• roofuskit@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    11 hours ago

    They worry about someone replacing the docker image on the hosting server with a malicious modified version for people to pull down during updates.

    • zalgotext
      link
      fedilink
      arrow-up
      6
      ·
      11 hours ago

      This worry exists for literally every 3rd party dependency, not just docker, and is addressed the same way - by running tests and vulnerability scans in a sandboxed test environment before shipping to prod