
Docker SBOM Checklist for Hosting and CI Teams
Use Docker SBOMs to inventory container images, verify dependencies, connect vulnerability scanning, and prepare supply-chain reviews before production changes.

Use Docker SBOMs to inventory container images, verify dependencies, connect vulnerability scanning, and prepare supply-chain reviews before production changes.

Docker is retiring Docker Content Trust and the Notary v1 service. Use this checklist to find DCT use, plan brownout tests, and migrate to Cosign or Notation.

Update Docker Desktop for CVE-2026-5843 and recent Docker Model Runner fixes. Check admin workstations, homelab systems, and support laptops.

Patch Apache Flink CVE-2026-35194 by upgrading to fixed Flink releases, restricting query submission, and reviewing recent cluster job activity.

Patch MLflow CVE-2026-2652 by updating to 3.10.0 or newer, restricting exposed MLOps services, and reviewing recent experiment activity.