18 ms·
This post seems like a good time to note that by default, there's no direct way to verify that what you are downloading from dockerhub is the exact same thing t
by nstart 6y ago
This post seems like a good time to note that by default, there's no direct way to verify that what you are downloading from dockerhub is the exact same thing that exists on dockerhub [1].
Discovered after seeing a comment on HN about a bill of materials for software, i.e., a list of "approved hashes" to ensure one can audit exactly what software is being installed, which in turn led me to this issue.
[1] - https://github.com/docker/hub-feedback/issues/1925 https://github.com/docker/hub-feedback/issues/1925
- guax 6y agoI remember when we used to sign binaries and packages and nobody checked the pgp files anyways. We could have something similar better today, just need to be automated enough.
- beermonster 6y agoI think image signing support (or at least was) is not as good as it can be. It would be nice if more images were signed by publishers and verification performed by default. Even then, that only gives you a stronger indication that the image hasn't been altered since it was signed by the image author at any point after it being signed. However it is not a guarantee that the source produced the binary content. It's also not a guarantee that the image author knew what they were signing - though this is a different issue. Debian has a reproducible builds initiative[1] so people can compile packages themselves and them match byte for byte what Debian built. Not sure how far they've got with that. https://wiki.debian.org/ReproducibleBuilds https://wiki.debian.org/ReproducibleBuilds
- iam-TJ 6y agoApproximately 25,000 of just over 30,000 source packages are now reproducible builds - generating over 80,000 binary packages. See the graphic on the page you linked to: https://tests.reproducible-builds.org/debian/unstable/amd64/stats_pkg_state.png https://tests.reproducible-builds.org/debian/unstable/amd64/...
- beermonster 6y agoI did also find this https://isdebianreproducibleyet.com/ https://isdebianreproducibleyet.com/
- noisenotsignal 6y agoYou can enable client enforcement of Docker Content Trust [1] so that all images pulled via tag must be signed. Whether people are actually signing their images is a different question that I don't know the answer to. [1] - https://docs.docker.com/engine/security/trust/#client-enforcement-with-docker-content-trust https://docs.docker.com/engine/security/trust/#client-enforc...
- beermonster 6y agoPresumably that approach works best in conjunction with third-party publishers publishing signed images? Very useful for your own images that you publish in your registry though.