cm0002@lemmy.world to Programmer Humor@programming.dev · 17 hours agoHow Docker was bornlemmy.mlimagemessage-square34fedilinkarrow-up1624arrow-down116cross-posted to: [email protected]
arrow-up1608arrow-down1imageHow Docker was bornlemmy.mlcm0002@lemmy.world to Programmer Humor@programming.dev · 17 hours agomessage-square34fedilinkcross-posted to: [email protected]
minus-squareroofuskit@lemmy.worldlinkfedilinkEnglisharrow-up2·12 hours agoThey worry about someone replacing the docker image on the hosting server with a malicious modified version for people to pull down during updates.
minus-squarezalgotext@sh.itjust.workslinkfedilinkarrow-up6·11 hours agoThis worry exists for literally every 3rd party dependency, not just docker, and is addressed the same way - by running tests and vulnerability scans in a sandboxed test environment before shipping to prod
minus-squareroofuskit@lemmy.worldlinkfedilinkEnglisharrow-up2·11 hours agoI was just answering a question. I had the same response above.
minus-squarezalgotext@sh.itjust.workslinkfedilinkarrow-up2·10 hours agoAnd I was just adding extra details
They worry about someone replacing the docker image on the hosting server with a malicious modified version for people to pull down during updates.
This worry exists for literally every 3rd party dependency, not just docker, and is addressed the same way - by running tests and vulnerability scans in a sandboxed test environment before shipping to prod
I was just answering a question. I had the same response above.
And I was just adding extra details