Hacker News new | ask | show | jobs
by bityard 910 days ago
Docker images can be signed. And docker images are no different than any other software: if you don't trust who it's from, don't run it.

(Whether the standard docker tooling or user decides to validate signatures is another thing.)