Sbom

Cloud, Containers & Security • Adrian Mouat, Kief Morris & Sam Newman • GOTO 2025

Cloud, Containers & Security • Adrian Mouat, Kief Morris & Sam Newman • GOTO 2025

In this panel discussion, experts Adrian Mouat, Kief Morris, and Sam Newman delve into the current landscape of cloud technology, container security, and infrastructure automation. They cover key topics such as supply chain security with Sigstore and SBOMs, the practical impact of AI on deterministic systems, the ongoing debate about cloud repatriation, and advanced Infrastructure as Code practices like TDD and managing configuration drift.

State of the Art of Container Security • Adrian Mouat & Charles Humble

State of the Art of Container Security • Adrian Mouat & Charles Humble

Adrian Mouat of Chainguard delves into container security, highlighting the flaws of traditional Linux distributions in modern, immutable environments. He explains Chainguard's approach of using 'distroless' images built from source with their Wolfi OS to achieve near-zero CVEs. The discussion covers the importance of replacing rather than updating containers, the roles of SBOMs and attestations, and key lessons from major supply chain attacks like the XZ Utils backdoor.

State of the Art of Container Security • Adrian Mouat & Charles Humble • GOTO 2026

State of the Art of Container Security • Adrian Mouat & Charles Humble • GOTO 2026

Adrian Mouat from Chainguard discusses the evolution of container security, highlighting the flaws of traditional Linux distributions for modern container workflows. He explains how Chainguard's approach of building minimal, 'distroless' images from source using Wolfi addresses the noise from vulnerability scanners, and delves into the importance of SBOMs, attestations, and a 'defense in depth' strategy, contextualized by recent major security incidents like the XZ Utils backdoor and Shai-hulud attacks.