2 ms·
"version + hash" is ugly though. I trust the publisher of my base image to keep compatibility even if they update their image and trust my test suites to detect
by dikei 3y ago
"version + hash" is ugly though. I trust the publisher of my base image to keep compatibility even if they update their image and trust my test suites to detect any issues, so I just use version without the hash nowadays.
- cratermoon 3y ago> I trust the publisher of my base image to keep compatibility even if they update their image That's how we get hacks like SolarWinds and MOVEit.
- dikei 3y agoUsing hash doesn't protect you from supply chain attack either. If the publisher is compromise, any updates could potentially be malicious. The alternative is to never update at all, which can be even worse.
- cratermoon 3y agoIt doesn't completely protect, no. Nothing does. Like much in security, defense in depth is the byword. Not checking the hash throws away a layer.