hazelcast / hazelcast/hazelcast-docker
Consider signing Container Images
- Dominant language
- Dockerfile
- Stars
- 94
- Forks
- 81
- Avg merge
- 4h 29m
- Merged PRs (30d)
- 2
Description
I understood we are currently NOT signing our container images.
I dont know how wide-spread container image signing is. But my - perhaps naive - view is that a Docker image is not too different from any sw package. And package signing in e.g. Maven repo or RPM/DEB repository has been a norm for many years. Is Docker any different?
Contributor guide
Research direction
Start by reviewing the repository's container image build and publishing configuration; no specific files or entry points are identified in the issue. Determine the project's signing requirements and workflow before proposing an implementation, since the issue currently asks whether signing should be adopted rather than defining a concrete change.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- docker
- Domain
- devops, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100