Skip to content

dhi: add deb hsp#25155

Open
craig-osterhout wants to merge 2 commits into
docker:mainfrom
craig-osterhout:dhi-debian-hsp
Open

dhi: add deb hsp#25155
craig-osterhout wants to merge 2 commits into
docker:mainfrom
craig-osterhout:dhi-debian-hsp

Conversation

@craig-osterhout
Copy link
Copy Markdown
Contributor

@craig-osterhout craig-osterhout commented May 22, 2026

Description

Added deb hardened system package CLI workflows.
Pending new dhictl CLI release to support docker dhi auth deb

Will update CLI reference in separate PR.

https://deploy-preview-25155--docsdocker.netlify.app/dhi/how-to/hardened-packages/

Related issues or tickets

https://docker.slack.com/archives/C04M34MRQS1/p1779399631450319

Reviews

  • Technical review
  • Editorial review
  • Product review

Signed-off-by: Craig Osterhout <craig.osterhout@docker.com>
@craig-osterhout craig-osterhout added the status/do-not-merge Pull requests that are awaiting some event or decision before they can be merged. label May 22, 2026
@netlify
Copy link
Copy Markdown

netlify Bot commented May 22, 2026

Deploy Preview for docsdocker ready!

Name Link
🔨 Latest commit bdaa93f
🔍 Latest deploy log https://app.netlify.com/projects/docsdocker/deploys/6a1098d1e618890008b87303
😎 Deploy Preview https://deploy-preview-25155--docsdocker.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@craig-osterhout craig-osterhout requested review from a team, Bkblodget and cdupuis May 22, 2026 17:46
Copy link
Copy Markdown

@docker-agent docker-agent left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Assessment: 🟡 NEEDS ATTENTION

This PR adds Debian hardened system package (HSP) CLI workflows to cli.md and hardened-packages.md. The structure and tab-based approach are well-implemented and follow existing patterns. The cli.md change correctly updates a dhictldocker dhi command reference.

The main concerns are in hardened-packages.md: the Verify section overstates what dpkg -L and apt-cache show reveal (provenance/cryptographic signatures), the public-repo demo Dockerfile installs curl twice (once as a build tool, once as the demo package), and the enterprise build command asymmetry between Alpine (docker build) and Debian (docker buildx build) may confuse users.

Comment thread content/manuals/dhi/how-to/hardened-packages.md Outdated
Comment thread content/manuals/dhi/how-to/hardened-packages.md Outdated
Comment thread content/manuals/dhi/how-to/hardened-packages.md Outdated
Comment thread content/manuals/dhi/how-to/hardened-packages.md
Comment thread content/manuals/dhi/how-to/hardened-packages.md
Signed-off-by: Craig Osterhout <craig.osterhout@docker.com>
@craig-osterhout craig-osterhout added the status/review Pull requests that are ready for review label May 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/dhi status/do-not-merge Pull requests that are awaiting some event or decision before they can be merged. status/review Pull requests that are ready for review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants