Hacker News new | ask | show | jobs
by zdw 871 days ago
Does anyone read/diff the build commands every time they get a new `latest` docker image?

There would already be implicit trust in whatever the local OS's package manager laid down, and trying to add another set of hard to audit binaries on top is not really an improvement.