💬 Talk

Beyond SBOMs: The Future of Container Supply Chain Security

Wednesday, May 6, 2026
12:00 - 12:30

Session Description

When a single phished NPM maintainer led to 18 compromised libraries—including Chalk and Debug, downloaded billions of times weekly—it proved one thing: SBOMs alone aren’t enough.

In this talk, Docker Captain Mohammad-Ali A’râbi explores how modern supply-chain attacks unfold and how the next generation of tools—attestations, provenance, and signing—can prevent a repeat of the September 2025 NPM breach.

You’ll learn how to build verifiable, trusted pipelines using Docker Scout, Syft, Cosign, and Rekor, and how to extend SBOMs with build-phase attestations. The session combines deep technical demos with hard-won lessons from the largest NPM attack ever—and insights from Mohammad-Ali’s book “Docker and Kubernetes Security”—turning supply-chain horror stories into actionable DevSecOps practices.

What you’ll learn:

  • 🧠 Understand how the 2025 NPM supply-chain attack happened—and why traditional SBOMs couldn’t stop it.
  • 📦 Pin & lock dependencies to prevent malicious updates from sneaking in.
  • 🧱 Generate, sign, and verify attestations using Docker Scout + Cosign + Rekor.
  • 🔒 Adopt zero-trust build pipelines with SLSA levels + OCI 1.1 referrers.
  • 🧰 Defend proactively with seven practical strategies: block lifecycle scripts, use hardware keys, and continuously scan with Snyk / Trivy / Scout.
  • 🚀 Turn compliance into confidence by making your entire container lifecycle verifiable.

Speaker

Docker Captain, Author of “Docker and Kubernetes Security”, Senior Software Engineer @ JobRad

Mohammad-Ali A’râbi is a Senior Backend Engineer at JobRad GmbH, Docker Captain 🐳, and Snyk Ambassador 🛡️ with over 20 years of coding experience and a deep passion for DevSecOps and container security.

He is the author of “Docker and Kubernetes Security”, a hands-on guide to securing containerized environments from build to runtime. As a community leader, Mohammad-Ali founded the Docker Meetup in Freiburg (now Cloud Native Freiburg), organizing dozens of events that connect developers across the Black Forest region.

Beyond his book, he shares advanced Git and Docker insights through his Git Weekly newsletter and frequent conference talks. When he’s not securing supply chains or hosting meetups, you’ll probably find him building side projects, collecting superhero figures, or playing Mortal Kombat. 🎮

Our Amazing Sponsors

Gold

Silver

Evening Event, Coffee, Meals, Snacks

Bronze

Community

Partner