• Scrollone@feddit.it
    link
    fedilink
    English
    arrow-up
    1
    ·
    3 days ago

    I know, but your security then depends on the package maintainer to keep the image up to date

    • phobiac@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      14 hours ago

      Am officially maintained Docker image is no less a security concern than an officially maintained apt repo. Depending on how you set up a container stack it can even be more secure. An attacker gaining root access to a container that you’ve given extremely selective access to the host machine is far better than them gaining root access to your actual system.