Catherine Edelveis

@edelveis.dev

Liberica JDK Advocate | Spring Boot Enthusiast | JavaFX Fancier | Tech Writer and YouTuber | Dog Mom | Views are my own Home: edelveis.dev CyberJAR channel: https://www.youtube.com/@cbrjar

📚New article! Buildpacks turn source code into a production-ready container image without a Dockerfile. But which buildpacks offering should you choose? Paketo, Heroku, Google, BellSoft, Red Hat, Tanzu, SAP, or Cloud Foundry? Check out the comparison: bell-sw.com/blog/buildpa...

Buildpacks Comparison: CNB, Base OS, Security & Support

Compare Buildpacks and Cloud Native Buildpacks from Paketo, Heroku, Google, Tanzu, BellSoft, Cloud Foundry, Red Hat, and SAP by languages, base OS, security, and support.

bell-sw.com

📑 Don't Trust That Package! My new article explores how zero trust principles can be applied to open source software, from analyzing the project health to gathering and monitoring security signals. Available in the latest JavaPRO PDF issue: javapro.io/2026/09/29/a...

Always Up to Date - with Every New Free PDF Edition! - JAVAPRO International

Don’t Want to Miss a Thing?By subscribing to our news, you’ll get each new PDF edition automatically —…

javapro.io

⚡️Tomorrow at JRush: When AI meets real software development @martinelli.ch , @jbaru.ch , and @asm0dey.site will talk about spec-driven development, coding-agent factories, context, reviews, and engineering decisions belonging to humans. Sign up and see you there! jrush.bell-sw.com/episode8

JRush Episode 8: Java in the Age of AI

AI works in the demo, then falls apart on real code. Three practitioners show what actually works. Live, free, Sept 29. Register now.

jrush.bell-sw.com

📖 Neuer Beitrag: Die Jagd nach jedem einzelnen CVE ist sinnlos. Eine bessere Lösung ist ein Schwachstellenmanagementsystem aufzubauen, das sich auf Hardened Images, Build-Provenienz, und Richtlinien für die Behebung von Schwachstellen stützt. javapro.io/de/wie-man-c...

Hardened Images: CVEs in Containern besser verwalten

Erfahren Sie, wie Hardened Images, Provenienz, kontinuierliche Scans und automatisierte Rebuilds helfen, CVEs in Containern kontrolliert zu verwalten.

javapro.io

🔖Rebuild or Rebase? What to Do When a Container Image Changes A CVE patch for your base lands - do you need to rebuild the whole image for that? Not necessarily. Me and Dmitry put our heads together and created a guide on efficient image updates: bell-sw.com/blog/rebuild...

Rebuild vs Rebase Container Images: Docker and Buildpacks

Learn when to rebuild or rebase container images, how Docker Buildx and Buildpacks handle cache and rebasing, and why unchanged layer digests can reduce Kubernetes image pulls.

bell-sw.com

Did you know? No need to always rebuild a container image when the base changes. We can rebase it: replace the runtime base and keep the upper layers unchanged. Buildpacks make it a first-class operation with pack rebase. BuildKit can do smth similar with COPY --link and a cache.

CyberJAR has been added to Foojay Java In Education Catalog! Thank you, @foojay.io and Igor Souza for recognition. This is an important milestone for CyberJAR, and I promise we will keep the momentum and deliver more content on all things Java☕️ education.foojay.social

Foojay Java in Education Catalog

A community-driven catalog of Java learning resources with websites, tutorials, videos, books, and tools for students, educators, coding clubs, and developers.

education.foojay.social

Dockerfiles are fine if they are written and maintained well. Then the base image gets old, the runtime needs a bump, and every repo has its own build ritual. @edelveis.dev gets into buildpacks: shared builders, rebasing, SBOMs, and when a Dockerfile still makes sense. bell-sw.com/blog/what-ar...

What Are Buildpacks? Buildpacks vs Dockerfiles Explained

Learn what Cloud Native Buildpacks do, how they compare with Dockerfiles, and how to use them with Java, Python, Go, and Node.js.

bell-sw.com

A smaller image is not automatically a hardened image. @edelveis.dev breaks down slim, distroless, scratch, and hardened images, then shows the Java adoption path: multi-stage builds, SBOMs, signatures, CI/CD checks, and a practical checklist. bell-sw.com/blog/what-ar...

What Are Hardened Container Images? A Comprehensive Guide

Learn what hardened container images are, how they reduce attack surface and CVE noise, and how to adopt them in production.

bell-sw.com