Mohammad-Ali A'râbi

@aerabi.com

🐳 Docker Captain ⚓ 🐶 Snyk Ambassador 🔐 💾 Software Engineer at JobRad 🚲 📚 Author of DockerSecurity.io 🔮 Mathematician 📍 Freiburg 🇩🇪🇨🇭🇳🇱🇮🇷

A document without a signature is just a rumor. Use Cosign to cryptographically sign your container images and attestations, ensuring complete supply chain trust. 🖋️🔐 Commando 9️⃣ Evie signs every artifact so that no CVE can tamper with it. 🤠 Meet the team: dockersecurity.io/co...

Bild

Complex builds shouldn't rely on massive CLI commands. Use Docker Bake (docker-bake.hcl) to define tags, multi-platform builds, and attestations as version-controlled code. 🏗️ Commando 8️⃣ Captain Ahab brings order to the chaos of the container whale. 🐋 Meet the team: dockersecurity.io/co...

Bild

Prove your vulnerability exemptions are legitimate. VEX Attestations act as tamper-proof OCI referrers that travel with your container, automating compliance. ✅ Commando 7️⃣ RuinTan, the Immortal, grants invincible, verifiable protection cards to the innocent. 💀 More: dockersecurity.io/co...

Bild

Stop scanner fatigue! Use VEX (Vulnerability Exploitability eXchange) to formally exempt CVEs that aren't exploitable in your specific context. 🔇 Commando 6️⃣ Mina, the Undead Assassin, knows exactly which monsters are a threat and which are harmless. 🧛‍♀️ Learn more: dockersecurity.io/co...

Bild

Don't just generate an SBOM—attach it to your image! Using --sbom=true during build ensures the artifact travels everywhere your container goes. 🪪 Commando 4️⃣ The Valkyrie issues permanent, tamper-proof ID cards at the gates of Asgard. 🛡️ Meet the team: dockersecurity.io/co...

Bild

Find the vulnerabilities before you deploy. Cross-reference your SBOM against real-time CVE databases: $ docker scout cves <image> Commando 3️⃣ Jack, the Cyborg Soldier, acts as the ultimate scanner, hunting monsters on the perimeter. 🤖 Meet the team: dockersecurity.io/co...

Bild

You can't patch what you don't know you have. Generating an SBOM gives you full visibility into every component of your software supply chain. 📋 $ docker sbom <image> Commando 2️⃣ Rothütle demands a list of all Asgard residents to hunt down hidden CVEs. Meet the team: dockersecurity.io/co...

Bild

Stop writing insecure Dockerfiles from scratch. 🛑 Use docker init to automatically generate production-ready, secure foundations based on best practices. That's how Commando 1️⃣ Gord, the Swordmaster, builds her impenetrable command center in Asgard. ⚔️ Meet the team: dockersecurity.io/co...

Bild

My JavaPro article on "10 essential Docker commands to hunt the predator" is live! We cover: 📜 SBOMs & Attestations 🛡️ Hardened Images (DHI) 🚫 VEX Exemptions 🕵️‍♂️ Zero-Day Defenses Read the full Asgard mission here 👇 javapro.io/2026/03/1... #Docker #DevSecOps #Java #ContainerSecurity

10 Docker Commandos: Docker Commands to Hunt the Predator - JAVAPRO International

Whose day is it on Tuesday? I mean, Wednesday is Odin’s day, Thursday is Thor’s day, and Friday is Frigg’s day, or…

javapro.io

My JavaPro article on "10 essential Docker commands to hunt the predator" is live! We cover: 📜 SBOMs & Attestations 🛡️ Hardened Images (DHI) 🚫 VEX Exemptions 🕵️‍♂️ Zero-Day Defenses Read the full Asgard mission here 👇 javapro.io/2026/03/1... #Docker #DevSecOps #Java #ContainerSecurity

10 Docker Commandos: Docker Commands to Hunt the Predator - JAVAPRO International

Whose day is it on Tuesday? I mean, Wednesday is Odin’s day, Thursday is Thor’s day, and Friday is Frigg’s day, or…

javapro.io

Docker Commandos landed at Rabobank! ⚔️🐳 Last week, I ran the v1.5 Asgard Mission workshop for ~30 engineers in the Netherlands—and 80% rated it 5/5! 🌟 Instead of dry security slides, we used a dark fantasy narrative to secure the container supply chain. 🧵👇

BildBildBildBild

Docker Commandos coming to Cologne. 💪 On April 20–23 I'll be at @JCON.one with my workshop: ☕ »Java Supply Chain Security with Docker« SBOMs. Attestations. Docker Hardened images. Cologne is in Carnival mode—so we're bringing the energy. 🎟️ 10% off with ARABI-VIP-15 CC @docker.com

Bild

Do I make a good Norse God? Jfokus people have created this avatar for me as I’m going to join them to talk about Docker Security. What do you think my Norse God name would be? A’rabír?

Bild