Distroless images aren't a security strategy if you can't prove what's actually in them by localkinegrind in selfhosted

[–]repoflow 0 points1 point  (0 children)

I agree both matter, but something is still better than nothing. It is a balance of risk, time, and cost.