astral-sh / astral-sh/uv-docker-example
Best Practices Using Docker Hardened Images?
- Dominant language
- Dockerfile
- Stars
- 809
- Forks
- 84
- PR merge metrics
- No merged PRs in 30d
Description
Today, [Docker announced](https://www.docker.com/blog/docker-hardened-images-for-every-developer/) free and open source hardened images for everyone. Included amongst that catalog is a [hardened uv image](https://hub.docker.com/hardened-images/catalog/dhi/uv).
> Docker Hardened Images are built to meet the highest security and compliance standards. They provide a trusted foundation for containerized workloads by incorporating security best practices from the start.
>
> These images are published with near-zero known CVEs, include signed provenance, and come with a complete Software Bill of Materials (SBOM) and VEX metadata. They're designed to secure your software supply chain while fitting seamlessly into existing Docker workflows.
Given the strengths of this security model, I expect hardened images will become the recommended best practice going forward. If so, could this repository be updated to reflect that direction?
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reviewing the repository's current Docker examples and the linked Docker Hardened Images and uv pages. No file or test is named, so first identify where image guidance is documented. Done means the repository's recommended approach is explicitly updated, if maintainers agree that hardened images should be the best practice.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- docker, dockerfile
- Domain
- devops, security
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100