Hi, I'm Nicholas 👋
I'm a Senior Platform Engineer

Buy Me A Coffee
Episode 31

Container Security with Josh Duffney

with Josh Duffney, Security Expert

April 6, 2025 Episode 31 33:37

Josh walks us through the powerful combination of open-source CNCF projects that address different aspects of container supply chain security. Learn how Trivy scans for vulnerabilities, Copasetic performs targeted patching when base image updates are available.

Josh walks us through the powerful combination of open-source CNCF projects that address different aspects of container supply chain security. Learn how Trivy scans for vulnerabilities, Copasetic performs targeted patching when base image updates are available.

Episode Highlights

  • Container supply chain security fundamentals
  • Trivy vulnerability scanning capabilities
  • Copasetic for targeted patching of base images
  • CNCF security project ecosystem

Josh demonstrates how these tools work together to create a comprehensive container security strategy.

Key Takeaways

  1. Vulnerability scanning - Using Trivy for comprehensive container security
  2. Targeted patching - Copasetic for efficient base image updates
  3. Supply chain security - End-to-end container security practices
  4. CNCF ecosystem - Leveraging open-source security tools

Resources Mentioned

  • Trivy vulnerability scanner
  • Copasetic patching tool
  • CNCF security landscape
  • Josh’s container security best practices

Topics Covered:

container-security cncf trivy devsecops