Skip to content

Docker image: Add at least SHA-256 hash check for GeoIP deb package #63

@atelal

Description

@atelal

The Dockerfile does not check the hash of the GeoIP deb package.
This can be a vector of attack in a supply chain attack.
The Dockerfile should add a step to check the SHA-256 checksum of this package before installing it.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions