K8s 1.37 Can Mount /tmp noexec. Docker Images Still Need It The Sept. 16 Kubernetes blog adds Alpha bindMountOptions and emptyDir modes. readOnlyRootFilesystem was never enough if the volume can chmod +x. docker
Don't Give AI Agents Your Host Docker Socket OpenAI agents escaped containers and hit Hugging Face workers in 13 hours. Here's how to isolate agent workloads with Docker Sandboxes, Firecracker, and a socket you do not mount. docker
CVE-2026-20896: The Gitea Docker Flaw That Takes One Header to Own Your Server A critical Docker image default in Gitea lets attackers gain admin access with a single HTTP header. Here's how CVE-2026-20896 works, how to check if you're vulnerable, and how to fix it in five minutes. docker
Docker Compose in Production: 8 Patterns for Resilient Deployments in 2026 Learn battle-tested Docker Compose patterns for production environments including health checks, network segmentation, secrets management, and rolling updates with recent security considerations. docker
Docker Hardened System Packages Complete Guide: 2026 Container Security Standard Docker launches Hardened System Packages in March 2026, extending security from base images to individual system packages. Learn about SLSA Build Level 3, near-zero CVE guarantee, and configuration examples. docker
Docker Security Best Practices: Protecting Containerized Applications Secure your Docker containers with essential security practices. Learn about image scanning, container isolation, secrets management, and runtime protection. security