Comment on Docker Hub's trust signals are a lie — and Huntarr is just the latest proof

<- View Parent
Kushan@lemmy.world ⁨1⁩ ⁨week⁩ ago

I generally agree with the sentiment but don’t pull by latest, or at the very least don’t expect every new version to work without issue.

Most projects are very well behaved as you say but they still need to upgrade major versions now and again that contains breaking charges.

I spebt an afternoon putting my compose files into git, setting up a simple CI pipeline and use renovate to automatically create PR’s when things update. Now all my services are pinned to specific versions and when there’s an update, I get a PR to make the change along with a nice change log telling me what’s actually changed.

It’s a little more effort but things don’t suddenly break any more. Highly recommend this approach.

source
Sort:hotnewtop