containers
Safeguard articles tagged "containers" — guides, analysis, and best practices for software supply chain and application security.
89 articles
Dockerizing Node.js and PHP Apps: A Practical Guide
Writing a node js dockerfile and learning how to dockerize php application deployments both hinge on the same handful of decisions — base image, layer order, and what you leave out of the final image.
Kubernetes securityContext: A Practical Hardening Guide
The securityContext in Kubernetes is where most pod hardening actually happens. A field-by-field guide to running non-root, dropping capabilities, and read-only roots.
Docker Image Security Scan: How to Scan Images for Vulnerabilities
A Docker image security scan inspects the layers of an image for known-vulnerable packages before you ship it. Here are the tools, commands, and the workflow that keeps scanning useful.
Docker Compose: Rebuilding Images Correctly (and Catching Stale Layers)
Why docker compose up sometimes runs old code, and how to rebuild images so what runs matches what you edited, including cache, stale layers, and orphaned images.
Writing a Secure Kubernetes Dockerfile: A Practical Hardening Guide
The Dockerfile you write decides most of a pod's attack surface before Kubernetes ever schedules it. Here is how to build images that run non-root, stay small, and survive a security review.
What a Cloud Native Security Platform Actually Does
A cloud native security platform unifies posture, workload, and supply chain controls for containerized apps. Here is what the category covers and how to tell the marketing from the substance.
Python Docker Images: How to Choose a Secure, Slim Base
Choosing among Python Docker images comes down to trade-offs between size, glibc compatibility, and attack surface. Here is how the official tags differ and how to build a lean, low-CVE image.
Container Hardening Guide 2025: From Base Image to Production
A practical guide to hardening container images and deployments. Covers base image selection, build-time security, runtime protections, and Kubernetes-specific controls.
Multi-Stage Docker Build Security in 2026
Multi-stage builds are the right way to ship secure container images, but the security benefits depend on getting the stage boundaries right. A guide for 2026.
How to Harden a Dockerfile in 10 Practical Steps
Ten concrete Dockerfile changes — digest pinning, multi-stage builds, non-root users, BuildKit secrets, SBOM attestations — that remove whole classes of container risk.
Choosing a Docker Security Tool: What Actually Matters
A Docker security tool scans images, configs, and running containers for risk. Here is what each category covers and how to pick one that fits your workflow.
Docker LABEL: A Security and Metadata Guide
How the Docker LABEL instruction works, the OCI annotation conventions worth adopting, and how good labels make image supply chains auditable.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.