|
|
|
|
|
by alfanick
2 hours ago
|
|
Pinky promise? How do you prove that what I download from you is actually what you promise you've build (and that SBOM is right)? Is this certified with some digital signature? From my threat attack model, you're just yet another liability - one single service to hack all your "safe" images. |
|
Respect your viewpoint and if these images aren't for you, that's totally fine of course. Many others find it useful to have someone else doing the commoditized but hard work of building thousands of components from source continuously, assembling them into ready to run images, signing, and being as open as possible about their state and configuration as possible.