• Drasla@lemmy.studio
    link
    fedilink
    arrow-up
    1
    arrow-down
    1
    ·
    15 hours ago

    You mean compromised code sneaking into Docker images? Or a DOS on dockerhub?

    • roofuskit@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      12 hours ago

      They worry about someone replacing the docker image on the hosting server with a malicious modified version for people to pull down during updates.

      • GreenKnight23@lemmy.world
        link
        fedilink
        arrow-up
        3
        ·
        14 hours ago

        ddos is vaguely related to a supply chain attack in the sense that it can be used as a distraction to implement said chain attack. it was pretty common tactic at one point.

        • disrupt services
        • implement bad library in backups as all focus turns to production
        • destroy production enough to require a restore

        I think this is what they meant, but it’s a stretch.