software supply chain security
-
Aug 4, 2026
The Software Supply Chain Is Under Siege. Devs Are Still the First Line of Defense
77% of organizations experienced a software supply chain incident in the past year. Explore Omdia’s latest research on top risks, security gaps, and why developers are your first line of defense.
Read now
-
Jul 31, 2026
Docker OIDC connections for GitHub Actions available for Docker Orgs
Eliminate Stored Credentials in Your CI/CD Pipelines TL;DR: Docker now supports OpenID Connect (OIDC) for GitHub Actions. Your workflows can authenticate with short-lived, per-run tokens instead of stored PATs or OATs. No secrets to rotate, no credentials to leak. GitHub OIDC connections are available to organizations with Docker Team, Docker Business, or Docker Hardened Images…
Read now
-
Jun 25, 2026
EU Cyber Resilience Act: Overview, Requirements, and Timelines
Learn what the EU Cyber Resilience Act requires, including SBOM mandates, vulnerability reporting, and compliance deadlines for container teams.
Read now
-
Jun 23, 2026
What is an SBOM (and Why Can’t You Ship Without One)?
Learn what a software bill of materials (SBOM) is, why it matters for supply chain security, how to generate one, and what formats and standards to use.
Read now
-
Jun 8, 2026
5 Software Supply Chain Security Best Practices for Development Teams
Learn the key software supply chain security best practices for container-based delivery, from trusted base images and dependency management to build provenance and runtime monitoring.
Read now
-
Jun 4, 2026
Hardened Images Explained: Fewer CVEs, Smaller Attack Surface
Learn what hardened container images are, how they reduce CVE exposure by removing unnecessary packages, and why they’re becoming the standard for secure container deployments.
Read now
-
Jun 3, 2026
What is Software Supply Chain Security?
Learn what software supply chain security is, why it matters, and how to protect every stage of your software delivery pipeline with container-based infrastructure and trusted content.
Read now
-
Scanner Integrations May 5, 2026
Precision Container Security with Docker and Black Duck
The complexity of modern containerized applications often leaves developers drowning in a sea of “noise”—vulnerabilities that exist in the file system but pose zero actual risk to the application. The integration between Black Duck and Docker Hardened Images (DHI) provides a definitive answer to this challenge. By combining Docker’s secure-by-default foundations, using VEX (Vulnerability Exploitability…
Read now