04 Feb 2026
1h 16m

Setting Docker Hardened Images free (Changelog Interviews #675)

Podcast cover

Changelog Master Feed

Docker's initiative to provide free hardened container images is explored, addressing the increasing threat of supply chain attacks. Tushar Jain, EVP of Engineering at Docker, explains the move from a paid product to a largely free offering, emphasizing the ethos of broad community access and secure starting points for developers. Docker Hardened Images include SBOMs, SLSA build pipeline, and cryptographic signing, while enterprise features like SLAs and FIPS images remain paid. The discussion covers the tension between usability and security, the importance of transparency through VEX statements, and the long-term vision of securing the entire software supply chain. Future plans involve hardened system and language packages, secure build pipelines, and AI-driven agents to aid migration and security management.

Outlines

Part 1: Introduction, Context

Part 2: Docker Hardened Images (DHI) Deep Dive

Part 3: Industry Impact, Strategy

Part 4: Vulnerability Management, Transparency

Part 5: Ecosystem, Implementation

Part 6: Principles, Future Vision

Part 7: AI, Next-Gen Security

Part 8: Conclusion, Wrap-up

Sign in to continue reading, translating and more.

Continue
 
mindmap screenshot
Preview
preview episode cover
How to Get Rich: Every EpisodeNaval