Keep It Contained Ep. 3: CI/CD for Security Teams

CI/CD pipelines are where modern software gets built and shipped, but for security teams, they're also one of the biggest untapped opportunities to catch problems early instead of reacting after the fact. In this episode of Keep It Contained, we break down: • What CI/CD actually means and why constant, incremental change makes security automation essential • The three key stages where security can be injected • Real-world example: how a scanner caught leaked temporary credentials baked into a container image • SAST, DAST, and vulnerability scanning: what they catch and where they fit in the pipeline • How to weigh the cost of a security check against how frequently you can run it • Where automation should stop and human judgment should take over • How security teams can build trust with developers instead of being seen as the "headmaster" The shift isn't just about adding more scans. It's about moving security left, cutting down alert fatigue, and giving security teams the time back to focus on the issues that actually matter. Learn more about Minimus and secure minimal container images: https://www.minimus.io

Webinar: Both Sides of Mythos: Offense, Defense, and What Comes Next
▶︎

Webinar: Both Sides of Mythos: Offense, Defense, and What Comes Next

Keynote: After the AI Hype – What’s Real, and What’s Next - Richard Campbell - 2026
▶︎

Keynote: After the AI Hype – What’s Real, and What’s Next - Richard Campbell - 2026

Keep It Contained Ep. 1: Building a Container Security Program
▶︎

Keep It Contained Ep. 1: Building a Container Security Program

DO NOT BUY: LG’s Spyware TVs, Monitors, and Wiretapping Concerns
▶︎

DO NOT BUY: LG’s Spyware TVs, Monitors, and Wiretapping Concerns

Backend web development - a complete overview
▶︎

Backend web development - a complete overview

Episode 014 — Where Systems Create Friction with Craig Isaak and Dr. Ryan Darby
▶︎

Episode 014 — Where Systems Create Friction with Craig Isaak and Dr. Ryan Darby

3 Candidates. 1 SOC Interview Question. (Who Gets The Job?)
▶︎

3 Candidates. 1 SOC Interview Question. (Who Gets The Job?)

MORNING PRAYER | Surrender Your Family to God with Faith and Walk this Day in His Peace and Prote...
▶︎

MORNING PRAYER | Surrender Your Family to God with Faith and Walk this Day in His Peace and Prote...

Mayor Zohran Mamdani on Socialism, Politics & NYC | The Weekly Show with Jon Stewart
▶︎

Mayor Zohran Mamdani on Socialism, Politics & NYC | The Weekly Show with Jon Stewart

Demo: Migrate Node, Mongo, and Python to Minimus Hardened Container Images
▶︎

Demo: Migrate Node, Mongo, and Python to Minimus Hardened Container Images

Keep It Contained Ep. 2: Evaluating Minimal Container Images
▶︎

Keep It Contained Ep. 2: Evaluating Minimal Container Images

Last Lecture Series: “How to Win Without Crushing Your Soul” - Graham Weaver
▶︎

Last Lecture Series: “How to Win Without Crushing Your Soul” - Graham Weaver

The Invisible Phone: Ditch PSTN Forever – No IMEI, No IMSI, No KYC, Total Stealth Calling
▶︎

The Invisible Phone: Ditch PSTN Forever – No IMEI, No IMSI, No KYC, Total Stealth Calling

Hjalmar Schacht: The Financial Genius Who Funded Hitler’s War Machine Documentary
▶︎

Hjalmar Schacht: The Financial Genius Who Funded Hitler’s War Machine Documentary

The final filmed interview with Sir Alex Younger, the late MI6 chief | The Economist
▶︎

The final filmed interview with Sir Alex Younger, the late MI6 chief | The Economist

John Morello and Frank Kim: AI, Vulnerability Management, and Secure by Default
▶︎

John Morello and Frank Kim: AI, Vulnerability Management, and Secure by Default

Politics Chat, July 23, 2026
▶︎

Politics Chat, July 23, 2026

John Morello & Chenxi Wang: How AI Is Changing Vulnerability Discovery
▶︎

John Morello & Chenxi Wang: How AI Is Changing Vulnerability Discovery

John Morello and Justin Somaini: AI, Automation, and the Real Cybersecurity Problem
▶︎

John Morello and Justin Somaini: AI, Automation, and the Real Cybersecurity Problem

Debugging Distroless Containers with Podman
▶︎

Debugging Distroless Containers with Podman