Comment on Docker Hub's trust signals are a lie — and Huntarr is just the latest proof

CameronDev@programming.dev ⁨22⁩ ⁨hours⁩ ago

Pull by digest just ensures that people end up running an ancient version, vulnerabilities and all long after any issues were patched, so that isn’t a one-size-fits-all solution either.

Most projects are well behaved, so pulling latest makes sense, they likely have fixes that you need. In the case of an actually malicious project, the answer is to not run it at all. Huntarr showed their hand, you cannot trust any of their code.

source
Sort:hotnewtop