Skip to content
View in the app

A better way to browse. Learn more.

Unraid

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Are dockers and plugins safe?

Featured Replies

Hi all,

 

Are dockers and plugins safe to use?  Specifically I'm thinking about malware or security vulnerabilities.  What, beyond the benevolence of the repository maintainer, would stop someone from creating a rogue plugin or docker that effectively turns your unRAID box into a bitcoin miner (eg).  Is there any sort of screening for the software in the default plugin/docker list that is enabled in Community Applications?

 

Am I being paranoid?

Well as far as I know the repos within Community Applications are all on github and opensource, so feel free to browse them and audit what is being installed yourself.  I know that at linuxserver.io we always publish the github repo for each release so you can look at it and we encourage you to put pull requests in if you think they're needed.

Hi all,

 

Are dockers and plugins safe to use?  Specifically I'm thinking about malware or security vulnerabilities.  What, beyond the benevolence of the repository maintainer, would stop someone from creating a rogue plugin or docker that effectively turns your unRAID box into a bitcoin miner (eg).  Is there any sort of screening for the software in the default plugin/docker list that is enabled in Community Applications?

 

Am I being paranoid?

Safeguards are built into CA to allow its moderators to add comments and/or override any setting in the application's template, and additionally allow the moderators to immediately blacklist any application (and in more extreme cases an entire author / repository) should a concern like that pop up to prevent any further installations of the application.

 

Additionally, if you have already installed the app, and also have Fix Common Problems plugin installed, then you would also receive a notification that whatever app you have installed has been blacklisted for such and such reasons (or has a moderator comment on it).

 

(The moderation system is also built to allow comments / blacklistings to be placed on any application found on dockerHub, even if no unRaid repository contains that particular application)

 

Additionally, CA automatically removes any embedded javascript from a template to prevent CA from becoming a vector for attacks.

Archived

This topic is now archived and is closed to further replies.

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.