

22·
1 day agoYeah this is why I use Debian instead of containers, you can read the release notes on a stable release.


Yeah this is why I use Debian instead of containers, you can read the release notes on a stable release.


What is securing those private channels?
Whatever vulnerability there is in that will basically give them root on your home sever right?


None, if it’s not in a Debian repo I don’t deploy it on my stable server.
It’s not really about docker itself, I just don’t think software has married enough if it’s not packaged properly


I use Debian


Outbound firewall and SMAC protections.
If you compromise my server you’ll struggle to phone home without manual intervention, which is good enough to stop botnets.
This is what good distros do, well some of them, I don’t think low touch repos like AUR/Homebrew/PPA’s would catch this, but I doubt huntarr will ever make it to Debian.
Ofc the trend of running upstream unverted containers undermines this.