---
title: "JRush Episode 7: Container Supply Chain Security for Java Teams"
description: "Watch JRush Episode 7 on demand: signed artifacts, hardened container images, and trusted pipelines for Java teams. Get the free replay, checklist, and materials."
image: https://jrush.bell-sw.com/hubfs/Episode_7.png
---

![](https://www.facebook.com/tr?id=671514874707498&ev=PageView&noscript=1) ![](https://www.facebook.com/tr?id=9691938794151384&ev=PageView&noscript=1) ![](https://www.facebook.com/tr?id=266650129256635&ev=PageView&noscript=1) ![](https://www.facebook.com/tr?id=634630745197325&ev=PageView&noscript=1) ![](https://www.facebook.com/tr?id=630390112025218&ev=PageView&noscript=1) ![](https://www.facebook.com/tr?id=763248408613009&ev=PageView&noscript=1)

[![JRush](https://jrush.bell-sw.com/hubfs/JRush%20New/Logos/jrush-logo.svg)](https://jrush.bell-sw.com/?hsLang=en)

[Talks](https://jrush.bell-sw.com/episode7#jrush-talks) [Takeaways](https://jrush.bell-sw.com/episode7#jrush-takeaways) [Headliners](https://jrush.bell-sw.com/episode7#jrush-headliners) [Web conference](https://jrush.bell-sw.com/episode7#jrush-about)

[Get recording](https://jrush.bell-sw.com/episode7#jrush-final-cta)

[Talks](https://jrush.bell-sw.com/episode7#jrush-talks) [Takeaways](https://jrush.bell-sw.com/episode7#jrush-takeaways) [Headliners](https://jrush.bell-sw.com/episode7#jrush-headliners) [Web conference](https://jrush.bell-sw.com/episode7#jrush-about) [Get recording](https://jrush.bell-sw.com/episode7#jrush-final-cta) 

[Get Episode 7 recording](https://jrush.bell-sw.com/episode7#jrush-final-cta)

On-demand episode | Originally aired June 23, 2026

# Container Supply Chain Security: Signed Artifacts, Hardened Images, Trusted Pipelines

Get the JRush Episode 7 recording, materials, and container security checklist. Three engineers walk through signed pipelines and attestations, reproducible Java image builds with Paketo Buildpacks, and a CVE response workflow that helps teams act without chasing scanner noise.

[Get the recording](https://jrush.bell-sw.com/episode7#jrush-final-cta) [View talks](https://jrush.bell-sw.com/episode7#jrush-talks)

Signal lock

CVE scan

Supply chain verified

What are the talks about?

## Three practical angles on container supply chain security.

Talk 0101

### Beyond SBOMs: The Future of Container Supply Chain Security

A breach story, the limits of SBOM-only controls, and a path to verifiable builds through attestations, provenance, and signing.

![Mohammad-Ali A'râbi](https://jrush.bell-sw.com/hubfs/JRush%20New/Episode%207/speaker1.png)

**Mohammad-Ali A'râbi**Docker Captain · Snyk Ambassador

Talk 0202

### Paketo Buildpacks: the Spring Boot Way to Build Images, and More!

How buildpacks work under the hood, what Spring Boot does with them, and where they beat hand-maintained Dockerfiles.

![Anthony Dahanne](https://jrush.bell-sw.com/hubfs/JRush%20New/Episode%207/speaker2.png)

**Anthony Dahanne**Paketo maintainer · HeroDevs

Talk 0303

### Beyond the Scan: Making Java Container Image Security Actionable

A practical model for hardened images, SBOMs, provenance, CVE classification, and safe updates without chasing scanner noise.

![Catherine Edelveis](https://jrush.bell-sw.com/hubfs/JRush%20New/Episode%207/speaker3.jpg)

**Catherine Edelveis**BellSoft Developer Advocate

Swipe talks

What you will learn

## A sharper workflow for secure Java containers.

Episode 7 focuses on the security decisions Java teams face after the scan: how artifacts are signed, how images are built, and how CVEs are triaged without slowing delivery.

**On-demand value**Use the recording and checklist as a practical reference for Java container pipeline reviews.

01

### Prove where your artifacts came from.

See where current controls fall short and how attestations, provenance, and signing create a verifiable build path that security and platform teams can trust during reviews.

02

### Build Java images without Dockerfile drift.

Understand where Paketo Buildpacks fit, how Spring Boot integration works, how layers are produced, and when buildpacks are the better path than hand-maintained Dockerfiles.

03

### Handle CVEs without chasing scanner noise.

Get a repeatable response model for hardened base images, CVE classification, safe updates, SBOMs, and provenance so scanner output turns into decisions instead of noise.

Headliners

## The people behind the tools and the workflows.

![Mohammad-Ali A'râbi](https://jrush.bell-sw.com/hubfs/JRush%20New/Episode%207/speaker1.png)

Speaker 01

Docker Captain · Snyk Ambassador · Author of Docker and Kubernetes Security

### Mohammad-Ali A'râbi

Mohammad-Ali wrote Docker and Kubernetes Security and has spent years building, breaking, and securing containerized systems. His session connects a real supply-chain attack with the controls teams need next: attestations, provenance, and signing.

[@MohammadAliEN](https://x.com/MohammadAliEN)

![Docker](https://jrush.bell-sw.com/hubfs/JRush%20New/Episode%207/docker-logo-white.svg) ![Snyk](https://jrush.bell-sw.com/hubfs/JRush%20New/Episode%207/snyk.svg)

Supply-chain security, signing, provenance

![Anthony Dahanne](https://jrush.bell-sw.com/hubfs/JRush%20New/Episode%207/speaker2.png)

Speaker 02

Paketo Java Buildpacks Maintainer · Software Developer, HeroDevs · Lead, Montreal Java User Group

### Anthony Dahanne

Anthony is one of the people who builds and maintains the Paketo Java buildpacks. He works across Java, containers, CI/CD, and build tooling, and shows how buildpacks can replace fragile Dockerfile maintenance with a more consistent image-building workflow.

[@anthonydahanne](https://x.com/anthonydahanne)

![HeroDevs](https://jrush.bell-sw.com/hubfs/JRush%20New/Episode%207/Herodevs.svg) ![Paketo](https://jrush.bell-sw.com/hubfs/JRush%20New/Episode%207/logo-paketo-light.svg) ![CNCF](https://jrush.bell-sw.com/hubfs/JRush%20New/Episode%207/CNCF_logo_white.svg)

Buildpacks, Java images, CI/CD

![Catherine Edelveis](https://jrush.bell-sw.com/hubfs/JRush%20New/Episode%207/speaker3.jpg)

Speaker 03

Developer Advocate, BellSoft · Co-host, CyberJAR

### Catherine Edelveis

Catherine helps teams ship secure, performant cloud-native Java using OpenJDK capabilities and open-source tools. Her talk turns scanner output into a practical workflow: hardened images, SBOMs, provenance, CVE classification, and safe updates.

[@cat\_edelveis](https://x.com/cat_edelveis)

![Alpaquita Linux](https://jrush.bell-sw.com/hubfs/Alpaquita%20col-wh%202.png) ![Liberica JDK](https://jrush.bell-sw.com/hubfs/LibericaJDK-logo-white.png) ![BellSoft](https://jrush.bell-sw.com/hubfs/bellsoft-logo.png)

Java security, CVE response, hardening

Swipe speakers

Free Java web conference

## Two focused hours. A lot less guesswork.

JRush is a free BellSoft series with expert talks, recordings, and technical materials for teams building, running, and securing Java applications. Episode 7 focuses on container supply chain security, from signed artifacts to buildpacks and CVE response.

**Free** Submit the form and get the recording, materials, and checklist.

**Focused** Signed artifacts, buildpacks, hardened images, and CVE response in one focused episode.

**Useful** Use the checklist after the episode for Java container security reviews.

Loading form...

FAQ

Replay,  
ready.

Submit the form once to get the Episode 7 recording, materials, and checklist in your inbox.

What is JRush? +

JRush is a free online series about Java development, cloud-native engineering, security, and practical tools for modern Java teams.

Is Episode 7 free? +

Yes. Submit the form and the autoresponder will send you the recording link, related materials, and the container security checklist for Episode 7.

Who is this episode for? +

It is built for Java developers, DevOps engineers, platform teams, application security engineers, and technical leads responsible for secure Java container delivery.

What will I receive after the form? +

You will receive access to the Episode 7 replay and materials covering signed artifacts, Paketo Buildpacks, hardened Java container images, CVE response, and the container security checklist.

![Docker](https://jrush.bell-sw.com/hubfs/JRush%20New/Episode%207/docker-logo-white.svg)

![Snyk](https://jrush.bell-sw.com/hubfs/JRush%20New/Episode%207/snyk.svg)

![HeroDevs](https://jrush.bell-sw.com/hubfs/JRush%20New/Episode%207/Herodevs.svg)

![Paketo](https://jrush.bell-sw.com/hubfs/JRush%20New/Episode%207/logo-paketo-light.svg)

![CNCF](https://jrush.bell-sw.com/hubfs/JRush%20New/Episode%207/CNCF_logo_white.svg)

![BellSoft](https://jrush.bell-sw.com/hubfs/JRush%20New/Episode%207/bellsoft.png)

![Liberica JDK](https://jrush.bell-sw.com/hubfs/JRush%20New/Episode%207/LibericaJDK-logo-white.png)

![Docker](https://jrush.bell-sw.com/hubfs/JRush%20New/Episode%207/docker-logo-white.svg)

![Snyk](https://jrush.bell-sw.com/hubfs/JRush%20New/Episode%207/snyk.svg)

![HeroDevs](https://jrush.bell-sw.com/hubfs/JRush%20New/Episode%207/Herodevs.svg)

![Paketo](https://jrush.bell-sw.com/hubfs/JRush%20New/Episode%207/logo-paketo-light.svg)

![CNCF](https://jrush.bell-sw.com/hubfs/JRush%20New/Episode%207/CNCF_logo_white.svg)

![BellSoft](https://jrush.bell-sw.com/hubfs/JRush%20New/Episode%207/bellsoft.png)

![Liberica JDK](https://jrush.bell-sw.com/hubfs/JRush%20New/Episode%207/LibericaJDK-logo-white.png)

Final call

## Leave your email. Get the recording.

Recording, checklist, links, and practical takeaways from JRush Episode 7 straight to your inbox.

Loading form...

**Done. Check your inbox.** We will send the Episode 7 recording, materials, and checklist to your email.

Free On demand Checklist included

Copyright © 2026 BellSoft LTD. All rights reserved.

<https://www.linkedin.com/company/bellsoft> <https://x.com/BellSoft> <https://www.youtube.com/c/BellSoft> <https://github.com/bell-sw>