▲ | progbits 5 days ago | ||||||||||||||||
I agree, but I'm not spending my time arguing with PCI auditors. Also it's safer from supply chain attacks. Malware inserted via compromised docker hub tokens is a growing threat. | |||||||||||||||||
▲ | firesteelrain 5 days ago | parent | next [-] | ||||||||||||||||
Right, I deal with NIST 800-53 based things where we have heavy albeit manual auditing. We pull from Iron Bank mostly but also employ Nexus Firewall. People can’t pull direct Docker Hub. | |||||||||||||||||
| |||||||||||||||||
▲ | cmckn 5 days ago | parent | prev [-] | ||||||||||||||||
Constantly updating to the latest version of innumerable software projects is safer from supply chain attacks? :) My experience has been that the cost of “patching” is often bugs and instability, having gained nothing security-wise. |