Already using slim or distroless images?
Then this is where things get interesting: what still separates a smaller image from one you can verify, patch, and enforce in production.
@cat_edelveis shows what to look for and where hardened images fit into a real security pipeline.
Delivering #LibericaJDK: supported, @Java standard compatible binaries. Among Top-5 @OpenJDK contributors.
- Artifact signing is one question. JRush Episode 7 goes much further: SBOMs, provenance, buildpacks, hardened images, CVE response, and the practical trade-offs between them. Plenty to take back to your pipeline. Episode: youtube.com/live/AsGmInC_6… Checklist:
- JEP 538 brings the PEM API back for a third preview in #Java27. PEMEncoder encodes keys, certificates, and CRLs as PEM. PEMDecoder reads them back into typed Java objects, without manual Base64 handling, header parsing, or KeyFactory setup.
- September 2026 is almost here, and Oracle JDK 21 users have a decision to make. Updates released after that point are planned to move from NFTC to OTN. Your applications will keep running, but keeping them securely updated may no longer be free. 🧵
- Alpine or not? Small size is the easy part of the answer. This video gets into everything that can change it once the image meets a real workload. youtu.be/37tnF-THIkE

