Skip to content

Publish checksums and/or signed packages #188

@konstruktoid

Description

@konstruktoid

https://download.docker.com/linux/static/, https://get.docker.com/rootless, https://docs.docker.com/engine/security/rootless/ and https://docs.docker.com/engine/release-notes/ lacks any information about manual package verification or package checksums.

When following the instruction on how to run the Docker daemon as a non-root user curl -fsSL https://get.docker.com/rootless | sh is recommended by the documentation.
There is however no verification of the downloaded packages or information on how to verify the downloaded packages in https://github.com/docker/docker-install/blob/master/rootless-install.sh

Code ref: https://github.com/docker/docker-ce-packaging/blob/master/static/hash_files

Metadata

Metadata

Assignees

No one assigned

    Labels

    community_newNew idea raised by a community contributor

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions