tools/docker/dockerfile_best_practices.md
Dockerfile Best Practices: Instruction-Level Authoring Guide
Non-default BuildKit build-security flags: secret mounts, SBOM/provenance attestations, distroless size/CVE numbers, and named Docker Hub supply-chain incidents (Leaky Vessels CVEs, JFrog imageless-repo campaign).