Container security is moving from vulnerability detection to attack surface reduction

Container security has spent years operating around a familiar cycle: scan, identify vulnerabilities, patch and repeat. But as the volume of vulnerabilities grows and regulatory requirements move deeper into software delivery workflows, that model is becoming increasingly difficult for engineering teams to sustain.

TheCUBE Research’s 2026 research found that 58% of respondents use vulnerability scanning as a software supply chain security control. At the same time, 47% identify software supply chain security as a top investment priority, signaling that organizations recognize the problem but are still heavily dependent on detecting vulnerabilities after they enter the software stack.

In the latest episode of theCUBE Research’s AppDevANGLE podcast, I spoke with Sudeep Goswami, chief executive officer of Traefik Labs, about an alternative approach: reducing the software included in container infrastructure so that fewer vulnerabilities exist in the first place. Traefik is pursuing that strategy through Distro Zero, an approach designed to strip away operating system components and dependencies that aren’t necessary to run the application.