Container Security & DevSecOps
Explore all 7 posts in the Container Security & DevSecOps series
Blog Posts
6 items
QuenchWorks: A Zero-CVE, Built-From-Source Replacement for the Bitnami Catalog
- Mohammad Abu Mattar
- DevOps
- Containers
- Supply Chain Security
- Kubernetes
- Open Source
- Published: 08 Jul, 2026
- Updated: 22 Jul, 2026
If you run anything on Kubernetes, there's a good chance you were pulling Bitnami images without even thinking about it. bitnami/postgresql, bitnami/redis, bitnami/nginx, the whole Helm charts l

What's the Deal with Shift-Left Security, and Why Should You Care?
- Mohammad Abu Mattar
- CI/CD
- DevSecOps
- Security
- Automation
- Application Security
- Published: 24 Jan, 2026
Let's be honest: in today's software world, security can't be an afterthought. If you're still waiting until the end of your development cycle to think about vulnerabilities, you're doing it wrong. Th

Container Image Signing with Cosign: A Hands-On Guide to Secure Your Supply Chain
- Mohammad Abu Mattar
- Security
- Supply Chain Security
- Containers
- DevSecOps
- Published: 18 Jan, 2026
In today's fast-paced software world, we all rely on container images to package and run our apps. They're super consistent and efficient, which is great! But this ease also brings new security headac

The Democratization of Container Security: Docker Hardened Images
- Mohammad Abu Mattar
- Docker
- Container Security
- DevSecOps
- Supply Chain Security
- Published: 19 Dec, 2025
On December 17, 2025, the world of container security changed in a big way. Docker decided to open up its entire catalog of over 1,000 Docker Hardened Images (DHI) to everyone under the Apache 2.0 lic

Unlocking the Secrets: HashiCorp Vault vs. AWS Secrets Manager vs. SOPS - Which Reigns Supreme
- Mohammad Abu Mattar
- DevOps
- Security
- Cloud Computing
- Published: 25 May, 2025
Let's face it, in today's tech world, keeping sensitive info safe – we're talking about those digital keys like API keys and passwords – is a big deal. They're what let you into important systems and

Policy as Code with Open Policy Agent: A Technical and Governance Perspective
- Mohammad Abu Mattar
- DevOps
- Security
- Cloud Governance
- Policy as Code
- Published: 08 Apr, 2025
Think about how much stuff modern organizations have running in the cloud these days. It's a lot, right? All those servers, applications, and connections can get pretty complicated to manage. Just cli
DevTips
1 item
Container Image Vulnerability Scanning in CI/CD with Trivy
- Mohammad Abu Mattar
- DevOps & DevSecOps
- Published: 10 Mar, 2026
Why Container Security Matters The Vulnerability Problem Container images are a critical attack surface in modern deployments. Every time you build a container image, it includes the bas