Comment on Replacement for Docker Content Trust (DCT)
maltfield@slrpnk.net 3 weeks ago Yes, you have to trust someone.
My point is that cryptographic signatures can reduce that risk from having to trust tens of thousands of people to just one person.
That’s a hugely meaningful reduction of risk.
K3can@lemmy.radio 2 weeks ago
Sounds like you’re fairly invested in this, so why not reach out to the maintainer? It shouldn’t be difficult for them to offer a signed hash.
…But keep in mind that most images are built using base images and various other dependencies, which could all also be compromised. It might be better to eliminate docker entirely.
I did. They’re interested. But which solution should I recommend?
Hence this question. So I can provide more useful information to the maintainer.