Comment on Docker Hub's trust signals are a lie — and Huntarr is just the latest proof
savvywolf@pawb.social 6 days ago
I don’t think those are sufficient. We could prove that a given binary can be produced from a given repo commit, but that doesn’t actually ensure that the code itself is safe. Malicious code is malicious code even if it’s reproducible.
frongt@lemmy.zip 5 days ago
This. So you’ve pinned to a specific reproducible version. Great! It’s still horribly riddled with vulnerabilities.