cider-security-research / cicd-goat

A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.
Apache License 2.0
1.94k stars 321 forks source link

Docker Hub - Image Access Management restricts ability for organizations to run cicd-goat #41

Closed abacchi closed 2 years ago

abacchi commented 2 years ago

Paid subscriptions of Docker Hub for organizations allow for the restrictions of what repositories their members can interact with.

https://docs.docker.com/docker-hub/image-access-management/ With image access management turned on, community images are restricted [blocked] by default. This covers the cicd-goat images and disallows them from running the platform.

There does not seem to be a way for administrators to allow individual Docker Hub repositories in the image access management settings.

Some solutions off the top of my head don't sound great:

TupleType commented 2 years ago

Hey @abacchi,

Hosting the images in a different repository does not seem to have high demand. Becoming a Docker Verified Publisher is not prioritized at the moment. Please address this issue within your organization.

Thank you.