An isolated sandbox is only secure if devs actually use it. When setup takes longer than skipping it, they skip it. Oleg Šelajev on how kits make Docker Sandboxes repeatable, stackable, and shareable without the setup overhead: https://bit.ly/45Fe895
Docker
@docker.com
Docker helps developers bring their ideas to life by conquering the complexity of app development.
"Is it okay to run an agent in YOLO mode?" Docker CISO Mark Lechner's take: "there's no other way to run it." Half-measures give you the illusion of guardrails, not an actual one. Watch the full episode for all our CISO panelists’ takes on agent containment: https://bit.ly/4ffkIZD
Docker has officially signed Microsoft's "Open Weights and American AI Leadership" letter. On the heels of NVIDIA's Open Secure AI Alliance, we’re proud to add our name to this equally important initiative. Docker was built on openness, & that will continue in the agentic era https://bit.ly/44YMuUi
Open Weights and American AI Leadership
Open weight AI can expand access, strengthen competition, improve security, and help sustain American AI leadership.
microsoft.com
77% of organizations experienced a software supply chain incident in the past year. A new independent Omdia report, based on a survey of 400 cybersecurity, IT and application leaders, explores what's driving those incidents and how organizations are responding. Read: https://bit.ly/4fPlZFE
Two updates to audit capabilities in Docker AI Governance. Every policy decision your agents trigger is now searchable in Docker Cloud and can be streamed to your SIEM tools. Read more: https://bit.ly/3RHNGZi
"Just update everything" isn't always an option. Per Krogslund and Colton Shaw from Spectro Cloud discuss what devs can learn from regulated industries like healthcare & defense about software supply chain security, dependencies, and preparing for AI agents. https://youtu.be/ekCn_5qfJk4
Docker Hub now supports OIDC with GitHub Actions for Docker Organizations: your workflow's identity is the credential. Short-lived tokens, zero stored secrets. Available today for Team and Business. https://bit.ly/4g5hKqX
bit.ly
Docker Captain Nick Janetakis published a great guide on backing up PostgreSQL in Docker, covering local storage and leveraging Plakar with S3. Read more: https://bit.ly/4pLGZ4Q
How to Back Up PostgreSQL in Docker (Local, S3, and Plakar) -- Nick Janetakis
We'll cover doing backups and restores with and without Plakar and show how you can save money along the way.
bit.ly
Trust and security are the foundation on which success in the agentic era is built. No one company can build that foundation alone. Docker is joining NVIDIA's Open Secure AI Alliance to help create a world where devs can move freely between open and frontier models: https://bit.ly/4wCIyoy
Docker Joins Nvidia's Open Secure AI Alliance
Docker joins NVIDIA's Open Secure AI Alliance to help build the security, governance, and trust frameworks that agentic AI systems demand.
docker.com
Introducing Agent Baseline: a vendor-neutral reference architecture for safely building, deploying, and operating AI agents in enterprise environments. Created with Snyk and Keycard, this open-source framework sets the minimum standard for agent safety: https://agentbaseline.org/
When there’s a new agent "auto mode" update, Docker President and COO Mark Cavage tries to make it do something it shouldn't. It usually takes him 4 min or less. His talk with Software Engineering Daily on agent security and what containment actually requires: https://bit.ly/4pTztFm
Docker and Sandboxing AI Agents - Software Engineering Daily
Mark Cavage is the President and COO of Docker. He joins Gregor Vand to discuss Docker Sandboxes, micro VMs, coding agent security, trusted access, and the future of agent infrastructure.
softwareengineeringdaily.com
Everyone is debating how much autonomy to give agents. What that conversation often skips is where humans need to stay in the loop. Watch the full episode for all of our CISO panelists’ takes on what this looks like in practice → https://bit.ly/4ffkIZD
When agents start pulling dependencies and building environments, your security model has to evolve. Learn about SBOMs, VEX, Docker Hardened Images, image signing, and build policies in Ajeet Raina's workshop at WeAreDevelopers North America. Tickets → https://bit.ly/4e7b7nD
The malware didn't bring its own credential scanner. It borrowed yours. In this AI Coding Agent Horror Stories issue: Ajeet Raina breaks down how a poisoned npm package turned AI coding agents into credential thieves, and how to make sure there's nothing to steal. https://bit.ly/4fYMytl
We joined ExclusiveNetworks Germany for the first Docker Vendor Spotlight in the DACH region to explore helping customers build the future of secure AI and cloud-native innovation together. 🚀A huge thank you to the team for organizing such a fantastic event!
At the AI Engineer World’s Fair, agent safety was one of the biggest topics on and off stage. Docker EVP of Engineering Tushar Jain sat down with Shubhankar Srivastava of Browserbase to talk about how to actually run agents safely, and rethinking the runtime itself. https://bit.ly/45tS0hK
Giving AI agents real capabilities also means thinking about their boundaries. Build and test your first Docker Sandbox in Dan Ndombe's hands-on workshop at WeAreDevelopers North America, and see how to keep your agents contained with safer runtime controls. Tickets → https://bit.ly/4e7b7nD
"Don't do that" isn't a security boundary. Docker Captain Karan Verma explains why prompts influence behavior, but runtime enforces it. This post breaks down the boundaries that help developers understand what an agent can actually access, execute, and interact with. https://bit.ly/4wUC97C
AI Governance: Runtime Enforcement, Not Runtime Advice | Docker
Explore governance at the runtime layer and learn why isolation, policy enforcement, and controlled tool access are becoming foundational for agentic systems.
docker.com
Giving agents access to your dev environment? Have some security concerns? Learn how to use Docker Sandboxes and MCP help create secure, trusted execution environments for AI agents in Oleg Šelajev's workshop at WeAreDevelopers North America. Tickets → https://bit.ly/4e7b7nD
The panel asked the questions. This post captures one CISO's perspective on the answers. Docker CISO Mark Lechner shares why governing agents where devs work, starting from trusted software, and designing for containment beats chasing perfect prevention. https://bit.ly/45qrK7W
Owning your AI stack means understanding what's inside it. Per Krogslund and Colton Shaw discuss why AI sovereignty starts with trusted software - and where SBOMs and hardened images fit in as organizations move from AI consumers to AI operators. https://bit.ly/4wmFtsz
Most of the AI conversation is still theoretical. This one isn't. Mark Lechner (Docker CISO), Zach Lloyd (Warp CEO), Gavriel Cohen (NanoClaw CEO), & Moriah Hara (Founder, CISO Next Gen) compare notes on what teams are actually doing to govern agents without slowing adoption: https://bit.ly/4ffkIZD
📣 Workshops for WeAreDevelopers North America just dropped! We're kicking things off with Michael Irwin's AI-ready developer environment workshop. Learn how to build a reproducible local setup for AI, from models and runtimes to Docker. San Jose, Sept. 23–25 Tickets → https://bit.ly/4e7b7nD
On August 3rd at Black Hat, we're joining Snyk and Keycard to walk through the reference architecture that the three of us co-authored for securing coding agents. Hosted by Insecure Agents. Expect food and drinks, a live panel, and great networking. Register here https://bit.ly/4b4UypY
Today's sandbox protects the agent. Tomorrow's may need to protect the code it writes. Oleg Šelajev talks with Docker Sandboxes PM Eric Jia about where sandboxing is headed and what developers should be preparing for next. https://bit.ly/4prZqLG
Ivan Kv of Shark Numbers gives Claude Code the same task twice: once inside Docker Sandbox and once directly on his machine. The result is a practical look at what an AI coding agent can actually see, access, and modify, and where the sandbox boundaries hold. https://bit.ly/4fbRScI
I Let Claude Code Run Wild. Docker Sandbox Controlled What It Could Access
🐳🔒 Docker Sandboxes: https://utm.io/uqScb AI coding agents like Claude Code, Codex, Gemini CLI, and other agentic coding tools can read files, run commands, install packages, and modify your project. That makes them useful, but it also creates a ser...
youtube.com
Software changes quickly, but the best way to keep up hasn’t. This NewStack article interviews WeAreDevelopers co-founder + Entire CEO on why dev-to-dev conversations matter more than ever. We’re excited to help bring this event to North America - see you in September! https://bit.ly/4fHqfrZ
WeAreDevelopers is coming to the US to give unsung developers a bigger voice
The WeAreDevelopers conference expands to San Jose, California, this September. WAD co-founder and CEO Sead Ahmetovic and Entire CEO Thomas Dohmke speak with The New Stack about the future of software...
bit.ly
Many CVEs flagged in a ClickHouse deployment don't even come from ClickHouse. This walkthrough uses Docker Hardened Images to explain why base image choice has such a big impact on security findings, and what changes when you start from a hardened foundation. https://bit.ly/4fF7ENk
ClickHouse on Docker Hardened Images | ClickHouse
ClickHouse is now available as a Docker Hardened Image: a minimal, security-hardened build that passes enterprise vulnerability scans by shipping only what the database needs to run, with no change to how ClickHouse behaves.
clickhouse.com
Every dev has a project they almost didn't build. Docker Captain Mohammad-Ali A'râbi shares how one hackathon idea turned into something much bigger, and what he learned from taking the chance. Learn more about his journey as an author, speaker, and community leader: https://bit.ly/454EMrI
Everyone agrees AI agents need isolation. But what comes next? In this AI Guide to the Galaxy episode, Oleg Šelajev sits down with Docker Sandboxes Product Manager Eric Jia to discuss local AI, Kits, and why AI-generated code may become the next runtime challenge. https://youtu.be/tWJseVZdWyM