data-api-builder icon indicating copy to clipboard operation
data-api-builder copied to clipboard

Docker Hub - publisher - Trusted Content

Open seantleonard opened this issue 1 year ago • 2 comments

Discussed in https://github.com/Azure/data-api-builder/discussions/2158

Originally posted by wrutkowski-xebia April 10, 2024 Hello,

Why image on Docker Hub is not published by Verified Publisher or Docker Official Image?

mcr.microsoft.com/azure-databases/data-api-builder:tag https://hub.docker.com/_/microsoft-azure-databases-data-api-builder

image

seantleonard avatar Apr 17 '24 15:04 seantleonard

Looking into this so far, these badges aren't indicative of binary signing or anything specific to our build process. Instead, these are programs hosted by Docker which either have a paid aspect to them or separate proposal process to onboard.

  1. Docker Official Image is a subjective selection program by Docker.
  2. Docker Verified Publisher program Info and sign up seems to be a partner program. need to see whether Microsoft already has this and how we can update our Deployment piplines to utilize that status, if available.

seantleonard avatar Apr 30 '24 19:04 seantleonard

Not a blocker at the moment. These are arbitrary (and in some cases) paid programs.

seantleonard avatar May 06 '24 15:05 seantleonard

Can revisit in the future if needed, but since these are paid, arbitrary programs, we don't have the bandwidth to accommodate at this time.

seantleonard avatar May 16 '24 22:05 seantleonard