• quick_snail@feddit.nl
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    3
    ·
    8 hours ago

    Docker is known insecure. It doesn’t verify any layers it pulls cryptography. The devs are aware. The tickets remain open.

    • FackCurs@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      12 minutes ago

      I don’t know if I remember correctly but I could not install Jellyfin on the latest Ubuntu server version. I had to use docker to get Jellyfin running.

    • def@aussie.zone
      link
      fedilink
      English
      arrow-up
      1
      ·
      4 hours ago

      If that is indeed true it would only mean that the docker container is vulnerable to a supply chain attack. You are not any more vulnerable to a vulnerability in the codebase.

      If you’re using the ghcr image, to post malicious code there, the attack would have already had to compromise their github infra … which would likely result in the attacker being able to push malicious code to git or publish malicious releases. Their linux distro packages are self published via a ppa/install script, which I would assume just pull from their github releases, so a bad github release would immediately be pulled as an update by users just as fast as a container.