container-security
Safeguard articles tagged "container-security" — guides, analysis, and best practices for software supply chain and application security.
446 articles
AWS ECR Image Signing in Production
Image signing in ECR has moved from nice-to-have to table stakes. Here is what it actually takes to run cosign and AWS Signer in production without breaking every deploy.
Cosign container signing
What is Cosign? A precise look at how this Sigstore tool signs and verifies container images, keyless signing, and how it compares to Notary v2.
The Minimal Base Image Myth: What Actually Reduces Attack Surface
Alpine, distroless, and scratch images don't automatically cut risk. The real attack-surface drivers are capabilities, root filesystem, network policies, and seccomp.
Firecracker micro-VM Security Model
AWS built Firecracker to run Lambda. The security model is the entire value proposition, and it holds up under scrutiny.
Alpine vs Distroless vs Ubuntu Base Images: Security Tradeoffs
Alpine is small, distroless is smaller, Ubuntu is comfortable. The real security question is CVE surface vs debuggability vs compatibility — with numbers.
GitHub Container Registry (ghcr.io): A Practical Security Guide
GitHub Container Registry (ghcr.io) is convenient and tightly integrated with Actions, but the defaults can leak images and tokens. Here's how to lock it down properly.
containerd Security Configuration Guide
containerd runs most of Kubernetes today. Its defaults are reasonable, but reasonable is not hardened. Here is how to close the gaps.
Zero-CVE Images vs Hardening Your Own: Cost and Risk Compared
Buy zero-CVE base images or build hardened ones yourself? A cost-and-risk comparison with real numbers: engineering hours, subscription pricing, and CVE half-life.
Kubernetes Container Security Scanner: How It Works and What to Use
A Kubernetes container security scanner checks images, manifests, and running workloads for known vulnerabilities and misconfigurations. Here is how the pieces fit and where to place them in a pipeline.
Container Security Scanning in 2024: Benchmarks, Tools, and What Actually Matters
Container image scanning tools vary widely in detection rates, false positive rates, and coverage. Here is a practical assessment of the container security scanning landscape in 2024.
Container escape
A container escape lets attackers break out of a container into the host or other workloads. Learn how these attacks work, real CVEs, and Kubernetes risk.
CIEM (Cloud Infrastructure Entitlement Management)
What is CIEM? A clear breakdown of Cloud Infrastructure Entitlement Management, how it differs from CSPM, and why excessive cloud permissions keep piling up.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.