astral-sh / astral-sh/uv-docker-example

Best Practices Using Docker Hardened Images?

Open
#74 0 comments 7 reactions 0 assignees View on GitHub
Dominant language
Dockerfile
Stars
809
Forks
84
PR merge metrics
No merged PRs in 30d

Description

Today, [Docker announced](https://www.docker.com/blog/docker-hardened-images-for-every-developer/) free and open source hardened images for everyone. Included amongst that catalog is a [hardened uv image](https://hub.docker.com/hardened-images/catalog/dhi/uv).

> Docker Hardened Images are built to meet the highest security and compliance standards. They provide a trusted foundation for containerized workloads by incorporating security best practices from the start.
>
> These images are published with near-zero known CVEs, include signed provenance, and come with a complete Software Bill of Materials (SBOM) and VEX metadata. They're designed to secure your software supply chain while fitting seamlessly into existing Docker workflows.

Given the strengths of this security model, I expect hardened images will become the recommended best practice going forward. If so, could this repository be updated to reflect that direction?

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reviewing the repository's current Docker examples and the linked Docker Hardened Images and uv pages. No file or test is named, so first identify where image guidance is documented. Done means the repository's recommended approach is explicitly updated, if maintainers agree that hardened images should be the best practice.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, dockerfile
Domain
devops, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.