<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Container-Security on CuraDevOps</title><link>https://curadevops.metacog.co.kr/tags/container-security/</link><description>Recent content in Container-Security on CuraDevOps</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 02 Sep 2026 14:51:34 +0000</lastBuildDate><atom:link href="https://curadevops.metacog.co.kr/tags/container-security/index.xml" rel="self" type="application/rss+xml"/><item><title>Defender for Cloud adds GA support for Azure Container Apps posture</title><link>https://curadevops.metacog.co.kr/insights/2026-09-02-launched-generally-available-microsoft-defender-for-cloud-su/</link><pubDate>Wed, 02 Sep 2026 14:51:34 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-09-02-launched-generally-available-microsoft-defender-for-cloud-su/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> If your platform runs Azure Container Apps, this GA feature lets you consolidate posture management under Defender for Cloud rather than operating a separate security toolchain; evaluate enabling it this quarter.&lt;/li>
&lt;li>&lt;strong>CI/CD — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Extends unified container security posture to serverless workloads on Azure — worth noting if your org is standardizing on Defender for Cloud as the security management plane.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> GA announcement&lt;/li>
&lt;/ul></description></item><item><title>Docker promotes zero-CVE base images with extended security coverage</title><link>https://curadevops.metacog.co.kr/insights/2026-08-18-make-zero-cves-your-new-default/</link><pubDate>Tue, 18 Aug 2026 11:17:30 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-18-make-zero-cves-your-new-default/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Learn:&lt;/strong> Docker&amp;rsquo;s extended security coverage and source-built images could reduce CVE surface on base images, but no EOL date or forced migration anchor exists — worth evaluating at next image refresh cycle.&lt;/li>
&lt;li>&lt;strong>CI/CD — Learn:&lt;/strong> Policy enforcement moving to developer machines and provenance guarantees through customized images are worth tracking for supply-chain hardening plans, but no deadline or breaking change makes this actionable now.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> deprecation mentioned (no explicit date found)&lt;/li>
&lt;/ul></description></item><item><title>Docker Engine (Moby) v25.0.17 patches three container CVEs</title><link>https://curadevops.metacog.co.kr/insights/2026-08-17-v25-0-17/</link><pubDate>Mon, 17 Aug 2026 12:38:40 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-17-v25-0-17/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> Three symlink/mount CVEs in the Docker engine (none KEV-listed, EPSS 0.00) warrant scheduling a patch to Moby 25.0.17 this sprint; also note that containerd 1.7 — vendored in this release — reaches EOL 2026-09-01, so any org running containerd 1.7 directly must plan a runtime upgrade within 15 days.&lt;/li>
&lt;li>&lt;strong>CI/CD — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> containerd 1.7 reaches EOL in 15d (2026-09-01) · major release (25.0) · CVE-2024-40635 — CISA KEV: not listed, EPSS 0.00 · CVE-2026-41567 — CISA KEV: not listed, EPSS 0.00 · CVE-2026-41568 — CISA KEV: not listed, EPSS 0.00&lt;/li>
&lt;/ul></description></item><item><title>Docker Hardened Images now free for all developers</title><link>https://curadevops.metacog.co.kr/insights/2026-07-22-a-safer-container-ecosystem-with-docker-free-docker-hardened/</link><pubDate>Wed, 22 Jul 2026 12:23:02 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-07-22-a-safer-container-ecosystem-with-docker-free-docker-hardened/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> Docker removing the cost barrier for hardened, minimal base images makes it practical to standardize on them across cluster workloads, reducing CVE surface without budget justification. Evaluate adopting Docker Hardened Images as the default base-image standard in your next quarterly planning cycle.&lt;/li>
&lt;li>&lt;strong>CI/CD — Plan:&lt;/strong> Hardened base images are directly relevant to build-time and artifact supply-chain security; with the free tier now available, it&amp;rsquo;s worth scheduling a migration of pipeline build images and application Dockerfiles to hardened variants as a supply-chain hardening step.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Docker making a previously premium security feature free reshapes the container security tooling landscape and is useful context for evaluating whether to formalize a hardened-image standard in the golden path, but no immediate strategic decision is required.&lt;/li>
&lt;/ul></description></item></channel></rss>