docker
Safeguard articles tagged "docker" — guides, analysis, and best practices for software supply chain and application security.
81 articles
The Dockerfile in Your Repository Is Probably Not What Builds
An urgent fix gets made on the build host, the backport never happens, and the repository copy becomes a historical document. Absent files prompt questions; stale ones answer them wrongly.
An Egress Allowlist You Can Enforce, Not Just Record
A proxy the workload can decline to use is a log, not a control. Why environment-variable proxies and host firewall rules both fail for untrusted code, and the internal-network plus gateway-container shape that does not.
A Container Stuck on health: starting Is Probably a Crash Loop
Each restart resets the health check, so a crash loop and a slow boot look identical in the status column. The one command that tells them apart, and the merge conflict class that produces the most convincing version.
CVE-2019-15752: Docker Desktop Community Edition Privilege Escalation Vulnerability
CVE-2019-15752 affects Docker Desktop Community Edition and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
containerd-shim Abstract Unix Socket Exposure Enabling Co...
CVE-2020-15257 lets processes in host-networked containers reach the containerd-shim socket and escape to the host. Impact, affected versions, and fixes explained.
CVE-2025-31133 in runc: Patch Posture & SBOM Response
runc container-escape via /proc mount manipulation affects Docker, Kubernetes, and every CRI runtime. Defender playbook below.
How to Build a Docker Image for Kubernetes Securely
You do not build Docker images inside Kubernetes the old way anymore. Here are the secure patterns for building images that k8s will run, from CI to in-cluster builders.
Docker Scratch Image: The Security Case for Empty Bases
A Docker scratch image starts from nothing, and that emptiness is the point: no shell, no package manager, and almost no CVEs for a scanner to find.
Node.js in Docker: A Practical Setup Guide
A practical setup guide for running node.js docker containers in production, choosing between docker node slim and full images, and locking down what actually matters for security.
The Node.js Image: A Security Guide to Docker Base Images
Choosing a Node.js image is a security decision, not just a size one. The tag you pick, alpine, slim, or distroless, and the version you pin decide most of your container's attack surface.
Docker image vulnerability scanning: best practices for CI/CD
Log4Shell hid in countless container images for years before scanning caught it. Here's how to scan base layers and gate builds before that happens again.
Best practices for containerizing .NET applications securely
.NET 8 gave containers a built-in non-root user and chiseled images that cut one team's CVE count 92% — most Dockerfiles still don't use either.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.