Sign in

Mohammad-Ali A'râbi

@aerabi.com
394 followers 563 following 387 posts

🐳 Docker Captain ⚓ 🐶 Snyk Ambassador 🔐 💾 Software Engineer at JobRad 🚲 📚 Author of DockerSecurity.io 🔮 Mathematician 📍 Freiburg 🇩🇪🇨🇭🇳🇱🇮🇷

PostsRepliesMedia
Mohammad-Ali A'râbi @aerabi.com · 28/09/2026
Haha, that wasn't the intention. The 0.9.5 was the final version for me, but I'm going to do a breaking change because of your feedback. 😅
110
Mohammad-Ali A'râbi @aerabi.com · 28/09/2026
Version v1.0.0 coming up. 😅
110
Mohammad-Ali A'râbi @aerabi.com · 28/09/2026
Yes, I should make it clear that it's not very educational. 🙈 Or perhaps add more education. 😅
100
Mohammad-Ali A'râbi @aerabi.com · 28/09/2026
Love it! Thanks for the shout out. 🤗 How did you like it?
110
Reposted by Mohammad-Ali A'râbi
Johannes Rabauer @rabauer.dev · 28/09/2026
I ordered my friend @aerabi.com new comic, Black Forest Shadow, about Docker/K8s security. It just arrived. He drew every panel with AI.
211
Mohammad-Ali A'râbi @aerabi.com · 17/08/2026
People often ask me about security: "What should we do if we only want to do a few things?" So, here are 5 things to do: 1⃣ Use sbx for agents 2⃣ Have 5 days of cooldown for packages 3⃣ Use Docker Hardened Images 4⃣ Generate SBOMs 5⃣ Scan them with Trivy
000
Reposted by Mohammad-Ali A'râbi
BellSoft @bellsoft.bsky.social · 17/06/2026
Talk 1 of 3 at JRush Ep.7. @aerabi.bsky.social, Docker Captain, author of "Docker and Kubernetes Security", on how to build a pipeline the breach can't get through. Free. June 23. jrush.bell-sw.com/episode7 #Java #DevSecOps
092
Reposted by Mohammad-Ali A'râbi
BellSoft @bellsoft.bsky.social · 16/06/2026
This is how supply chain attacks get through. @aerabi.bsky.social covering this live at JRush Ep.7. Free. June 23. jrush.bell-sw.com/episode7 #Java #DevSecOps
062
Mohammad-Ali A'râbi @aerabi.com · 04/05/2026
My article on Mini Shai Hulud 🪱 is out! www.dockersecurity.io/blog/mini-sh...
dockersecurity.io
Mini Shai-Hulud: The Next Evolution of NPM Supply Chain Worms
A deep dive into the Mini Shai-Hulud attack, a sophisticated NPM worm that uses the Bun runtime to bypass security and targets developer agents for persistence.
010
Mohammad-Ali A'râbi @aerabi.com · 30/04/2026
Someone sent me a DM today and said my CV-builder GitHub CI pipeline was a game-changer for him. My CV is on a GitHub repo, and it's built and published as an artifact every time you push to the repo. I gave a talk at @Docker All Hands about it once. youtu.be/DMwbXN3QKbs?...
youtu.be
Build Your CV with Docker and GitHub Actions
YouTube video by Docker
000
Mohammad-Ali A'râbi @aerabi.com · 22/04/2026
How to secure your supply chain ⛓️ with @jbaru.ch! 🤠 www.youtube.com/live/pFfJZRA...
youtube.com
AINativeDev and JavaPro at JCON Europe 2026
YouTube video by AI Native Dev
011
Mohammad-Ali A'râbi @aerabi.com · 15/04/2026
4 years ago on this day, I started a Twitter series called "Git Pro Tips". They are now available on git-weekly's website: git-weekly.com/tips
git-weekly.com
Git Tips
A collection of short and useful Git tips for all levels.
000
Mohammad-Ali A'râbi @aerabi.com · 09/04/2026
A document without a signature is just a rumor. Use Cosign to cryptographically sign your container images and attestations, ensuring complete supply chain trust. 🖋️🔐 Commando 9️⃣ Evie signs every artifact so that no CVE can tamper with it. 🤠 Meet the team: dockersecurity.io/co...
000
Mohammad-Ali A'râbi @aerabi.com · 08/04/2026
Complex builds shouldn't rely on massive CLI commands. Use Docker Bake (docker-bake.hcl) to define tags, multi-platform builds, and attestations as version-controlled code. 🏗️ Commando 8️⃣ Captain Ahab brings order to the chaos of the container whale. 🐋 Meet the team: dockersecurity.io/co...
010
Mohammad-Ali A'râbi @aerabi.com · 07/04/2026
I just completed the Docker Commandos v1.5 Asgard Mission! 🐳🛡️ Check out my certificate of completion: www.dockersecurity.io/commandos/in...
dockersecurity.io
Mohammad-Ali's Docker Commando Certificate - Docker and Kubernetes Security
Mohammad-Ali has successfully completed the Docker Commandos v1.5 Asgard Mission. Demonstrate your own mastery of supply-chain security!
000
Mohammad-Ali A'râbi @aerabi.com · 07/04/2026
Prove your vulnerability exemptions are legitimate. VEX Attestations act as tamper-proof OCI referrers that travel with your container, automating compliance. ✅ Commando 7️⃣ RuinTan, the Immortal, grants invincible, verifiable protection cards to the innocent. 💀 More: dockersecurity.io/co...
000
Mohammad-Ali A'râbi @aerabi.com · 06/04/2026
Stop scanner fatigue! Use VEX (Vulnerability Exploitability eXchange) to formally exempt CVEs that aren't exploitable in your specific context. 🔇 Commando 6️⃣ Mina, the Undead Assassin, knows exactly which monsters are a threat and which are harmless. 🧛‍♀️ Learn more: dockersecurity.io/co...
000
Mohammad-Ali A'râbi @aerabi.com · 05/04/2026
Want to slash your attack surface to zero? Use Docker Hardened Images: FROM dhi.io/node:25 Instead of: FROM node:25 Hardened Images are not hard. Commando 5️⃣ Artemisia, the Amazonian Commander, guards the heavily fortified, zero-CVE district. ⚓ www.dockersecurity.i...
000
Mohammad-Ali A'râbi @aerabi.com · 04/04/2026
Don't just generate an SBOM—attach it to your image! Using --sbom=true during build ensures the artifact travels everywhere your container goes. 🪪 Commando 4️⃣ The Valkyrie issues permanent, tamper-proof ID cards at the gates of Asgard. 🛡️ Meet the team: dockersecurity.io/co...
000
Mohammad-Ali A'râbi @aerabi.com · 04/04/2026
Nice! I'll check it out. 😊
000
Mohammad-Ali A'râbi @aerabi.com · 03/04/2026
Find the vulnerabilities before you deploy. Cross-reference your SBOM against real-time CVE databases: $ docker scout cves <image> Commando 3️⃣ Jack, the Cyborg Soldier, acts as the ultimate scanner, hunting monsters on the perimeter. 🤖 Meet the team: dockersecurity.io/co...
120
Mohammad-Ali A'râbi @aerabi.com · 02/04/2026
You can't patch what you don't know you have. Generating an SBOM gives you full visibility into every component of your software supply chain. 📋 $ docker sbom <image> Commando 2️⃣ Rothütle demands a list of all Asgard residents to hunt down hidden CVEs. Meet the team: dockersecurity.io/co...
000
Mohammad-Ali A'râbi @aerabi.com · 01/04/2026
Stop writing insecure Dockerfiles from scratch. 🛑 Use docker init to automatically generate production-ready, secure foundations based on best practices. That's how Commando 1️⃣ Gord, the Swordmaster, builds her impenetrable command center in Asgard. ⚔️ Meet the team: dockersecurity.io/co...
010
Reposted by Mohammad-Ali A'râbi
Mohammad-Ali A'râbi @aerabi.com · 31/03/2026
My JavaPro article on "10 essential Docker commands to hunt the predator" is live! We cover: 📜 SBOMs & Attestations 🛡️ Hardened Images (DHI) 🚫 VEX Exemptions 🕵️‍♂️ Zero-Day Defenses Read the full Asgard mission here 👇 javapro.io/2026/03/1... #Docker #DevSecOps #Java #ContainerSecurity
javapro.io
10 Docker Commandos: Docker Commands to Hunt the Predator - JAVAPRO International
Whose day is it on Tuesday? I mean, Wednesday is Odin’s day, Thursday is Thor’s day, and Friday is Frigg’s day, or…
043
Mohammad-Ali A'râbi @aerabi.com · 31/03/2026
My JavaPro article on "10 essential Docker commands to hunt the predator" is live! We cover: 📜 SBOMs & Attestations 🛡️ Hardened Images (DHI) 🚫 VEX Exemptions 🕵️‍♂️ Zero-Day Defenses Read the full Asgard mission here 👇 javapro.io/2026/03/1... #Docker #DevSecOps #Java #ContainerSecurity
javapro.io
10 Docker Commandos: Docker Commands to Hunt the Predator - JAVAPRO International
Whose day is it on Tuesday? I mean, Wednesday is Odin’s day, Thursday is Thor’s day, and Friday is Frigg’s day, or…
043
Mohammad-Ali A'râbi @aerabi.com · 30/03/2026
The worship material and story are available here:
dockersecurity.io
Docker Commandos — Narrative-Driven Docker Security Workshop - Docker and Kubernetes Security
A hands-on Docker security workshop told through the story of 10 commandos fighting CVE monsters in Asgard. Covering SBOMs, attestations, hardened images, VEX, Docker Bake, Cosign, and zero-day defense.
000
Mohammad-Ali A'râbi @aerabi.com · 30/03/2026
Docker Commandos landed at Rabobank! ⚔️🐳 Last week, I ran the v1.5 Asgard Mission workshop for ~30 engineers in the Netherlands—and 80% rated it 5/5! 🌟 Instead of dry security slides, we used a dark fantasy narrative to secure the container supply chain. 🧵👇
110
Mohammad-Ali A'râbi @aerabi.com · 16/02/2026
Docker Commandos coming to Cologne. 💪 On April 20–23 I'll be at @JCON.one with my workshop: ☕ »Java Supply Chain Security with Docker« SBOMs. Attestations. Docker Hardened images. Cologne is in Carnival mode—so we're bringing the energy. 🎟️ 10% off with ARABI-VIP-15 CC @docker.com
010
Mohammad-Ali A'râbi @aerabi.com · 17/12/2025
Guess who's a verified book author on Medium! aerabi.medium.com
010
Mohammad-Ali A'râbi @aerabi.com · 17/12/2025
Docker Hardened Images are now free! FROM dhi‌.io‌/node:24 From this moment on, you can use the near-zero-CVE Docker images as your base images, for free! Learn more here:
dev.to
Docker Hardened Images are Free
Docker introduced Hardened Images in 2025 as a secure-by-default base image line, designed to keep...
021
Mohammad-Ali A'râbi @aerabi.com · 07/12/2025
Container Security Advent, day 7 is rather ceremonial. Like Sunday. 🎄⚔️🤠 Tip. Rebuild your Docker images regularly and keep your dependencies in check. dev.to/aerabi/-day-...
dev.to
000
Mohammad-Ali A'râbi @aerabi.com · 05/12/2025
Container Security Advent, day 5 is here! 🌫️🌲👣 The fog thickens as Gord and Rothütle enter the valley toward Oberried… Today's security tip: Environment Drift—when small inconsistencies warp your whole system. dev.to/aerabi/day-5...
dev.to
Day 5 — The Fog in the Valley
In the previous 4 days, we followed Gord and Rothütle as they journeyed through the Black Forest....
020
Mohammad-Ali A'râbi @aerabi.com · 04/12/2025
Container Security Advent, day 4 is here! 🍽️🌒👣 Tonight in Kirchzarten, Gord keeps vigil while the village sleeps… And our security tip dives into continuous monitoring.
dev.to
Day 4 — Midnight Vigil
Gord and Rothütle arrive in Kirchzarten as dusk falls, the sky painted in deep oranges and purples....
020
Mohammad-Ali A'râbi @aerabi.com · 04/12/2025
Do I make a good Norse God? Jfokus people have created this avatar for me as I’m going to join them to talk about Docker Security. What do you think my Norse God name would be? A’rabír?
000
Mohammad-Ali A'râbi @aerabi.com · 03/12/2025
Container Security Advent, day 3 is here! 🪔📩🌃🌲
dev.to
Day 3 — Through the Gate
Night settles over Salzstraße as Rothütle and Gord arrive at Hauptmann Seutter von Loetzen's...
000
Mohammad-Ali A'râbi @aerabi.com · 02/12/2025
Day 2 of the DevSecOps Advent blog is here! 🕯️🚪📩📜 They get a typed letter!
dev.to
Day 2 — The Typed Letter
Leaving Zum Roten Bären behind them, Rothütle and Gord walk through the quiet evening streets of...
000
Mohammad-Ali A'râbi @aerabi.com · 01/12/2025
So… I started an Advent series that mixes Gothic Black Forest storytelling with container security tips, because clearly I've gone crazy. 🎩🌲💀🐋 Day 1 is live:
dev.to
Day 1 — The Red Bear Inn: Beginning the Security Advent (Defense in Depth)
Welcome to the first issue of Black Forest Shadow, an Advent series where two worlds collide: A...
020
Reposted by Mohammad-Ali A'râbi
Pradumna Saraf @pradumnasaraf.dev · 24/11/2025
Thank you, @aerabi.com, for gifting a copy of your newly published book, Docker and Kubernetes Security, and for bringing it all the way from Germany to Istanbul. I will go through it soon. If you want to learn @docker.com and Kubernetes security, I highly recommend this book.
A hand holds a blue book cover titled "Docker Kubernetes Security" by Mohammad-Ali A'râbi. The top left features the "DS DockerSecurity.io" logo and website, with "[v1.0.0]" on the top right. A white square with a plus sign is positioned between "Docker" and "Kubernetes" in the main title. Below, it details "Supply Chain Security + Runtime Protection" alongside a stylized white and light blue whale tail design. The author's name, "Mohammad-Ali A'râbi", is prominent at the bottom, with "Forewords by Hamida Rebai and Liran Tal" beneath it. A black keyboard is partially visible below the book, against a vibrant, blurred orange and red background.A white piece of paper features a handwritten dedication in blue ink at the top, reading "To the best Captain in India," followed by the signature "Mohammad-Ali." Below this, printed in a gothic-style font, is the title "Docker and Kubernetes Security." Underneath the title is a black illustration of a stylized archer, possibly a man, riding a lion-like mythological creature with a bow and arrow. The paper is placed in front of a computer monitor displaying a vibrant, blurry red and orange abstract wallpaper with a row of indistinct application icons at the bottom.
151
Mohammad-Ali A'râbi @aerabi.com · 22/11/2025
🤯 Issue #24 of Git Weekly is LIVE! I was up until midnight finishing it, but it was worth it. 🏆 My book is an official DEVOPS DOZEN 2025 FINALIST! 🎉 Plus, a deep dive into 6 powerful git diff commands and news on the new India Edition print release. www.linkedin.com/pulse/24-git...
linkedin.com
24. Git Diff Between Branches
Welcome to Git Weekly issue 24, written straight from Freiburg after two insane weeks. Before we get to today's git topic, let's do a quick recap—because a lot happened.
040
Mohammad-Ali A'râbi @aerabi.com · 20/11/2025
I just compiled a list of Docker security books for 2026. Did I miss anything?
dockersecurity.io
Top 5 Container Security Books for 2026 - Docker and Kubernetes Security
A curated list of the best books on Docker and Kubernetes security for 2026.
030
Mohammad-Ali A'râbi @aerabi.com · 19/11/2025
Our next Docker meetup in Freiburg is announced! 📅 December 11th 🕕 18:00 CET 📍 Freiburg, JobRad's campus www.meetup.com/docke...
meetup.com
Christmas with Containers 2025, Thu, Dec 11, 2025, 6:00 PM | Meetup
Christmas is around the corner, and we have a lot to unpack! Two Docker Captains are coming to Freiburg to talk about the latest features. **Timo Stark** was just awarded
020
Mohammad-Ali A'râbi @aerabi.com · 11/11/2025
I'm really proud to announce that "Docker and Kubernetes Security" has been selected as a finalist in the Best DevOps Book of the Year category for the 2025 #DevOpsDozensAwards! 🏆 Please VOTE now for the ultimate honorees in 23 categories. www.surveymonkey.com...
020
Mohammad-Ali A'râbi @aerabi.com · 10/11/2025
I often share my wins—so here are some rejections too: 🧊 My #CNCF Ambassador application was rejected (because too many Ambassadors in Germany). ☕️ My @javaland.bsky.social talk was soft-rejected and put on the waiting list. Now I get to pay for both JavaLand and KubeCon! 😅
000
Mohammad-Ali A'râbi @aerabi.com · 08/11/2025
I finished #Hacktoberfest 2025 by creating an open-source book and got a Supercontributor badge for it. Stay tuned on the book! 📻 www.holopin.io/hacktoberfes...
holopin.io
I got the Hacktoberfest 2025: Supercontributor badge from Hacktoberfest @hacktoberfest @digitalocean!
@aerabi has earned the Hacktoberfest 2025: Supercontributor badge from Hacktoberfest.
020
Mohammad-Ali A'râbi @aerabi.com · 03/11/2025
Guess who's going to Berlin on Thursday to talk about Docker security? 😅
010
Mohammad-Ali A'râbi @aerabi.com · 02/11/2025
Docker Captains Summit = pure inspiration. 🐳 Still processing what an incredible few days that was. Many thanks to Eva Bojorges and the rest of Docker team for the awesome experience. 💃🛳️ CC @docker.com
A photo of 60 Docker Captains and Docker employees
010
Mohammad-Ali A'râbi @aerabi.com · 24/10/2025
Going to Docker Captains Summit in İstanbul with Docker Captain @jkoenig.dev! 🛫 CC @docker.com 🎉
030
Mohammad-Ali A'râbi @aerabi.com · 21/10/2025
🚨 Massive Internet outage because of us-east-1 today? Well… I did warn you in my book. 😅
010
Mohammad-Ali A'râbi @aerabi.com · 17/10/2025
Git Weekly 22 is here! 🚀 And it's about fixing up your commits! ⚠️ Spoiler alert: It might also contain a discount code. www.linkedin.com/pulse/fixup-...
linkedin.com
Fixup Your Commit
Welcome to Git Weekly issue 22. In this issue, we talk about Git commit fixup! But, before that, some news from the last two weeks! My book Docker and Kubernetes Security has been published! You can g...
010
Mohammad-Ali A'râbi @aerabi.com · 17/10/2025
No more Shai Hulud!
010