More The Changelog: Software Development, Open Source episodes

Setting Docker Hardened Images free (Interview) thumbnail

Setting Docker Hardened Images free (Interview)

Published 4 Feb 2026

Duration: 1:16:49

Docker launches initiative to improve supply chain security through open-sourced, hardened images and transparency standards.

Episode Description

In May of 2025, Docker launched Hardened Images, a secure, minimal, production-ready set of images. In December, they made DHI freely available and op...

Overview

The podcast covers Docker's efforts to improve supply chain security by open-sourcing its Hardened Images, which are minimal container images intended to reduce security risks and streamline development processes. It addresses the increasing prevalence of supply chain attacks and outlines Docker's strategy to counter them using transparency standards such as SBOM (Software Bill of Materials), SLSA (Supply Chain Level Security Alignment), and VEX (Vulnerability Exploitability eXchange). These standards aim to ensure reproducible builds, better vulnerability tracking, and secure content delivery, providing a more trustworthy foundation for container-based applications.

Docker plans to offer free access to Hardened Images for open-source projects and developers, while also providing enterprise-level features to meet compliance and advanced security requirements. The initiative includes the development of a custom build system that adheres to SLSA guidelines, enforcing secure defaults in configurations, and promoting security as an integral part of the software development lifecycle. The conversation also notes Docker's expanding role in AI and agent-based workflows, with new runtime security features and isolation mechanisms designed to enhance security in these emerging areas.

Recent Episodes of The Changelog: Software Development, Open Source

3 Sept 2026 Forking Cal.com to closed source (Interview)

"AI-generated code floods open source projects, obscuring vulnerabilities and overwhelming maintainers, prompting shifts to private repositories and cloud-based development as security risks escalate."

25 Aug 2026 Postgres at PlanetScale (Interview)

"PlanetScale launched a $5 PostgreSQL plan, detailed metal deployment for performance, previewed sharded PostgreSQL product Niki, and discussed AI workloads, CI/CD challenges, and engineering-driven scaling strategies."

21 Jul 2026 Canary tokens and digital tripwires (Interview)

"Thinkst, a 50-person cybersecurity firm, specializes in Canary honeypots and Canary Tokens, offering simple, no-maintenance detection tools with $22.5M ARR, no price hikes in a decade, and AI-driven threat awareness."

5 Jun 2026 From open source hits to OpenAI (Interview)

A deep dive into open source contributions, AI-driven developer roles, challenges in maintaining projects like Spectrum and GitHub's acquisitions, balancing altruistic work with career growth, technical topics such as GraphQL and database scalability, and the evolving landscape of cloud environments and plugin ecosystems.

15 May 2026 MCP on Code Mode (Interview)

The Field CTO role focuses on data-driven product alignment with customer needs, advocating secure cloud environments, the Model Context Protocol for agent interactions, and balancing automation with security in AI-driven development workflows.

More The Changelog: Software Development, Open Source episodes