Get Episode 7 recording
On-demand episode | Originally aired June 23, 2026

Container Supply Chain Security: Signed Artifacts, Hardened Images, Trusted Pipelines

Get the JRush Episode 7 recording, materials, and container security checklist. Three engineers walk through signed pipelines and attestations, reproducible Java image builds with Paketo Buildpacks, and a CVE response workflow that helps teams act without chasing scanner noise.

What are the talks about?

Three practical angles on container supply chain security.

Talk 0101

Beyond SBOMs: The Future of Container Supply Chain Security

A breach story, the limits of SBOM-only controls, and a path to verifiable builds through attestations, provenance, and signing.

Talk 0202

Paketo Buildpacks: the Spring Boot Way to Build Images, and More!

How buildpacks work under the hood, what Spring Boot does with them, and where they beat hand-maintained Dockerfiles.

Talk 0303

Beyond the Scan: Making Java Container Image Security Actionable

A practical model for hardened images, SBOMs, provenance, CVE classification, and safe updates without chasing scanner noise.

What you will learn

A sharper workflow for secure Java containers.

Episode 7 focuses on the security decisions Java teams face after the scan: how artifacts are signed, how images are built, and how CVEs are triaged without slowing delivery.

On-demand valueUse the recording and checklist as a practical reference for Java container pipeline reviews.
01

Prove where your artifacts came from.

See where current controls fall short and how attestations, provenance, and signing create a verifiable build path that security and platform teams can trust during reviews.

02

Build Java images without Dockerfile drift.

Understand where Paketo Buildpacks fit, how Spring Boot integration works, how layers are produced, and when buildpacks are the better path than hand-maintained Dockerfiles.

03

Handle CVEs without chasing scanner noise.

Get a repeatable response model for hardened base images, CVE classification, safe updates, SBOMs, and provenance so scanner output turns into decisions instead of noise.

Headliners

The people behind the tools and the workflows.

Mohammad-Ali A'râbi
Speaker 01

Docker Captain · Snyk Ambassador · Author of Docker and Kubernetes Security

Mohammad-Ali A'râbi

Mohammad-Ali wrote Docker and Kubernetes Security and has spent years building, breaking, and securing containerized systems. His session connects a real supply-chain attack with the controls teams need next: attestations, provenance, and signing.

@MohammadAliEN
Docker Snyk
Supply-chain security, signing, provenance
Anthony Dahanne
Speaker 02

Paketo Java Buildpacks Maintainer · Software Developer, HeroDevs · Lead, Montreal Java User Group

Anthony Dahanne

Anthony is one of the people who builds and maintains the Paketo Java buildpacks. He works across Java, containers, CI/CD, and build tooling, and shows how buildpacks can replace fragile Dockerfile maintenance with a more consistent image-building workflow.

@anthonydahanne
HeroDevs Paketo CNCF
Buildpacks, Java images, CI/CD
Catherine Edelveis
Speaker 03

Developer Advocate, BellSoft · Co-host, CyberJAR

Catherine Edelveis

Catherine helps teams ship secure, performant cloud-native Java using OpenJDK capabilities and open-source tools. Her talk turns scanner output into a practical workflow: hardened images, SBOMs, provenance, CVE classification, and safe updates.

@cat_edelveis
Alpaquita Linux Liberica JDK BellSoft
Java security, CVE response, hardening

Free Java web conference

Two focused hours. A lot less guesswork.

JRush is a free BellSoft series with expert talks, recordings, and technical materials for teams building, running, and securing Java applications. Episode 7 focuses on container supply chain security, from signed artifacts to buildpacks and CVE response.

Free Submit the form and get the recording, materials, and checklist.
Focused Signed artifacts, buildpacks, hardened images, and CVE response in one focused episode.
Useful Use the checklist after the episode for Java container security reviews.
Loading form...

FAQ

Replay,
ready.

Submit the form once to get the Episode 7 recording, materials, and checklist in your inbox.

JRush is a free online series about Java development, cloud-native engineering, security, and practical tools for modern Java teams.

Yes. Submit the form and the autoresponder will send you the recording link, related materials, and the container security checklist for Episode 7.

It is built for Java developers, DevOps engineers, platform teams, application security engineers, and technical leads responsible for secure Java container delivery.

You will receive access to the Episode 7 replay and materials covering signed artifacts, Paketo Buildpacks, hardened Java container images, CVE response, and the container security checklist.

Docker
Snyk
HeroDevs
Paketo
CNCF
BellSoft
Liberica JDK
Docker
Snyk
HeroDevs
Paketo
CNCF
BellSoft
Liberica JDK

Final call

Leave your email. Get the recording.

Recording, checklist, links, and practical takeaways from JRush Episode 7 straight to your inbox.

Loading form...
Done. Check your inbox. We will send the Episode 7 recording, materials, and checklist to your email.
Free On demand Checklist included