I’m talking not only about trusting the distribution chain but about the situation where some services dont rebuild their images using updated bases if they dont have a new release.

So per example if the particular service latest tag was a year ago they keep distributing it with a year old alpine base…

  • B0rax@feddit.org
    link
    fedilink
    English
    arrow-up
    65
    arrow-down
    1
    ·
    23 days ago

    No. I only have a limited amount of time for maintaining my home infrastructure. I chose my battles.

    • jimmy90@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      edit-2
      22 days ago

      i do look out for new images that could be a drop in replacement

      the new no-distro builds of containers is very interesting

      • femtek@lemmy.blahaj.zone
        link
        fedilink
        English
        arrow-up
        1
        ·
        16 hours ago

        Yeah, I saw that another person forked NPM and used that for awhile before moving on to something else. Work is handled outside of myself but I don’t do it at home. I did learn how to though to get an understanding of it.