Docker image has no signer when running "docker trust inspect"

Viewed 74

I'm trying to determine which alpine image version on DockerHub I should use.

I saw the latest tag for alpine on DockerHub (as of 04/23/2021) is 3.13.5 so I ran this command:

$ docker trust inspect --pretty alpine:3.13.5

No signatures for alpine:3.13.5

I checked an older version of alpine and got this:

$ docker trust inspect --pretty alpine:3.12.1

Signatures for alpine:3.12.1

SIGNED TAG   DIGEST                                                            SIGNERS
3.12.1       c0e9560cda118f9ec63ddefb4a173a2b2a0347082d7dff7dc14272e7841a5b5a  (Repo Admin)

Does it mean I should not trust alpine:3.13.5 since there is no signer? Thanks alot!

1 Answers

Image signing has broken before in the past so I suspect this is just something down upstream at Docker (I'm pinging some of my contacts on this, but the weekend has already started for many so it might be a bit until they respond).

Notary version 1 hasn't had much uptake, which is why this can go so long with so few noticing it isn't working. We're actively working on a Notary version 2 that will hopefully fix a lot of the issues that limited the adoption of version 1, but that will be a while until version 2 is GA and we can phase out version 1.

Until then, I suspect the latest alpine image is safe, and for added assurance, running the image through a vulnerability scanner would be a useful way to minimize risks. Particularly since the vulnerability scanner will indicate known vulnerabilities in old versions of an image that would still be signed.

Related