Matthias Knäpper
@knaepp.bsky.social

Meet the Ecosystem: Partners and Customers at WeAreDevelopers with Docker/#docker #container - As teams put AI agents to work, they need to move quickly without losing control of what they deploy.They’re combining models, tools, and infrastructure... tinyurl.com/23zgot4d 
6 Benefits of Sandbox Environments (and How Docker Sandboxes Delivers Them)/#docker #container - In our State of Agentic AI report, 60% of organizations reported having AI agents running in production.Those agents install packages, run scripts, and call... tinyurl.com/2brshac2 
YOLO Mode: Agent Autonomy Without the Guardrails/#docker #container - AI agents have come a long way in both capability and everyday use since generative AI went mainstream in late 2022.In Stack Overflow’s 2025 Developer Survey, 84% of developers said... tinyurl.com/27upkh9v 
Below the Harness: Governing a Multi-Model, Multi-Harness World/#docker #container - We believe the future is a multi-model, multi-harness world.And we think it needs a new trust model. In 1988, Norm Hardy described a problem that had been quietly... tinyurl.com/2bnncylg 
Docker VMM Public Beta: A Complete Overhaul, Built for Performance/#docker #container - Today we’re announcing the public beta of a fully rebuilt Docker VMM:a new first-party virtualization layer underneath Docker Desktop, optimized for containers,... tinyurl.com/292e4nrs 
A new security baseline for enterprise agentic adoption/#docker #container - Agent Baseline is a blueprint for AI adoption that defines six security outcomes for putting enterprise agents to work without giving them unchecked authority. Consider this... tinyurl.com/2y3clxas 
Governance Is a Developer Experience Problem/#docker #container - This is the third post of a 3-part series by Docker Captain Karan Verma.Catch up on Part 1:Your Laptop Is the New Production Environment and Part 2:Runtime Enforcement, Not Runtime... tinyurl.com/2bzj5lcl 
Runtime Enforcement, Not Runtime Advice/#docker #container - In Part 1, we explored why traditional security models struggle with autonomous agents.As developers begin delegating more work to AI systems, a growing amount of activity happens outside... tinyurl.com/25t7ymxb 
Agentic AI Needs Guardrails, Not Guesswork/#docker #container - What does it take to secure AI agents without slowing developers down?A recent panel explored the answer I recently joined Zach Lloyd, founder and CEO of Warp;Gavriel Cohen, co-founder and... tinyurl.com/27cd6ge7 
Coding Agent Horror Stories: The Agent That Deleted Production/#docker #container - In Part 1, we walked through six categories of AI coding agent failures and why they keep happening.The agent runs as you, with your filesystem permissions and your... tinyurl.com/287mfyvn 
IBM WebSphere Application Server is affected by a cross-site request forgery vulnerability (CVE-2026-8408) tinyurl.com/2bxx5qna 
IBM WebSphere Application Server Liberty is affected by a denial of service vulnerability due to Eclipse Parsson (CVE-2026-9563) tinyurl.com/28zgs9bh 
Your Laptop Is the New Production Environment/#docker #container - A few years ago, the most powerful AI tools in a developer’s workflow helped write code.Today, they can do much more.It’s increasingly common to hand an AI agent a task like: Read... tinyurl.com/28sm2f3t 
Automating IBM Storage FlashSystem Tasks with REST APIs, PowerShell, Scripting, and Ansible tinyurl.com/257dkh94 
Why AI Agents Need Isolation/#docker #container - AI coding agents are quickly becoming part of everyday development workflows.Today, AI tools can write and execute code, install dependencies, debug repositories, interact with APIs, automate terminal... tinyurl.com/25orkewh 
What Does EU AI Act Compliance Require?/#docker #container - For teams building AI-governed systems, the EU AI Act adds compliance obligations to every stage of the development lifecycle, from documenting training data to reporting incidents in... tinyurl.com/242sg4z3 
IBM FlashCore Module (FCM) Product Guide: Evolution of IBM FlashCore Technology and FCM5 Enhancements tinyurl.com/2y2hp3rx 
IBM WebSphere Application Server is affected by a remote code execution vulnerability (CVE-2026-9319) tinyurl.com/29az3z3e 
Docker Content Trust: Retirement and Migration Guidance/#docker #container - TLDR:Docker Content Trust (DCT) and the Notary v1 service at notary.docker.io are being fully retired (first announced in July of 2025).This blog explains what is changing, who... tinyurl.com/22aa4aqd 
PH71556:IBM WebSphere Application Server is affected by server-side request forgery (CVE-2026-9006) tinyurl.com/2bfw79bm 
IBM WebSphere Application Server is affected by server-side request forgery (CVE-2026-9006) tinyurl.com/22rg43qt 
PH71370:IBM WebSphere Application Server is affected by multiple vulnerabilities (CVE-2026-8646, CVE-2026-9320, CVE-2026-9071) tinyurl.com/2y9moegl 
PH71631:IBM WebSphere Liberty is affected by multiple vulnerabilities (CVE-2026-8646, CVE-2026-9320, CVE-2026-9071) tinyurl.com/24v2k8oz 
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities when using the Web Server Plug-ins (CVE-2026-9072, CVE-2026-8858, CVE-2026-10852) tinyurl.com/29el6xts 
Cyber Resiliency and Scanning with IBM Storage Sentinel powered by Index Engines CyberSense tinyurl.com/2cys2c5f 
Docker joins the Athena coalition: a cross-industry collaboration for supply chain security/#docker #container - The obvious takeaway from 2026’s biggest incidents is that attackers are increasingly using AI to move fast.Docker’s CISO, Mark Lechner,... tinyurl.com/2dq3gwzv 
PH71590:IBM WEBSPHERE APPLICATION SERVER IS VULNERABLE TO IDENTITY SPOOFING (CVE-2026-8644) tinyurl.com/29tpcwvy 
THE AUTHENTICATION CALL IS TRIGGERING TOKEN VALIDATION MULTIPLE TIMES AND THROWING MULTIPLE EXCEPTIONS. tinyurl.com/242tmo7j 
Base64 module in jython includes " " and "/" character irrespective of defined alternate characters. tinyurl.com/222lgglt 
Docker Hardened Images enhanced vulnerability scanning with Docker and Aikido/#docker #container - Aikido now scans Docker Hardened Images (DHI) with built-in VEX support.Vulnerabilities that Docker has verified as non-exploitable drop out of the queue... tinyurl.com/285btw3j 
5 Software Supply Chain Security Best Practices for Development Teams/#docker #container - Understanding software supply chain security is one thing.Putting it into practice across a real pipeline, with real deadlines and real constraints, is... tinyurl.com/2a2wcscj 
Addressing processing of archives with negative offsets in Tarfile Jython Module tinyurl.com/22h5aq8f 
PLUGIN-CFG.XML FILE GENERATED WITH THE GenPluginCfg.sh COMMAND FAIL DUE TO ASM JAR FILENAME CHANGE tinyurl.com/27mouhpm 
IBM Redbooks | Context Without Limits: A High-Performance KV Cache Platform for Large-Scale AI Inference tinyurl.com/2cuc7mvy 
What is AI Governance? Frameworks, Principles, and Best Practices/#docker #container - AI agents are moving fast.According to our State of Agentic AI report, 60% of organizations already have AI agents in production, yet 40% cite security and compliance... tinyurl.com/26bml29c 
PH71453:IBM WEBSPHERE APPLICATION SERVER IS AFFECTED BY REMOTE CODE EXECUTION (CVE-2026-9311, CVE-2026-9330) tinyurl.com/256q24dr 
PH71422:IBM WEBSPHERE APPLICATION SERVER IS VULNERABLE TO IDENTITY SPOOFING (CVE-2026-8644) tinyurl.com/2albx2at 
"Classes" link in "Class loader viewer" causes console log out due to missing CSRF ID in request. tinyurl.com/2d4tq2mj 
What is Software Supply Chain Security?/#docker #container - Software supply chain attacks have accelerated faster than most security teams anticipated.Sonatype’s 2026 State of the Software Supply Chain report identified more than 454,000 new... tinyurl.com/2cqs22qj 
Hardened Images Explained: Fewer CVEs, Smaller Attack Surface/#docker #container - When security teams scan their container environments for the first time, they often discover hundreds of known vulnerabilities, and almost none of them trace back to... tinyurl.com/25u28vcr