Even worse, what happens when they MITM all of the installs because the docker container has really bad security such as:
RUN wget http://nginx.org/download/nginx-1.18.0.tar.gz
https://github.com/signalapp/Signal-TLS-Proxy/blob/master/ng...
Installing via HTTP, with no verification of installer seems like a reallyyyyy bad idea.