• roofuskit@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      They worry about someone replacing the docker image on the hosting server with a malicious modified version for people to pull down during updates.

      • zalgotext@sh.itjust.works
        link
        fedilink
        arrow-up
        1
        ·
        1 month ago

        This worry exists for literally every 3rd party dependency, not just docker, and is addressed the same way - by running tests and vulnerability scans in a sandboxed test environment before shipping to prod