- 
                Notifications
    You must be signed in to change notification settings 
- Fork 9
Open
Description
Harden UBI dev Dockerfile
Severity: Medium | Area: Containers | Labels: containers, hardening
Summary
- Runs as root, unpinned base, editable VCS install, interactive ENTRYPOINT.
Files
- Dockerfile (repo root)
Acceptance Criteria
- Add non-root user; pin base image by digest; avoid editable installs in release images; ENTRYPOINT runs app via exec.
- Document dev vs runtime images.
Rationale: Improve container security and reproducibility.
Metadata
Metadata
Assignees
Labels
No labels