Developer Toolsdocker_blogAlphaLab AI score 26/100
Docker extends security logging to SIEMs for full policy audit trail
Docker has enhanced its AI Governance product to automatically stream all policy decisions to existing SIEM systems while maintaining a searchable record in Docker Cloud. The update addresses growing supply chain threats, with Docker CISO Mark Lechner characterizing recent attacks on tools like Trivy and KICS as a 'permanent shift in the threat landscape'. These changes complement Docker's existing supply chain security measures, including over 4,000 hardened images built from source with SLSA Build Level 3 provenance and signed SBOMs. The platform currently handles 3.5 million weekly pulls of hardened components, which include not just container images but also Helm charts and extended lifecycle support packages.