This is an intentional duplicate of #5874 which has been closed and ignored for months.
Where are the signatures for the official library images?
If docker has for some reason decided to stop signing the official images, please make a public announcement. Otherwise you're leaving us hanging like a teenaged love interest, but with a hella lot more on the line.
Please keep the hyperbole to a minimum here. There has not been a compromise here, and you're frankly barking up the wrong tree in this repository, which is why the previous issue is closed.
As stated in that previous thread, the maintainers of this repository have no control over nor involvement in the signing process of the images we publish (however much we'd love to change that if someone at Docker Inc reading this would like to collaborate on making changes there!). Yelling about it here does not get the attention of the folks who control that signing process.
What I do know is that the service which Docker runs for signing our images has had some stability issues, but as stated above, nobody on this repository is directly involved there so we really cannot give you any more information than that, however much I wish I could.
Thanks for the reply @tianon. I added the hyperbole merely to get attention. I'll remove the mention of compromise from the title.
I hadn't heard anything back from the docker team in the intervening months, and since that issue (and this repo) were the only public nexus of communication about this issue, I figured here was better than shouting into the void. The closed issue at some point did in fact elicit a reply from the docker team.
Really, I'm merely looking for some communication, even if that is _"It's still broken, but we plan to fix it"_ or _"We may or may not fix it, but either way you probably shouldn't rely on it"_.
From the POV of a new docker user this does seem very odd indeed. If I pull node:alpine with content trust enabled I get a 13 month old image with vulnerabilities. If I pull with it disabled I get the eight day old image I was expecting.
As prospective docker customers I guess we're best talking to them directly about the fact this hasn't exactly inspired confidence!
I am quite amazed landing here...
Through the contact form I sent the following question:
When enabling Docker Content Trust, I receive outdated versions of images, for example Python-3.9.0 instead of Python-3.9.5.
This seems to be an old issue:
https://github.com/docker-library/official-images/issues/6838Could you please update the docs in a clear way to inform that although DCT provides verified images, quite often they are outdated... a.k.a. insecure?
Most helpful comment
From the POV of a new docker user this does seem very odd indeed. If I pull node:alpine with content trust enabled I get a 13 month old image with vulnerabilities. If I pull with it disabled I get the eight day old image I was expecting.
As prospective docker customers I guess we're best talking to them directly about the fact this hasn't exactly inspired confidence!