You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
With Independent Container Updates, one attack vector is to provide older container images to a client. When upgrading to a new version of the container image, we should ensure that the version is actually newer than the previous one.
One way to do this is to rely on the Bundle.logIndex field provided by signatures, which will be signed by a trusted public key.
The text was updated successfully, but these errors were encountered:
almet
added
the
icu
Issues related with independent container updates
label
Jan 30, 2025
With Independent Container Updates, one attack vector is to provide older container images to a client. When upgrading to a new version of the container image, we should ensure that the version is actually newer than the previous one.
One way to do this is to rely on the
Bundle.logIndex
field provided by signatures, which will be signed by a trusted public key.The text was updated successfully, but these errors were encountered: