Save your free spot
June 23 at 6pm CEST | 9am PT

Your container supply chain has a gap. Here's how to close it.

Not a slide deck. Three engineers working hands-on with Docker Scout, Cosign, Paketo Buildpacks, and Java container hardening walk you through signed pipelines and attestations, reproducible Java image builds, and a CVE response workflow that doesn't slow your team down. Live demos. Real code. Free.

A free JRush session on signed pipelines, reproducible Java image builds, and a CVE response workflow your team can actually use.

🎁 Get the container security checklist when you register.

Free checklist included

Save your spot in under a minute.

Register once to get the container security checklist, the live broadcast link before JRush, and the recording after the event.

ChecklistLive linkRecording
HubSpot form will load here.

Topics

What are the talks about?

Buildpacks 02

Paketo Buildpacks: the Spring Boot Way to Build Images, and More!

How buildpacks work under the hood, what Spring Boot does with them, and where they beat hand-maintained Dockerfiles.

Image security 03

Beyond the Scan: Making Java Container Image Security Actionable

A practical model for hardened images, SBOMs, provenance, CVE classification, and safe updates without chasing scanner noise.

What you will walk away with

Not more tool names. A better operating model.

Three demo-backed answers to the container security problems your team has right now.

Useful after the event Each takeaway maps to a decision your team actually has to make in a Java container pipeline.
01

Signed pipelines that prove where your artifacts came from

See where current controls fall short and how attestations, provenance, and signing create a verifiable build path.

CosignRekorSLSAOCI 1.1
02

Reproducible Java image builds without Dockerfile drift

Understand where Paketo Buildpacks fit, how Spring Boot integration works, and when buildpacks are the better path.

PaketoSpring BootCNBOCI images
03

A practical way to handle CVEs without chasing scanner noise

Get a repeatable response model for hardened base images, CVE classification, safe updates, SBOMs, and provenance.

CVE triageSBOMHardened imagesAlpaquita

Headliners

The people behind the tools and the workflows

Mohammad-Ali A'râbi
Speaker 01

Docker Captain · Snyk Ambassador · Author of Docker and Kubernetes Security

Mohammad-Ali A'râbi

@MohammadAliEN on X

Mohammad-Ali literally wrote the book on Docker and Kubernetes security and has spent years building, breaking, and securing containerized systems. His session connects a real supply-chain attack with the controls teams need next: attestations, provenance, and signing.

Docker Snyk

Supply-chain security, signing, provenance

Anthony Dahanne
Speaker 02

Paketo Java Buildpacks Maintainer · Software Developer, HeroDevs · Lead, Montreal Java User Group

Anthony Dahanne

@anthonydahanne on X

Anthony is one of the people who actually builds and maintains the Paketo Java buildpacks. He works across Java, containers, CI/CD, and build tooling, and will show how buildpacks can replace fragile Dockerfile maintenance with a more consistent image-building workflow.

HeroDevs Paketo CNCF

Buildpacks, Java images, CI/CD

Catherine Edelveis
Speaker 03

Developer Advocate, BellSoft · Co-host, CyberJAR

Catherine Edelveis

@cat_edelveis on X

Catherine helps teams ship secure, performant cloud-native Java using OpenJDK capabilities and open-source tools. Her talk turns scanner output into a practical workflow: hardened images, SBOMs, provenance, CVE classification, and safe updates.

Alpaquita Linux Liberica JDK BellSoft

Java security, CVE response, hardening

Web conference series

Two focused hours. A lot less guesswork.

JRush gives Java teams compact expert talks, live discussion, recording, and materials they can return to after the event.

episode_07/output
jrush.output
episode_07
$ jrush episode-07 --format compact --target java-teams
resolving container-security context
output ready
supply_chain.contextincluded
buildpacks.workflow_demoincluded
image_hardening.modelincluded
live_qna.sessionincluded
recording_and_materialsafter live
Time cost

Focused live context. Reusable after the event.

2h

Free checklist

Get the container security checklist

Register for JRush and get a quick self-check for runtime hardening, CVE hygiene, SBOMs, image signing, and base image security.

HubSpot form will load here.

Checklist arrives right after registration. The broadcast link will come before JRush, and the recording after the event.

10-point self-checkContainer imagesBuilt for security reviews
Docker Snyk HeroDevs Paketo CNCF BellSoft Liberica JDK

FAQ

Yes,
free.

Register to get the broadcast link before JRush. The recording will arrive after the event.

A series of free online seminars on Java development, cloud-native engineering, security, and the tools shaping the Java ecosystem.

Yes. The event is free to attend. Register to receive the broadcast link and recording.

Yes. The program is built around practical demos, real tooling, and workflows that Java teams can adapt after the event.

No. The talks are useful for Java developers, DevOps engineers, platform teams, architects, and anyone responsible for shipping secure Java containers.

Yes. Registered attendees receive the recording after the conference ends.

Save your spot

Secure images start with better questions.

Get the checklist, join the live session, and walk away with a clearer way to review your Java container pipeline.

HubSpot form will load here.

Checklist arrives right after registration. The broadcast link will come before JRush, and the recording after the event.

Runtime hardening SBOMs Signed artifacts Base images