3 ms·
That's why you only pull official images and signed ones. And that's why I have an in-between step. Harbor.io allows you to configure it as a proxy with appro
by Lemmi 3y ago
That's why you only pull official images and signed ones.
And that's why I have an in-between step.
Harbor.io allows you to configure it as a proxy with approval mechanism and cve scanning
- sneak 3y agoDocker content trust (ie signature checking) is disabled by default. We won't even do this for webpages, but we find it a fine default for code that executes inside critical infrastructure. It's utter madness. Cool to see someone is doing something about it.