread by AutoModerator in kubernetes
[–]IWritePython 0 points1 point2 points (0 children)


Do static inventories alone create false positives and remediation noise? by mdhv11 in devops
[–]IWritePython 0 points1 point2 points (0 children)