

5·
1 day agotrusting an oci repository is the same as trusting a distro repository, if its a dodgey unknown you got from god knows where and you cant verify, dont use it


trusting an oci repository is the same as trusting a distro repository, if its a dodgey unknown you got from god knows where and you cant verify, dont use it


People realise they can just stop viewing social feeds and the quality of life either doesn’t change or sometimes improves?
oci repositories support signing artifacts, container trust policies are a thing. bootc repos are both signed and are distro repos, ostree Fedora and ublue are using it
Just because quay.io or hub.docker can be accessed without signatures or trust doesn’t mean there aren’t repos out there using it.