In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to bootstrap containers.
{
"binaries": [
{
"binary_name": "liblxc1",
"binary_version": "1.0.10-0ubuntu1.1"
},
{
"binary_name": "lxc",
"binary_version": "1.0.10-0ubuntu1.1"
},
{
"binary_name": "lxc-templates",
"binary_version": "1.0.10-0ubuntu1.1"
},
{
"binary_name": "lxc-tests",
"binary_version": "1.0.10-0ubuntu1.1"
},
{
"binary_name": "python3-lxc",
"binary_version": "1.0.10-0ubuntu1.1"
}
]
}{
"binaries": [
{
"binary_name": "liblxc1",
"binary_version": "2.0.11-0ubuntu1~16.04.3+esm1"
},
{
"binary_name": "lua-lxc",
"binary_version": "2.0.11-0ubuntu1~16.04.3+esm1"
},
{
"binary_name": "lxc",
"binary_version": "2.0.11-0ubuntu1~16.04.3+esm1"
},
{
"binary_name": "lxc-common",
"binary_version": "2.0.11-0ubuntu1~16.04.3+esm1"
},
{
"binary_name": "lxc-templates",
"binary_version": "2.0.11-0ubuntu1~16.04.3+esm1"
},
{
"binary_name": "lxc-tests",
"binary_version": "2.0.11-0ubuntu1~16.04.3+esm1"
},
{
"binary_name": "lxc1",
"binary_version": "2.0.11-0ubuntu1~16.04.3+esm1"
},
{
"binary_name": "python3-lxc",
"binary_version": "2.0.11-0ubuntu1~16.04.3+esm1"
}
]
}