Blog

Latest insights on container security, SBOMs, and DevSecOps best practices.

Docker Security Dispatch — Issue 3: Zurich, Worms, and the AI Frontier 🏔️

May 2026 recap: DevOpsDays Zurich, TanStack and Nx Console supply chain compromises, Mini Shai-Hulud's long tail, Copy Fail, AI workloads, and the road to Berlin.

Featured
Voices from the Community: Forewords and Praise for 'Docker and Kubernetes Security'

A collection of the full forewords and book reviews from industry experts on Mohammad-Ali A'râbi's book, Docker and Kubernetes Security, as they appear in the published book.

Seven Docker Tips Every Engineer Should Know (from Docker Captains)

Docker's official Twitter/X account shared a series of practical tips from Docker Captains. This post revisits those seven tips with more context and examples.

My Cloud-Native Journey: Docker, Kubernetes, Security, and Open Source

A personal reflection on my journey in the cloud-native ecosystem, from becoming a Docker Captain to mentoring the next generation of open-source contributors, and my application for the CNCF Ambassador program.

Featured
Book Review: Operational AI with Docker

An exclusive behind-the-scenes look at the book 'Operational AI with Docker' by Ajeet Singh Raina and Harsh Manvar, including insights from my role as a technical reviewer.

Swiss Jass: Commandos Edition is Now on Google Play Store

Swiss Jass: Commandos Edition, a card game app inspired by the traditional Swiss card game Jass, is now available on the Google Play Store. The app features the Black Forest Commandos, a cast of characters that you have also met in the book Black Forest Shadow and the Docker Commandos workshop series.

Docker Security Dispatch — Issue 2: From JCON to Zurich 🏔️

Recapping JCON Europe, the Mini Shai-Hulud attack, an interview with Baruch Sadogursky, the 'Whispering JAR' in JAVAPRO, Foojay.io debut, Docker Sandboxes, and upcoming talks.

Featured
Mini Shai-Hulud: The Next Evolution of NPM Supply Chain Worms

A deep dive into the Mini Shai-Hulud attack, a sophisticated NPM worm that uses the Bun runtime to bypass security and targets developer agents for persistence.

Generating SBOM with Docker Scout
3 min read

Generating SBOM with Docker Scout

Am I vulnerable? That's the first question a CTO might ask in the case of a new CVE. To answer it, you need to know what's inside your container. SBOM is the word of the day. Especially, since EU Resilience Act makes it mandatory.

Docker Security Dispatch — Issue 1: Docker Turns 13 🎂

The first issue of Docker Security Dispatch: Docker's 13th birthday, the launch of Black Forest Shadow, a workshop at Rabobank, a JavaPro article, the best Docker book quarter in years, and what's next at JCON.

Featured
Dockerizing a Java 26 Project with Docker Init

Java 26 just landed. Here's how to Dockerize a Spring Boot project from scratch using Docker Init—the first move in the Docker Commandos playbook.

Featured
Docker Commandos v1.5: Asgard Mission
27 min read

Docker Commandos v1.5: Asgard Mission

Hands-on workshop materials for the 10 Docker Commandos at Rabobank, covering SBOM generation, CVE scanning, hardened images, VEX exemptions, Docker Bake, Cosign signing, and zero-day defense.

Featured
The Complete Docker Read List: Q1 2026 Edition

A curated reading list of the best books on Docker and Kubernetes for the first quarter of 2026, featuring releases from Docker Captains and industry experts.

Black Forest Commandos: The Rebranding of a Security Workshop
Updated 7 min read

Black Forest Commandos: The Rebranding of a Security Workshop

How Docker Commandos evolved into Black Forest Commandos, connecting the narrative-driven security workshop with the origin story in the Black Forest Shadows universe.

The Largest NPM Supply Chain Attack Ever and How to Defend Against It

Learn how to implement security best practices in multi-stage Docker builds, from source code to production images.

Docker Hardened Images are Free
3 min read

Docker Hardened Images are Free

Docker Hardened Images are now open-source under Apache 2.0 license and free to use in your projects.

Docker and Kubernetes Security Book: All Links

A curated list of all references and links related to the Docker and Kubernetes Security book by Mohammad-Ali A'râbi.

Featured
Top 5 Container Security Books for 2026
4 min read

Top 5 Container Security Books for 2026

A curated list of the best books on Docker and Kubernetes security for 2026.

Docker Deep Dive Workshop at WeAreDevelopers

A step-by-step guide to the Docker Deep Dive workshop I conducted at WeAreDevelopers World Congress 2025, covering Docker's latest features and tools for containerization and security.

How to Become a Docker Captain
Updated 5 min read

How to Become a Docker Captain

A personal journey and guide on how to become a Docker Captain, sharing knowledge, building community, and contributing to the Docker ecosystem.