DevConf.US 2025

John Amaral

John Amaral is the CTO and co-founder of Root.io. John has more than 25 years of experience as a technologist and product development leader in information security and networking. Before Root, John was Head of Product at Cisco Cloud Security. John previously held product and engineering leadership roles at CloudLock (acquired by Cisco), Trustwave (acquired by Singtel), and Vericept, among others.

In 2007, John was selected as a top 40 under 40 business leader by American Venture Magazine. John holds an Executive MBA from MIT Sloan School of Management and a bachelor’s degree in Electrical Engineering from the University of Massachusetts.


Job title

CTO and co-founder

Company or affiliation

Root.io


Session

09-19
16:00
35min
How Secure is Your Base Image? A Live Security Test of Popular Containers
John Amaral

Most developers use container base images without fully understanding their security posture. Even “minimal” or “hardened” images can contain vulnerabilities, and static security choices alone aren’t enough.This session will test commonly used container images—Alpine, Debian, Ubuntu, and Distroless—to reveal how many vulnerabilities they contain. We’ll explore why base image security is a moving target and how teams can ensure long-term security without constant manual intervention.

Live Demo:
• Scan widely used container images to reveal hidden vulnerabilities.
• Compare audience predictions vs. real-time scan results.
• Apply automated remediation to show how security can be continuously maintained.

Security and Compliance
106 (Capacity 45)