Yes but NixOS does all of these things already, without the process overhead
Even the minimal SBOM part? It's hard to be more minimal than a busybox binary.
That’s fair, NixOS avoids the direct stuff from Docker itself but if you’re basing on an Alpine image or something that would probably be more minimal / smaller
Even the minimal SBOM part? It's hard to be more minimal than a busybox binary.
That’s fair, NixOS avoids the direct stuff from Docker itself but if you’re basing on an Alpine image or something that would probably be more minimal / smaller