Skip to content

Conversation

@twelsh-aw
Copy link
Contributor

@twelsh-aw twelsh-aw commented Jan 30, 2025

Description

Some background dialog between security, desktop, moby teams and some security researchers. At the present time, this is an accepted risk in Docker Desktop installations for Windows and should be clarified in better detail.

Related issues or tickets

PSEC-1839

Reviews

@github-actions github-actions bot added the area/desktop Issue affects a desktop edition of Docker. E.g docker for mac label Jan 30, 2025
@netlify
Copy link

netlify bot commented Jan 30, 2025

Deploy Preview for docsdocker ready!

Name Link
🔨 Latest commit 854fbd0
🔍 Latest deploy log https://app.netlify.com/sites/docsdocker/deploys/679b82d2dd270600091cab05
😎 Deploy Preview https://deploy-preview-21929--docsdocker.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site configuration.

Some background dialog between security, desktop, moby teams and some security researchers. At the present time, this is an accepted risk in Docker Desktop installations for Windows and should be clarified in better detail.
@twelsh-aw twelsh-aw marked this pull request as ready for review January 30, 2025 03:04
Copy link
Contributor

@aevesdocker aevesdocker left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @twelsh-aw. Just some style guide and formatting nits

twelsh-aw and others added 4 commits January 30, 2025 07:26
Co-authored-by: Allie Sadler <102604716+aevesdocker@users.noreply.github.com>
Co-authored-by: Allie Sadler <102604716+aevesdocker@users.noreply.github.com>
Co-authored-by: Allie Sadler <102604716+aevesdocker@users.noreply.github.com>
Co-authored-by: Allie Sadler <102604716+aevesdocker@users.noreply.github.com>
- `--quiet`: Suppresses information output when running the installer
- `--accept-license`: Accepts the [Docker Subscription Service Agreement](https://www.docker.com/legal/docker-subscription-service-agreement) now, rather than requiring it to be accepted when the application is first run
- `--no-windows-containers`: Disables the Windows containers integration
- `--no-windows-containers`: Disables the Windows containers integration. This can have security implication. For more information, see [Windows containers](/manuals/desktop/setup/install/windows-permission-requirements.md#windows-containers).
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This phrasing makes it a bit unclear that not having it is the less secure thing. Maybe we should rephrase but not sure what's the best wording

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Maybe 'This can improve security'?

Copy link
Contributor Author

@twelsh-aw twelsh-aw Jan 30, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agreed. That seems clearer. Will go with 'This can improve security.'

Longer term, we do have plans to tweak these options and make the secure option is the default behaviour. So this is all interim text anyways.

@aevesdocker aevesdocker merged commit 04d0957 into docker:main Jan 30, 2025
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/desktop Issue affects a desktop edition of Docker. E.g docker for mac

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants