Improvements to info about official repos (#5533)

This commit is contained in:
Misty Stanley-Jones 2017-12-15 15:29:31 -08:00 committed by GitHub
parent 078f3f7427
commit b975bbad0f
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 9 additions and 14 deletions

View File

@ -5,7 +5,7 @@ title: Official repositories on Docker Hub
--- ---
The Docker [Official Repositories](https://hub.docker.com/official/) are a The Docker [Official Repositories](https://hub.docker.com/official/) are a
curated set of Docker repositories that are promoted on Docker Hub. They are curated set of Docker repositories hosted on Docker Hub. They are
designed to: designed to:
* Provide essential base OS repositories (for example, * Provide essential base OS repositories (for example,
@ -25,15 +25,10 @@ designed to:
particularly important as many Official Repositories are some of the most particularly important as many Official Repositories are some of the most
popular on Docker Hub. popular on Docker Hub.
* Provide a channel for software vendors to redistribute up-to-date and
supported versions of their products. Organization accounts on Docker Hub can
also serve this purpose, without the careful review or restrictions on what
can be published.
Docker, Inc. sponsors a dedicated team that is responsible for reviewing and Docker, Inc. sponsors a dedicated team that is responsible for reviewing and
publishing all Official Repositories content. This team works in collaboration publishing all content in the official repositories. This team works in
with upstream software maintainers, security experts, and the broader Docker collaboration with upstream software maintainers, security experts, and the
community. broader Docker community.
While it is preferable to have upstream software authors maintaining their While it is preferable to have upstream software authors maintaining their
corresponding Official Repositories, this is not a strict requirement. Creating corresponding Official Repositories, this is not a strict requirement. Creating
@ -65,11 +60,11 @@ these efforts.
## How do I know the Official Repositories are secure? ## How do I know the Official Repositories are secure?
Docker provides a preview version of Docker Cloud's Each of the imagse in the Official Repositories is scanned using Docker Cloud's
[Security Scanning service](/docker-cloud/builds/image-scan/) for all of the [Security Scanning service](/docker-cloud/builds/image-scan/). The results of
Official Repositories located on Docker Hub. These security scan results provide these security scans provide valuable information about which images contain
valuable information about which images contain security vulnerabilities, which security vulnerabilities, and allow you to choose images that align with your
you should use to help you choose secure components for your own projects. security standards.
To view the Docker Security Scanning results: To view the Docker Security Scanning results: