• kitnaht@lemmy.world
    link
    fedilink
    arrow-up
    1
    ·
    1 month ago

    The biggest problem that I have with docker is honestly, the fear of a supply-chain attack.

      • roofuskit@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 month ago

        They worry about someone replacing the docker image on the hosting server with a malicious modified version for people to pull down during updates.

        • zalgotext@sh.itjust.works
          link
          fedilink
          arrow-up
          1
          ·
          1 month ago

          This worry exists for literally every 3rd party dependency, not just docker, and is addressed the same way - by running tests and vulnerability scans in a sandboxed test environment before shipping to prod