• @[email protected]
    link
    fedilink
    56 hours ago

    This worry exists for literally every 3rd party dependency, not just docker, and is addressed the same way - by running tests and vulnerability scans in a sandboxed test environment before shipping to prod