Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> "Write your own Dockerfiles" is not useful security advice.

I actually think it is. It makes you more intimate with the application and how it runs, and can mitigate one particular supply-chain security vector.

Agreeing that the reasoning is confused but that particular advice is still good I think.





Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: