news
Containers Considered Dangerous
-
Akseli Lahtinen ☛ My PostgreSQL database got nuked lol
Check your docker compose files for the port and be explicit about it being localhost only if needed
-
[Repeat] Techstrong Group Inc ☛ Software Supply Chain Security: Why 99% of Your Container is Mystery Code
That single line pulled in 19,000 files, 700 binaries, and a complete Linux operating system. The actual business logic in a typical container represents 1% of what ends up in production. The other 99%? Mystery meat.
And guess how many lines it took me to fix all these problems? Yes, you might have guessed it right. One line.
The truth is, your code usually isn’t the source of your Software Supply Chain Security problems. Let’s take a look at how to take back control of your code, without any mystery in it.