tl;dr I found several bugs in apk, the default package manager for Alpine Linux. Alpine is a really lightweight distro that is very commonly used with Docker. The worst of these bugs, the subject of this blog post, allows a network man-in-the-middle (or a malicious package mirror) to execute arbitrary code on the userâs machine. This is especially bad because packages arenât served over TLS when u
{{#tags}}- {{label}}
{{/tags}}