<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/secure-by-default-is-your-only-way-forward-7jivbwzjl" -->

---
title: Secure by default is your only way forward | daily.dev
description: Docker argues that agentic coding tools amplify old supply-chain risks because AI agents build on unaudited base images and dependencies without questioning...
canonical: https://daily.dev/posts/secure-by-default-is-your-only-way-forward-7jivbwzjl
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Secure by default is your only way forward | daily.dev
og:description: Docker argues that agentic coding tools amplify old supply-chain risks because AI agents build on unaudited base images and dependencies without questioning...
og:url: https://daily.dev/posts/secure-by-default-is-your-only-way-forward-7jivbwzjl
og:image: https://api.daily.dev/og/posts/7JivBWZJl.png
og:image:alt: Secure by default is your only way forward
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Secure by default is your only way forward

**[Docker](https://daily.dev/sources/docker)** · 9 min read · 0 upvotes · 0 comments

## Summary

Docker argues that agentic coding tools amplify old supply-chain risks because AI agents build on unaudited base images and dependencies without questioning trust, and pull packages and MCP connectors at machine speed. The piece promotes Docker Hardened Images (minimal, signed, SBOM-backed images with 7-day CVE remediation and up to 5 years of extended lifecycle support), Docker Sandboxes (MicroVM-isolated environments for agent sessions), and a hardened MCP Catalog and Toolkit with an MCP Gateway for authenticated, logged tool calls. Docker frames this as a unified foundation and security boundary for both human and agent-driven development, and teases a live session on the topic at WeAreDevelopers World Congress in San Jose.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.docker.com/blog/secure-by-default-is-your-only-way-forward>

## Questions this post answers

### What is Docker Sandbox and how does it isolate AI coding agents from the host?

Docker Sandbox runs each agent session in its own disposable, MicroVM-based environment that walls the agent off from the host at the operating-system level. Credentials are proxied in only for the task at hand and never stored inside the box, and teams control what data flows in and out, limiting damage if an infostealer lands inside a session.

_Teams isolating AI coding agents can track sandboxing and container security approaches on daily.dev._

### How much does using Docker Hardened Images reduce container attack surface compared to standard base images?

Docker Hardened Images reduce attack surface by up to 95% by shipping only what an application needs, leaving near-zero critical and high CVEs from day one. They stay compatible with existing Alpine and Debian images, so adoption requires only a one-line change to the Dockerfile's FROM line, with remediated images available within seven days of an upstream CVE fix.

_Developers evaluating hardened base images for supply-chain security can follow updates on daily.dev._

### What is Docker Extended Lifecycle Support and how long does it cover unsupported software?

Extended Lifecycle Support provides commercially backed security patches for up to five years past a package's upstream end-of-life date, so teams can keep receiving fixes and compliance answers after official support stops. This lets organizations move to a replacement on their own timeline rather than being forced by upstream's schedule.

_Teams planning migrations off unsupported dependencies can track lifecycle support options via daily.dev._

## Similar posts on daily.dev

- [Securing the software supply chain shouldn’t be hard. According to theCUBE Research, Docker makes it simple](https://daily.dev/posts/securing-the-software-supply-chain-shouldn-t-be-hard-according-to-thecube-research-docker-makes-it-df8klykdx) · Docker · 0 upvotes · 0 comments
- [Agentic AI Security: What CISOs Say About Governing AI Agents](https://daily.dev/posts/agentic-ai-security-what-cisos-say-about-governing-ai-agents-76hsg5kbg) · Docker · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#ai-agents](https://daily.dev/tags/ai-agents), [#docker](https://daily.dev/tags/docker), [#containers](https://daily.dev/tags/containers), [#mcp](https://daily.dev/tags/mcp)

[View this post on daily.dev](https://daily.dev/posts/secure-by-default-is-your-only-way-forward-7jivbwzjl)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Secure by default is your only way forward","url":"https://daily.dev/posts/secure-by-default-is-your-only-way-forward-7jivbwzjl","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/secure-by-default-is-your-only-way-forward-7jivbwzjl"},"datePublished":"2026-08-31T13:00:49.869Z","dateModified":"2026-08-31T13:02:00.300Z","description":"Docker argues that agentic coding tools amplify old supply-chain risks because AI agents build on unaudited base images and dependencies without questioning...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/7be8a0db8ab91f7126d8d6f3da0e7f7f?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/7be8a0db8ab91f7126d8d6f3da0e7f7f?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Docker","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Docker","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/8a1022bebfc04a7d824c309bd3686787","url":"https://daily.dev/sources/docker"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/secure-by-default-is-your-only-way-forward-7jivbwzjl","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,ai-agents,docker,containers,mcp","timeRequired":"PT9M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Docker","item":"https://daily.dev/sources/docker"},{"@type":"ListItem","position":3,"name":"Secure by default is your only way forward"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/secure-by-default-is-your-only-way-forward-7jivbwzjl#faq","mainEntity":[{"@type":"Question","name":"What is Docker Sandbox and how does it isolate AI coding agents from the host?","acceptedAnswer":{"@type":"Answer","text":"Docker Sandbox runs each agent session in its own disposable, MicroVM-based environment that walls the agent off from the host at the operating-system level. Credentials are proxied in only for the task at hand and never stored inside the box, and teams control what data flows in and out, limiting damage if an infostealer lands inside a session. Teams isolating AI coding agents can track sandboxing and container security approaches on daily.dev."}},{"@type":"Question","name":"How much does using Docker Hardened Images reduce container attack surface compared to standard base images?","acceptedAnswer":{"@type":"Answer","text":"Docker Hardened Images reduce attack surface by up to 95% by shipping only what an application needs, leaving near-zero critical and high CVEs from day one. They stay compatible with existing Alpine and Debian images, so adoption requires only a one-line change to the Dockerfile's FROM line, with remediated images available within seven days of an upstream CVE fix. Developers evaluating hardened base images for supply-chain security can follow updates on daily.dev."}},{"@type":"Question","name":"What is Docker Extended Lifecycle Support and how long does it cover unsupported software?","acceptedAnswer":{"@type":"Answer","text":"Extended Lifecycle Support provides commercially backed security patches for up to five years past a package's upstream end-of-life date, so teams can keep receiving fixes and compliance answers after official support stops. This lets organizations move to a replacement on their own timeline rather than being forced by upstream's schedule. Teams planning migrations off unsupported dependencies can track lifecycle support options via daily.dev."}}]}
```

