Dstack-TEE / Dstack-TEE/dstack-examples
best practice: use hashes in dockerfile
Open
bug
- Dominant language
- Python
- Stars
- 27
- Forks
- 26
- Avg merge
- 1h 25m
- Merged PRs (30d)
- 7
Description
the lightclients docker-compose.yml isn't checking the downloaded files against any hardcoded value
Contributor guide
Research direction
Start in lightclients docker-compose.yml and identify each downloaded file that needs integrity verification. Add checks against hardcoded expected hashes, and consider the work complete when every downloaded file is checked before use.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- docker-compose
- Domain
- devops, security
- Issue type
- Feature
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 42/100