{"id":4832,"date":"2026-08-17T13:01:00","date_gmt":"2026-08-17T13:01:00","guid":{"rendered":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/08\/17\/make-zero-cves-your-new-default\/"},"modified":"2026-08-17T13:01:00","modified_gmt":"2026-08-17T13:01:00","slug":"make-zero-cves-your-new-default","status":"publish","type":"post","link":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/08\/17\/make-zero-cves-your-new-default\/","title":{"rendered":"Make zero CVEs your new default"},"content":{"rendered":"<p class=\"wp-block-paragraph\"><em>Now in Docker AI Governance: a single searchable record of every policy decision your agents trigger, streamed to the SIEM your security team already runs, so you can show what your agents did and what your policy stopped.<\/em><\/p>\n<p class=\"wp-block-paragraph\">Today, Docker AI Governance now streams every policy decision in your organization into the SIEM your security team already runs, with a searchable record of all of it in Docker Cloud. You can see what your agents did, and what your policy stopped them from doing.<\/p>\n<h2 class=\"wp-block-ponyo-heading text-lg\">\n        Enforcement is step one<br \/>\n    <\/h2>\n<p class=\"wp-block-paragraph\">\n<\/p><p class=\"wp-block-paragraph\">Somewhere in the past year, supply-chain attacks stopped being isolated incidents. The compromises now reach the tools the industry trusts to defend itself, <a href=\"https:\/\/www.docker.com\/blog\/trivy-kics-and-the-shape-of-supply-chain-attacks-so-far-in-2026\/\">with Trivy and KICS among this year\u2019s targets<\/a>. Mark Lechner, Docker\u2019s Chief Information Security Officer, <a href=\"https:\/\/www.docker.com\/blog\/defending-your-software-supply-chain-what-every-engineering-team-should-do-now\/\">called the latest wave \u201ca permanent shift in the threat landscape\u201d<\/a>, and nothing since has argued with him. Meanwhile the volume keeps climbing. <a href=\"https:\/\/www.docker.com\/blog\/docker-sandboxes-run-agents-in-yolo-mode-safely\/\">Over a quarter of production code is now AI-authored<\/a>, and agents pull in dependencies at machine speed. If you run a platform team or a security program, you already know how this math feels. More code, more images, more dependencies, almost none of it written by your own engineers. And all of it becomes your responsibility the moment it ships.<\/p>\n<p class=\"wp-block-paragraph\">None of this is news to us. Securing the software supply chain is the problem we\u2019re here to solve, and our commitment to it is absolute. The latest round of updates widens the trusted foundation Docker is building under your supply chain, and tightens how it\u2019s enforced. More of the software inside your images is now built and patched by Docker itself. Security coverage continues after software reaches end of life. Images get tailored to your environment without losing their guarantees. And policy enforcement now reaches every developer machine. The details are below. First, where all of this is headed.<\/p>\n<h2 class=\"wp-block-ponyo-heading text-lg\">\n        <strong>A trusted foundation for the whole supply chain<\/strong>\n<\/h2>\n<figure class=\"wp-block-image size-full\"><img data-opt-id=693946574  fetchpriority=\"high\" decoding=\"async\" width=\"2300\" height=\"1474\" src=\"https:\/\/www.docker.com\/app\/uploads\/2026\/08\/Screenshot-2026-08-05-at-14-49-37-Hardened-Images-catalog-Docker-Hub.png\" alt=\"Screenshot 2026 08 05 at 14 49 37 Hardened Images catalog Docker Hub\" class=\"wp-image-92725\" title=\"- Screenshot 2026 08 05 at 14 49 37 Hardened Images catalog Docker Hub\" \/><\/figure>\n<p class=\"wp-block-paragraph\">\n<\/p><p class=\"wp-block-paragraph\">\n<\/p><p class=\"wp-block-paragraph\">It all starts from one principle, and Docker Hardened Images was built on it. Security that doesn\u2019t get adopted doesn\u2019t secure anything. The entire catalog is free for every developer, because a secure baseline shouldn\u2019t be a premium feature. Every image is compatible with Alpine and Debian, the distributions your teams already run, and Docker builds every one of them itself, from source. Adoption is a FROM-line change, not a migration project. And every image is independently verifiable, with signed SBOMs (software bills of materials) and SLSA Build Level 3 provenance, so your auditors work from evidence instead of vendor claims.<\/p>\n<p class=\"wp-block-paragraph\">A year in, <a href=\"https:\/\/www.docker.com\/blog\/why-we-chose-the-harder-path-docker-hardened-images-one-year-later\/\">the numbers make the case<\/a>. The <a href=\"https:\/\/hub.docker.com\/hardened-images\/catalog\" rel=\"nofollow noopener\" target=\"_blank\">catalog<\/a> has grown past 4,000 hardened images, plus MCP servers, Helm charts, and ELS images. It draws more than 3.5 million pulls a week, with over a million builds running regularly to keep all of it patched, and open source projects like <a href=\"https:\/\/www.docker.com\/resources\/how-n8n-uses-docker-hardened-images-webinar\/\">n8n run production on DHI<\/a>. The catalog grows the way it always has, driven by what customers request. But the goal was never just a catalog. The goal is one trusted foundation under your whole software supply chain, where the images you run, the packages inside them, the charts that deploy them, and the tools your agents call all carry the same provenance. Security becomes the default from day one, and it holds, without asking your teams to change how they work.<\/p>\n<p class=\"wp-block-paragraph\">Docker is leading that charge. Here\u2019s what that looks like in practice.<\/p>\n<h2 class=\"wp-block-ponyo-heading text-lg\">\n        Built from source, down to every package<br \/>\n    <\/h2>\n<p class=\"wp-block-paragraph\">\n<\/p><p class=\"wp-block-paragraph\">The hardening keeps reaching deeper into the stack. <a href=\"https:\/\/www.docker.com\/blog\/announcing-docker-hardened-system-packages\/\">Docker Hardened System Packages<\/a> take hardening below the image, to the packages inside it, across both Alpine and Debian, with every package built from upstream source, patched, and maintained by Docker in the same SLSA Build Level 3 pipeline that builds the images themselves. And the repository behind them is open to more than the catalog. DHI Enterprise customers can point apt or apk directly at Docker\u2019s hardened package repository and bring the same packages into images they build themselves, extending the hardened supply chain beyond the images Docker ships to every image your organization builds.<\/p>\n<p class=\"wp-block-paragraph\">The coverage keeps widening. What began with Alpine now spans Debian, with Python, the <a href=\"https:\/\/hub.docker.com\/hardened-images\/catalog\" rel=\"nofollow noopener\" target=\"_blank\">catalog\u2019s<\/a> most pulled image, among the first to ship fully hardened. The work compounds every week, and the <a href=\"https:\/\/dhi.io\/deb\/debian\/main\/index.html\" rel=\"nofollow noopener\" target=\"_blank\">Debian<\/a> and <a href=\"https:\/\/dhi.io\/apk\/alpine\/v3.24\/main\/index.html\" rel=\"nofollow noopener\" target=\"_blank\">Alpine<\/a> package lists are public, so you can watch the catalog harden in real time.<\/p>\n<p class=\"wp-block-paragraph\">If you\u2019ve spent time chasing base-image CVEs, you know why this matters. System packages are notorious for slow fixes; a patch can sit waiting on the distribution\u2019s next release for months or years. Docker doesn\u2019t wait. We patch at the package level, ahead of upstream when it counts, and the fix lands in every image that uses that package, in one build wave instead of image by image. Entire businesses have been built on delivering community-distribution security updates faster than the community. With DHI, that speed is included.<\/p>\n<p class=\"wp-block-paragraph\">The guarantees hold up under inspection, too. Packages you add through DHI customization, tailoring an image to your workloads, come from that same hardened repository, not an unverified public mirror, so they are hardened system packages in their own right and the SLA that covers the base image extends through everything you add. And because one vendor stands behind the image, the packages inside it, the CVE investigation, and the patch, your auditors get a single chain of signed provenance instead of a stack of vendor assurances.<\/p>\n<p class=\"wp-block-paragraph\">Your distribution, meanwhile, stays your distribution. Building a hardened package ecosystem from source is a serious engineering commitment, and Docker made it twice, for Alpine and for Debian, so keeping your house standard never costs you your security posture.<\/p>\n<h2 class=\"wp-block-ponyo-heading text-lg\">\n        Patch past end of life<br \/>\n    <\/h2>\n<figure class=\"wp-block-image size-full\"><img data-opt-id=966924625  fetchpriority=\"high\" decoding=\"async\" width=\"2300\" height=\"1474\" src=\"https:\/\/www.docker.com\/app\/uploads\/2026\/08\/Screenshot-2026-08-05-at-14-51-50-Hardened-Images-catalog-Docker-Hub.png\" alt=\"Screenshot 2026 08 05 at 14 51 50 Hardened Images catalog Docker Hub\" class=\"wp-image-92726\" title=\"- Screenshot 2026 08 05 at 14 51 50 Hardened Images catalog Docker Hub\" \/><\/figure>\n<p class=\"wp-block-paragraph\">\n<\/p><p class=\"wp-block-paragraph\">Production software has a habit of outliving its maintainers. Migrations wait on budgets, dependencies, and test cycles, and CVEs don\u2019t wait with them. That\u2019s the problem <a href=\"https:\/\/www.docker.com\/products\/hardened-images\/\">DHI Extended Lifecycle Support (ELS)<\/a> exists for. It keeps end-of-life software patched, with SBOMs and provenance maintained, for up to five more years.<\/p>\n<p class=\"wp-block-paragraph\">ELS isn\u2019t limited to a set catalog, either. Docker watches the end-of-life calendar and builds coverage ahead of it, and anything you don\u2019t see, you can request. MinIO is the newest addition. Upstream archived the project in February 2026, yet in the DHI catalog it lives on, patched and hardened, and your migration runs on your schedule instead of upstream\u2019s.<\/p>\n<h2 class=\"wp-block-ponyo-heading text-lg\">\n        Customize at scale, manage as code<br \/>\n    <\/h2>\n<p class=\"wp-block-paragraph\">\n<\/p><p class=\"wp-block-paragraph\">Nobody runs stock images in production. You add CA certificates, agents, and the packages your applications demand. The trouble is that in most of this market, the first change you make is where the vendor\u2019s guarantees end, and everything after it is yours to carry. <a href=\"https:\/\/docs.docker.com\/dhi\/how-to\/customize\/\" rel=\"nofollow noopener\" target=\"_blank\">DHI customization<\/a> works the other way around. You define what your images need, and Docker manages the full lifecycle of your customized images, rebuilding them through the same hardened pipeline on every upstream patch. The SBOM, the attestations, and the SLA travel with the customization instead of dying at it.<\/p>\n<p class=\"wp-block-paragraph\">Customization operates at scale, too. Bulk customizations run through the UI, CLI, and API, with YAML configuration and GitHub Actions support, so you can tailor hundreds of repositories in one pass and let the rebuilds take care of themselves. And if your platform runs on Terraform, customization is code as well. The <a href=\"https:\/\/registry.terraform.io\/providers\/docker-hardened-images\/dhi\/latest\" rel=\"nofollow noopener\" target=\"_blank\">DHI Terraform provider<\/a> mirrors and customizes hardened images with the same pull requests and reviews as the rest of your infrastructure.<\/p>\n<p class=\"wp-block-paragraph\">The savings are real infrastructure, not a rounding error. Customers tell us they\u2019ve shut off the CI pipelines that existed only to rebuild images, because Docker rebuilds for them. The blind redeploy cadence goes with those pipelines. You ship an update when a fix actually needs to go out, knowing exactly what changed, instead of rebuilding everything on a schedule and hoping QA catches what moved.<\/p>\n<p class=\"wp-block-paragraph\">For organizations whose data-residency requirements keep images inside the EU, EU-hosted customizations arrive in September. Your customized images will live in Docker Hub\u2019s EU region with the same SBOMs, attestations, and SLA as everywhere else. Residency stops being the reason your hardening program waits.<\/p>\n<h2 class=\"wp-block-ponyo-heading text-lg\">\n        Harden beyond base images<br \/>\n    <\/h2>\n<p class=\"wp-block-paragraph\">\n<\/p><p class=\"wp-block-paragraph\">The same standard keeps moving up the stack. The catalog now carries fully supported Helm charts, so your Kubernetes deployments start hardened too. And it carries a growing set of hardened MCP servers, because the tools your agents call deserve the same scrutiny as the images they run on.<\/p>\n<h2 class=\"wp-block-ponyo-heading text-lg\">\n        Govern it all with Docker Scout policy<br \/>\n    <\/h2>\n<p class=\"wp-block-paragraph\">\n<\/p><p class=\"wp-block-paragraph\">Scanning tells you what\u2019s wrong. Policy is how you keep it from shipping. And enforcement is where most supply-chain programs quietly fail, because hardened artifacts only protect you when your teams actually use them. Developers move fast and default to what works, and the developer machine is exactly where the current wave of attacks aims.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/docs.docker.com\/scout\/\" rel=\"nofollow noopener\" target=\"_blank\">Docker Scout<\/a> policy closes that gap. It evaluates flexible, customizable policies from the CLI and inside CI, and it ships with the same policies Docker uses to verify every hardened image in the catalog. The policies are written in Rego, the industry standard, and they\u2019re portable, so the same rules that gate a build in your CI travel with your teams to every developer machine in your organization. Gating at the registry matters, but it stops at the registry; developers can route around it all day. Policy that travels to the machine is how you hold every image you run, and every image your teams build, to the bar Docker holds itself to.<\/p>\n<p class=\"wp-block-paragraph\">It\u2019s an additive control. It works alongside the scanners you already run, and it\u2019s already in the Docker subscription you have.<\/p>\n<h2 class=\"wp-block-ponyo-heading text-lg\">\n        The foundation is already in your stack<br \/>\n    <\/h2>\n<p class=\"wp-block-paragraph\">\n<\/p><p class=\"wp-block-paragraph\">The supply-chain problem is not going to shrink. More code is coming, agents are becoming contributors, and the patch windows regulators expect keep getting shorter. Point tools won\u2019t carry that weight. A foundation that\u2019s secure by default will, backed by an ecosystem that keeps it that way. That is exactly what <a href=\"https:\/\/www.docker.com\/solutions\/security\/\">Docker\u2019s security portfolio<\/a> delivers. Hardened content on the distributions you already run, customization that keeps its guarantees, support that outlasts upstream, and policy you control, from one vendor accountable for all of it.<\/p>\n<p class=\"wp-block-paragraph\">And none of it asks you to adopt something new. It\u2019s all in the Docker you already run. Your builds, tools, and pipelines stay the same. Your CVE count doesn\u2019t.<\/p>\n<p class=\"wp-block-paragraph\">Browse the <a href=\"https:\/\/hub.docker.com\/hardened-images\/catalog\" rel=\"nofollow noopener\" target=\"_blank\">DHI catalog<\/a> and pull your first hardened image today. And if you want the full story, how all of this works together, with your questions answered live, join our live webinar in early September. We\u2019d love to see you there. [webinar registration link]<\/p>\n<p class=\"wp-block-paragraph\">\n<\/p>","protected":false},"excerpt":{"rendered":"<p>Now in Docker AI Governance: a single searchable record of every policy decision your agents trigger, streamed to the SIEM [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":4833,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[4],"tags":[],"class_list":["post-4832","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-docker"],"_links":{"self":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/4832","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/comments?post=4832"}],"version-history":[{"count":0,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/4832\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media\/4833"}],"wp:attachment":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media?parent=4832"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/categories?post=4832"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/tags?post=4832"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}