Comment on Replacement for Docker Content Trust (DCT)

<- View Parent
K3can@lemmy.radio ⁨1⁩ ⁨week⁩ ago

Sounds like you’re fairly invested in this, so why not reach out to the maintainer? It shouldn’t be difficult for them to offer a signed hash.

…But keep in mind that most images are built using base images and various other dependencies, which could all also be compromised. It might be better to eliminate docker entirely.

original
Sort:hotnewtop