|
|
|
|
|
by cyphar
2613 days ago
|
|
Which effectively nobody does. Package managers and distribution packaging systems default to the safe method rather then defaulting to insecure rewritable tags. To be fair, the docker.io/library/* images are signed but no other images are and there are a bunch of issues with how the signing policies work for users that want to enforce that some images must be signed. |
|
Installing known-vulnerable old versions of legitimate software can be just as bad as installing custom malware.