• @blazeknaveOP
    link
    English
    28 hours ago

    I don’t know. Last time I used it was maintained. Seems like a security vulnerability running something this critical out of date, no?

    • @[email protected]
      link
      fedilink
      English
      2
      edit-2
      8 hours ago

      Just because there is no update does not mean there are security vulnerabilities to worry about, or do you have a specific one that is not fixed?

      The attack vector seems very narrow to me. It checks the container registry downloads the containers and runs some docker commands.

      It has no interface, so in order to attack it you either have to compromise the container registry (but then it would be easier to compromise the containers you download) the secure connection used to download the containers (https is quite stable) or something on the server side.

      Also the project does not really look that abundant to me.

      EDIT: So i have not checked this, but watchtower is probably using docker for most steps anyway? So basically the only thing that could be attacked is via the notifications watchtower is sending?