Skip to content

wolfi and slim toolkit #15077

Answered by amouat
DocKDE asked this question in Q&A
Discussion options

You must be logged in to vote

Yes, I would say there's a philosophical difference here. We try to build small images from the start and slim tries to reduce larger images. Both are valid approaches, but we would rather fix any problems by reducing our packages than running slim.

Busybox is an interesting one. From a secuirty perspective it's a pain as there are often powerful utilities in there for attackers can use. We've already removed a lot of functionality from busybox, but we're currently looking at reducing it even further. I don't think slim will help here as it's a single binary; we just need to choose the right compile flags.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by amouat
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants