I guess this "Docker-Hub pay-to-play" thing that I'm seeing inconsistent (and unsourced) complaints about this morning is another example of the "common index" problem.
i.e., public services that don't do the creation & hosting of information tend to go without scrutiny for a lot longer than services that are primarily repositories for big storage, but in the end they're just as important.