Skip to content
This repository was archived by the owner on Aug 2, 2023. It is now read-only.
This repository was archived by the owner on Aug 2, 2023. It is now read-only.

Question: why use docker image from ghcr? #110

@ThijsBroersen

Description

@ThijsBroersen

I see an issue with the switch to this image because a tag or commit ref to this repo becomes less secure as this docker ref could be overwritten. Also forking this action (security practice for organisations) is not really useful as the action logic is still in remote code which can change without notice.

Is my observation correct?
I cannot find any security related pages about how to protect against unknown content in container jobs.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions