Talk 1 of 3 at JRush Ep.7. @aerabi.bsky.social, Docker Captain, author of "Docker and Kubernetes Security", on how to build a pipeline the breach can't get through. Free. June 23. jrush.bell-sw.com/episode7 #Java #DevSecOps
Mohammad-Ali A'râbi
@aerabi.com
🐳 Docker Captain ⚓ 🐶 Snyk Ambassador 🔐 💾 Software Engineer at JobRad 🚲 📚 Author of DockerSecurity.io 🔮 Mathematician 📍 Freiburg 🇩🇪🇨🇭🇳🇱🇮🇷
This is how supply chain attacks get through. @aerabi.bsky.social covering this live at JRush Ep.7. Free. June 23. jrush.bell-sw.com/episode7 #Java #DevSecOps
My article on Mini Shai Hulud 🪱 is out! www.dockersecurity.io/blog/mini-sh...
Mini Shai-Hulud: The Next Evolution of NPM Supply Chain Worms
A deep dive into the Mini Shai-Hulud attack, a sophisticated NPM worm that uses the Bun runtime to bypass security and targets developer agents for persistence.
dockersecurity.io
Someone sent me a DM today and said my CV-builder GitHub CI pipeline was a game-changer for him. My CV is on a GitHub repo, and it's built and published as an artifact every time you push to the repo. I gave a talk at @Docker All Hands about it once. youtu.be/DMwbXN3QKbs?...
Build Your CV with Docker and GitHub Actions
YouTube video by Docker
youtu.be
How to secure your supply chain ⛓️ with @jbaru.ch! 🤠 www.youtube.com/live/pFfJZRA...
AINativeDev and JavaPro at JCON Europe 2026
YouTube video by AI Native Dev
youtube.com
4 years ago on this day, I started a Twitter series called "Git Pro Tips". They are now available on git-weekly's website: git-weekly.com/tips
Git Tips
A collection of short and useful Git tips for all levels.
git-weekly.com
A document without a signature is just a rumor. Use Cosign to cryptographically sign your container images and attestations, ensuring complete supply chain trust. 🖋️🔐 Commando 9️⃣ Evie signs every artifact so that no CVE can tamper with it. 🤠 Meet the team: dockersecurity.io/co...
Complex builds shouldn't rely on massive CLI commands. Use Docker Bake (docker-bake.hcl) to define tags, multi-platform builds, and attestations as version-controlled code. 🏗️ Commando 8️⃣ Captain Ahab brings order to the chaos of the container whale. 🐋 Meet the team: dockersecurity.io/co...
I just completed the Docker Commandos v1.5 Asgard Mission! 🐳🛡️ Check out my certificate of completion: www.dockersecurity.io/commandos/in...
Mohammad-Ali's Docker Commando Certificate - Docker and Kubernetes Security
Mohammad-Ali has successfully completed the Docker Commandos v1.5 Asgard Mission. Demonstrate your own mastery of supply-chain security!
dockersecurity.io
Prove your vulnerability exemptions are legitimate. VEX Attestations act as tamper-proof OCI referrers that travel with your container, automating compliance. ✅ Commando 7️⃣ RuinTan, the Immortal, grants invincible, verifiable protection cards to the innocent. 💀 More: dockersecurity.io/co...
Stop scanner fatigue! Use VEX (Vulnerability Exploitability eXchange) to formally exempt CVEs that aren't exploitable in your specific context. 🔇 Commando 6️⃣ Mina, the Undead Assassin, knows exactly which monsters are a threat and which are harmless. 🧛♀️ Learn more: dockersecurity.io/co...
Want to slash your attack surface to zero? Use Docker Hardened Images: FROM dhi.io/node:25 Instead of: FROM node:25 Hardened Images are not hard. Commando 5️⃣ Artemisia, the Amazonian Commander, guards the heavily fortified, zero-CVE district. ⚓ www.dockersecurity.i...
Don't just generate an SBOM—attach it to your image! Using --sbom=true during build ensures the artifact travels everywhere your container goes. 🪪 Commando 4️⃣ The Valkyrie issues permanent, tamper-proof ID cards at the gates of Asgard. 🛡️ Meet the team: dockersecurity.io/co...
Find the vulnerabilities before you deploy. Cross-reference your SBOM against real-time CVE databases: $ docker scout cves <image> Commando 3️⃣ Jack, the Cyborg Soldier, acts as the ultimate scanner, hunting monsters on the perimeter. 🤖 Meet the team: dockersecurity.io/co...
You can't patch what you don't know you have. Generating an SBOM gives you full visibility into every component of your software supply chain. 📋 $ docker sbom <image> Commando 2️⃣ Rothütle demands a list of all Asgard residents to hunt down hidden CVEs. Meet the team: dockersecurity.io/co...
Stop writing insecure Dockerfiles from scratch. 🛑 Use docker init to automatically generate production-ready, secure foundations based on best practices. That's how Commando 1️⃣ Gord, the Swordmaster, builds her impenetrable command center in Asgard. ⚔️ Meet the team: dockersecurity.io/co...
My JavaPro article on "10 essential Docker commands to hunt the predator" is live! We cover: 📜 SBOMs & Attestations 🛡️ Hardened Images (DHI) 🚫 VEX Exemptions 🕵️♂️ Zero-Day Defenses Read the full Asgard mission here 👇 javapro.io/2026/03/1... #Docker #DevSecOps #Java #ContainerSecurity
10 Docker Commandos: Docker Commands to Hunt the Predator - JAVAPRO International
Whose day is it on Tuesday? I mean, Wednesday is Odin’s day, Thursday is Thor’s day, and Friday is Frigg’s day, or…
javapro.io
My JavaPro article on "10 essential Docker commands to hunt the predator" is live! We cover: 📜 SBOMs & Attestations 🛡️ Hardened Images (DHI) 🚫 VEX Exemptions 🕵️♂️ Zero-Day Defenses Read the full Asgard mission here 👇 javapro.io/2026/03/1... #Docker #DevSecOps #Java #ContainerSecurity
10 Docker Commandos: Docker Commands to Hunt the Predator - JAVAPRO International
Whose day is it on Tuesday? I mean, Wednesday is Odin’s day, Thursday is Thor’s day, and Friday is Frigg’s day, or…
javapro.io
Docker Commandos landed at Rabobank! ⚔️🐳 Last week, I ran the v1.5 Asgard Mission workshop for ~30 engineers in the Netherlands—and 80% rated it 5/5! 🌟 Instead of dry security slides, we used a dark fantasy narrative to secure the container supply chain. 🧵👇
Docker Commandos coming to Cologne. 💪 On April 20–23 I'll be at @JCON.one with my workshop: ☕ »Java Supply Chain Security with Docker« SBOMs. Attestations. Docker Hardened images. Cologne is in Carnival mode—so we're bringing the energy. 🎟️ 10% off with ARABI-VIP-15 CC @docker.com
Guess who's a verified book author on Medium! aerabi.medium.com
Docker Hardened Images are now free! FROM dhi.io/node:24 From this moment on, you can use the near-zero-CVE Docker images as your base images, for free! Learn more here:
Docker Hardened Images are Free
Docker introduced Hardened Images in 2025 as a secure-by-default base image line, designed to keep...
dev.to
Container Security Advent, day 7 is rather ceremonial. Like Sunday. 🎄⚔️🤠 Tip. Rebuild your Docker images regularly and keep your dependencies in check. dev.to/aerabi/-day-...
dev.to
Container Security Advent, day 5 is here! 🌫️🌲👣 The fog thickens as Gord and Rothütle enter the valley toward Oberried… Today's security tip: Environment Drift—when small inconsistencies warp your whole system. dev.to/aerabi/day-5...
Day 5 — The Fog in the Valley
In the previous 4 days, we followed Gord and Rothütle as they journeyed through the Black Forest....
dev.to
Container Security Advent, day 4 is here! 🍽️🌒👣 Tonight in Kirchzarten, Gord keeps vigil while the village sleeps… And our security tip dives into continuous monitoring.
Day 4 — Midnight Vigil
Gord and Rothütle arrive in Kirchzarten as dusk falls, the sky painted in deep oranges and purples....
dev.to
Do I make a good Norse God? Jfokus people have created this avatar for me as I’m going to join them to talk about Docker Security. What do you think my Norse God name would be? A’rabír?
Container Security Advent, day 3 is here! 🪔📩🌃🌲
Day 3 — Through the Gate
Night settles over Salzstraße as Rothütle and Gord arrive at Hauptmann Seutter von Loetzen's...
dev.to
Day 2 of the DevSecOps Advent blog is here! 🕯️🚪📩📜 They get a typed letter!
Day 2 — The Typed Letter
Leaving Zum Roten Bären behind them, Rothütle and Gord walk through the quiet evening streets of...
dev.to
So… I started an Advent series that mixes Gothic Black Forest storytelling with container security tips, because clearly I've gone crazy. 🎩🌲💀🐋 Day 1 is live:
Day 1 — The Red Bear Inn: Beginning the Security Advent (Defense in Depth)
Welcome to the first issue of Black Forest Shadow, an Advent series where two worlds collide: A...
dev.to
Thank you, @aerabi.com, for gifting a copy of your newly published book, Docker and Kubernetes Security, and for bringing it all the way from Germany to Istanbul. I will go through it soon. If you want to learn @docker.com and Kubernetes security, I highly recommend this book.