That's why you only pull official images and signed ones.
And that's why I have an in-between step.
Harbor.io allows you to configure it as a proxy with approval mechanism and cve scanning
And that's why I have an in-between step.
Harbor.io allows you to configure it as a proxy with approval mechanism and cve scanning
We won't even do this for webpages, but we find it a fine default for code that executes inside critical infrastructure.
It's utter madness. Cool to see someone is doing something about it.