Uploaded April 2026 | Updated September 2026, 3 hours ago
The biggest security risk may not be the application code, but the base image you ship it with as it may contain even more CVEs over time. But fixing vulns in situ is a road to nowhere: you will waste engineering time, delay deploys, and race against the clock as new CVEs emerge constantly. The only viable solution is to harden the container image from the start.
This session explores what hardened images are and how this approach cuts the CVEs to almost zero, reduces MTTP, scanner noise, and operational toil. We will walk through containerizing a Java service on a hardened base with the best security practices in place and compare the CVE numbers before and after. The outcome: lean, transparent, deterministic container image that is secure by design, not by word.
Join Cat Edelveis and DaShaun Carter live!
The biggest security risk may not be the application code, but the base image you ship it with as it may contain even more CVEs over time. But fixing vulns in situ is a road to nowhere: you will waste engineering time, delay deploys, and race against the clock as new CVEs emerge constantly. The only viable solution is to harden the container image from the start.
This session explores what hardened images are and how this approach cuts the CVEs to almost zero, reduces MTTP, scanner noise, and operational toil. We will walk through containerizing a Java service on a hardened base with the best security practices in place and compare the CVE numbers before and after. The outcome: lean, transparent, deterministic container image that is secure by design, not by word.
Join Cat Edelveis and DaShaun Carter live!










