Skip to content

An external dependency to groundnuty/k8s-wait-for is pinned using tag. #144

@aaguiarz

Description

@aaguiarz

Source tags can be overwritten in case of a supply chain attack and a compromised image may be pulled down.

The risk is greater in the case of external, third party dependencies not under the projects control.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    Status

    Backlog

    Status

    Todo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions