Java Developers Prefer Delegating Container Security to Providers
- Securityish
- Tools & Best Practices
Quick Summary
The Securityish Brief
BellSoft’s 2025 State of Container Security report surveyed 427 developers at Devoxx, revealing significant concerns regarding container security. Nearly half of the developers, 48 percent, expressed a preference for relying on hardened container providers rather than making their own security decisions. The survey found that 23 percent of developers had faced container-related security incidents in the past year, indicating a pressing need for better security practices.
Security was identified as the most critical factor when selecting a base container image, with 29 percent prioritizing it over performance (21 percent) and image size (17 percent). Despite this, many developers still rely on general-purpose Linux distributions (55 percent) and JDKs (69 percent), which are often bloated and require additional security measures.
Human error was cited as the leading cause of container security mistakes by 62 percent of respondents, followed by difficulties with patching (36 percent) and gaps before patch availability (32 percent). Organizational constraints, such as time and resource limitations (49 percent), further complicate security efforts.
To address these challenges, developers are employing various strategies, including using trusted container registries (45 percent), vulnerability scanning (43 percent), and software bill-of-materials (SBOM) generation (18 percent). However, 10 percent reported taking no additional security measures beyond standard tools.
BellSoft CEO Alex Belokrylov emphasized that teams desire security, efficiency, and simplicity but struggle due to their current strategies and tools. He advocates for adopting hardened images to alleviate security and maintenance burdens.
Interestingly, while AI tools are widely used in coding, they did not emerge as a significant factor in this year’s survey responses, despite 74 percent of developers using AI for coding tasks last year.
Implications for Developers
This survey highlights the ongoing struggle Java developers face in securing container environments. The reliance on general-purpose distributions may expose organizations to unnecessary risks, as these often contain excessive packages that complicate security. Developers should consider transitioning to hardened container images to mitigate these risks.
Additionally, the high percentage of security incidents attributed to human error underscores the need for better training and awareness within development teams. Organizations should prioritize security training and implement robust processes to reduce the likelihood of mistakes.
Finally, the findings suggest that organizations need to allocate more resources and time to container security, as a lack of prioritization can lead to vulnerabilities and incidents.
Key Takeaways
- Consider using hardened container images to reduce security and maintenance burdens.
- Implement regular training for development teams to minimize human error in container security.
- Prioritize security in your container selection process to mitigate risks.
- Allocate sufficient resources and time to container security initiatives within your organization.
- Utilize trusted container registries and vulnerability scanning tools to enhance security measures.
Key Terms & Concepts
- Container Security: In this article, container security refers to the practices and tools used to secure containerized applications and their environments.
- Hardened Containers: Hardened containers are pre-configured images designed to minimize vulnerabilities and reduce the security burden on developers.
- Software Bill of Materials (SBOM): An SBOM is a list of components in a software product, used to track vulnerabilities and ensure compliance.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.