hazelcast / hazelcast/hazelcast-docker

Consider signing Container Images

Open
#254 1 comment 0 reactions 0 assignees View on GitHub
internal Type: Enhancement
Dominant language
Dockerfile
Stars
94
Forks
81
Avg merge
4h 29m
Merged PRs (30d)
2

Description

I understood we are currently NOT signing our container images.

I dont know how wide-spread container image signing is. But my - perhaps naive - view is that a Docker image is not too different from any sw package. And package signing in e.g. Maven repo or RPM/DEB repository has been a norm for many years. Is Docker any different?

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the repository's container image build and publishing configuration; no specific files or entry points are identified in the issue. Determine the project's signing requirements and workflow before proposing an implementation, since the issue currently asks whether signing should be adopted rather than defining a concrete change.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker
Domain
devops, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.