home.social

#docker-hub — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #docker-hub, aggregated by home.social.

fetched live
  1. Docker Fundamentals: теория и базовая эксплуатация

    Я очень рад, что существует такая технология, как Docker, и внедряю её в проекты и инфраструктуру клиентов. Однако есть одно «но»: многие не понимают, что это и зачем оно нужно, а объяснять иногда достаточно сложно (особенно повторять каждый раз каждому человеку, да и есть шанс что-то упустить). В этой статье вы узнаете базу по Docker, где найти практику и актуальные знания. Технология будет полезна многим: от специалистов по безопасности до разработчиков. А сама статья будет познавательна для тех, кто только изучает работу Docker и хочет узнать ответы на вопросы, которые часто задаются на собеседованиях, где требуется Docker. Приступим! Читать

    habr.com/ru/companies/ruvds/ar

    #docker #dockercompose #dockerfile #docker_swarm #dockerhub #devops #инструменты_разработки #инструменты #инструменты_разработчика #ruvds_статьи

  2. Checkmarx KICS Tool Compromised in Supply-Chain Breach

    A critical vulnerability was discovered in the Checkmarx KICS tool due to a supply-chain breach, where a malicious Docker image was briefly hosted on DockerHub, exposing users to potential security risks between April 22, 2026, 14:17:59 UTC and 15:41:31 UTC. The breach was quickly identified and rectified, with affected tags restored…

    osintsights.com/checkmarx-kics

    #SupplyChainBreach #Dockerhub #CheckmarxKics #EmergingThreats #TrojanizedImage

  3. Checkmarx nel mirino di TeamPCP: l’immagine Docker ufficiale di KICS trojanizzata per esfiltrare i segreti dell’infrastruttura

    Per la seconda volta in due mesi, il gruppo TeamPCP ha violato la supply chain di Checkmarx, pubblicando immagini Docker trojanizzate del security scanner KICS ed estensioni VS Code maligne capaci di rubare token cloud, credenziali GitHub e chiavi SSH. Il payload mcpAddon.js, consegnato tramite runtime Bun da un commit retrodatato, punta a trasformare ogni pipeline CI/CD in un punto di esfiltrazione.

    insicurezzadigitale.com/checkm

  4. Checkmarx nel mirino di TeamPCP: l’immagine Docker ufficiale di KICS trojanizzata per esfiltrare i segreti dell’infrastruttura

    Per la seconda volta in due mesi, il gruppo TeamPCP ha violato la supply chain di Checkmarx, pubblicando immagini Docker trojanizzate del security scanner KICS ed estensioni VS Code maligne capaci di rubare token cloud, credenziali GitHub e chiavi SSH. Il payload mcpAddon.js, consegnato tramite runtime Bun da un commit retrodatato, punta a trasformare ogni pipeline CI/CD in un punto di esfiltrazione.

    insicurezzadigitale.com/checkm

  5. Malicious Docker Images Compromise Checkmarx Supply Chain

    Malicious Docker images compromised the Checkmarx supply chain by embedding a tampered KICS binary that secretly collected and sent sensitive data to an external endpoint. This sneaky data-exfiltration risk put users at risk, thanks to an altered scan report generated by the poisoned image.

    osintsights.com/malicious-dock

    #MaliciousDockerImages #SupplyChain #DockerHub #DataExfiltration #Kics

  6. Momentan geht mir Dockerhub voll aufn Sack. Angeblich Pulllimit erreicht (100 Pulls in 6 Stunden)

    IM LEBEN NICHT! :neocat_angry:

    #Docker #Dockerhub

  7. Momentan geht mir Dockerhub voll aufn Sack. Angeblich Pulllimit erreicht (100 Pulls in 6 Stunden)

    IM LEBEN NICHT! :neocat_angry:

    #Docker #Dockerhub

  8. Finally got time to update the source of my bentopdf instance, to avoid pulling from the "discontinued" docker hub version

    Remember to switch to ghcr.io/alam00000/bentopdf-simple:1.15.3 to avoid being compromised by the other version

    More context: github.com/alam00000/bentopdf/

    #selfhosted #selfhosting #pdf #homelab #security #docker #dockerhub #ghcr #

  9. Finally got time to update the source of my bentopdf instance, to avoid pulling from the "discontinued" docker hub version

    Remember to switch to ghcr.io/alam00000/bentopdf-simple:1.15.3 to avoid being compromised by the other version

    More context: github.com/alam00000/bentopdf/

    #selfhosted #selfhosting #pdf #homelab #security #docker #dockerhub #ghcr #

  10. Nhà phát triển Bentopdf vừa mất quyền kiểm soát namespace trên Docker Hub, đưa ra cảnh báo: **Không pull bentopdf/** và **không cập nhật container lên phiên bản mới**. Tới thời điểm này vẫn chưa có thông tin cập nhật mới; nhà phát triển im lặng trên GitHub. #Docker #Bentopdf #SelfHosted #DockerHub #CôngNghệ #Vietnam #TinCôngNghệ

    reddit.com/r/selfhosted/commen

  11. Nhà phát triển Bentopdf vừa mất quyền kiểm soát namespace trên Docker Hub, đưa ra cảnh báo: **Không pull bentopdf/** và **không cập nhật container lên phiên bản mới**. Tới thời điểm này vẫn chưa có thông tin cập nhật mới; nhà phát triển im lặng trên GitHub. #Docker #Bentopdf #SelfHosted #DockerHub #CôngNghệ #Vietnam #TinCôngNghệ

    reddit.com/r/selfhosted/commen

  12. 📦 Compressed 7z archive created automatically after scan completion

    ⚙️ Environment variables: HOSTNAME (log suffix), EXIT_AFTER_RUN, CLEAN_LOGS_AFTER_ARCHIVE, CLAM_EXCLUDE_TMP

    🔒 Host filesystem mounted at /host in read-only mode for safe scanning

    🚀 Available on #DockerHub: michabbb/security-scanner

    🔗 github.com/michabbb/docker-sec

  13. 📦 Compressed 7z archive created automatically after scan completion

    ⚙️ Environment variables: HOSTNAME (log suffix), EXIT_AFTER_RUN, CLEAN_LOGS_AFTER_ARCHIVE, CLAM_EXCLUDE_TMP

    🔒 Host filesystem mounted at /host in read-only mode for safe scanning

    🚀 Available on #DockerHub: michabbb/security-scanner

    🔗 github.com/michabbb/docker-sec

  14. We're thinking about providing a self-hosted image proxy cache for CodeFloe, limited to CodeFloe CI servers to prevent abuse.

    Read more here: forum.codefloe.com/t/dockerhub

    #codefloe #dockerhub #harbor #forgejo

  15. In basic concept, this would be similar to what #Harbor can do with #DockerHub.

  16. In basic concept, this would be similar to what #Harbor can do with #DockerHub.

  17. DockerHub удаляет старые JDK теги — ваши пайплайны могут быть под угрозой

    Если вы используете openjdk:<tag> образы в CI/CD и пулите их с Docker Hub, Вам следует оперативно перепроверить свои пайплайны: мейнтейнеры DockerHub удалили ряд устаревших тегов без громких анонсов. Некоторые сборки уже не работают — пострадали сотни пользователей. В данной новости, эксперт сообщества Spring АйО Михаил Поливаха рассказывает, что произошло, почему это проблема, и какие есть альтернативы.

    habr.com/ru/companies/spring_a

    #java #kotlin #docker #dockerhub #deploy #devops #spring #spring_boot #spring_framework #springboot

  18. Todo for the weekend: set up my own Docker registry so I don't have to rely on the Docker Inc registry...

    #Docker #AWS #Dockerhub #FullServiceDisruption

  19. FYI Docker Hub is experiencing an outage at the moment.

    Attempting to pull images from hub.docker.com may fail. Seeing some builds fail with "401 Unauthorized"

    dockerstatus.com/

    #Docker #DockerHub