Docker Notary
github.com
github.com
Running your own registry is probably the case you had in mind.
Paraphrasing one of my colleagues, ensuring what you're installing doesn't do anything evil is basic hygiene, it applies to all software, not just Docker containers. Notary can provide you cryptographic guarantees that the base image you're using did indeed get published by Ubuntu, or RedHat, or even me, and hasn't been tampered with between their build system and you. It's up to you whether you decide to trust those publishers.