container-security
Safeguard articles tagged "container-security" — guides, analysis, and best practices for software supply chain and application security.
100 articles
The Kubernetes Token Nobody Asked For
Every pod gets a token that authenticates to the API server, whether the application inside it ever calls the API or not. It sits there anyway, readable by anything that can read a file in the container, because the default is on.
A Tag Is Not a Version
You deployed myapp:1.4.2 in March and myapp:1.4.2 in September. Those are not necessarily the same image. Almost every tag you rely on is a mutable pointer that someone else can move without telling you.
The SBOM Your Customer Wants Is Not the One You Generated
An SBOM is a statement about a specific artifact. Generate it from the repository and you have an accurate document about something nobody runs, missing the base image where most of your published CVEs live.
An Egress Allowlist You Can Enforce, Not Just Record
A proxy the workload can decline to use is a log, not a control. Why environment-variable proxies and host firewall rules both fail for untrusted code, and the internal-network plus gateway-container shape that does not.
Four Artifactory CVEs in Sixteen Days: The Registry Is the Supply Chain
JFrog Artifactory had never appeared in CISA’s exploited-vulnerabilities catalogue. Between 27 August and 11 September 2026 it gained four entries, including unauthenticated administrative access under default configuration.
Docker symlink race condition escape (CVE-2018-15664)
A TOCTOU race in Docker's docker cp symlink resolution let malicious containers write to host files as root. Impact, CVSS, and fixes inside.
Docker Engine crafted image denial of service (CVE-2021-21285)
CVE-2021-21285 lets a crafted container image crash Docker Engine before 20.10.3. Affected versions, severity, timeline, and remediation steps.
Docker Engine remap-root UID mapping vulnerability (CVE-2021-21284)
CVE-2021-21284 let remapped-root containers escalate to real host root, defeating Docker's userns-remap isolation. Here's the full breakdown and fix.
Time-of-check to time-of-use (TOCTOU) race condition vulnerabilities
TOCTOU race conditions let attackers swap a resource between a security check and its use. Real CVEs, exploit mechanics, and prevention patterns explained.
Kubernetes Security News Today: What to Watch and How to Respond
Keeping up with Kubernetes security news today means more than reading headlines. Here's how to triage a fresh CVE, what IngressNightmare taught us, and where to look first.
Kubernetes RBAC misconfiguration explained
RBAC misconfigurations like wildcard rules and default service account bindings have powered real cluster takeovers, from CVE-2018-1002105 to Siloscape.
Secrets leakage in Docker images explained
How credentials get baked into Docker image layers, real incidents that exposed them, and how to detect and stop secrets leakage in container images.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.