you don’t trust the Docker signing process, so getting a cryptographically signed image from there seems to fail your criteria.
If the image is signed by the developer, you don’t have to trust Docker (Hub) at all.
You could build a Debian base image in-house from scratch if you wanted to and limit your tools to Debian only signed packages.
But how would I verify the source code? It would have to be signed.
It doesn’t matter if it’s the release image layer that’s signed or the source (used to build the image layer) that’s signed. Either would need to be crypographically signed by the developer.
Ultimately you need to trust something.
Indeed. You need to trust something.
However, by using cryptographic signatures on release artifacts (eg container image layers), we can reduce that risk from having to trust tens of thousands of people to just one person.
That’s a hugely meaningful reduction of risk.
I did. They’re interested. But which solution should I recommend?
Hence this question. So I can provide more useful information to the maintainer.