Untrusted APK Repositories
Adding custom or community APK repositories without verifying their trustworthiness in Dockerfiles.
Attackers could introduce tampered packages that execute malicious code during build or runtime, compromising containers, pipelines, and dependent images.
Adding custom or community APK repositories without verifying their trustworthiness in Dockerfiles.
Sourcery automatically identifies remote code execution due to untrusted apk packages in dockerfile and many other security issues in your codebase.