Problem Statement
What practice best reduces container image supply-chain risk?
Explanation
Use minimal, verified bases. Scan dependency layers and sign images so clusters can verify provenance before running them.
Code Solution
SolutionRead Only
docker build -t registry/app:1.2.3 . cosign sign registry/app:1.2.3 trivy image --exit-code 1 registry/app:1.2.3
