Your Images are Out of Date (probably) - The Silent Rebuilds problem

Your Images are Out of Date (probably) - The Silent Rebuilds problem

March 4, 2026 · 37 min · Episode 191

About this episode

This episode discusses the issue of Silent Rebuilds in container base images and the importance of automating updates to prevent vulnerabilities.

Container base images (like Official Docker Hub images) are often updated without new tag versions. I call this Silent Rebuilds. There's no way to know this happens without image digest-checking automation like Dependabot and Renovate with specific settings. Failure to keep up-to-date is a prime source of vulnerabilities that can lead to serious security breaches. Automate the updates! Check out the video podcast version here: https://youtu.be/z_ahbsSc4Fo 😇 My new GitHub Security workshop has launched! A free 2-hour workshop with hands-on labs to harden your repos and your workflows from common supply chain attacks. I'll cover how attackers are getting in, and then we'll lock down a sample repo so you know what needs to be done to protect your code. You'll leave with a deep understanding of risks and mitigations as well as a list of helpful tools to keep your repos safe, including my new "gasa" tool for scanning your repos and orgs. ★Show Links★ Course waitlist: GitHub Actions Pro https://www.bretfisher.com/blog/silent-rebuilds https://github.com/BretFisher/silent-rebuilds https://www.bretfisher.com/chainguard-event Creators & Guests Cristi Cotovan - Editor Bret Fisher…

More episodes of DevOps and Docker Talk: Cloud Native Interviews and Tooling

Explore listener stats, chart rankings, contacts and more on the DevOps and Docker Talk: Cloud Native Interviews and Tooling podcast page.