ossf / wg-securing-critical-projects

Helping allocate resources to secure the critical open source projects we all depend on.
Apache License 2.0
318 stars 34 forks source link

curl/libcurl official docker image relevance ? #51

Open xquery opened 2 years ago

xquery commented 2 years ago

Unsure if criticality is based on latest data, though noticed when reviewing:

https://docs.google.com/spreadsheets/d/1ONZ4qeMq8xmeCHX03lIgIYE4MEXVfVL6oj05lbuXTDM/edit#gid=306266575

modulo curl project (https://curl.se) that it may not factor in the official curl docker image (https://hub.docker.com/r/curlimages/curl)

The current count is ~4B docker pulls just from docker hub (there are other registries)

https://hub.docker.com/v2/repositories/curlimages/

thx in advance