Skip to content

Fix possible by not specifying a USER, a program in the container may run as 'root' in Dockerfile - #8

Open
begininvoke wants to merge 1 commit into
WaveSpeedAI:mainfrom
begininvoke:redgem/security-fix-e6cec088
Open

Fix possible by not specifying a USER, a program in the container may run as 'root' in Dockerfile#8
begininvoke wants to merge 1 commit into
WaveSpeedAI:mainfrom
begininvoke:redgem/security-fix-e6cec088

Conversation

@begininvoke

Copy link
Copy Markdown

This changes images/test_worker/Dockerfile to address something a scan flagged. It is around line 32.

The Dockerfile does not set a non‑root USER, so the container's processes (including the CMD) run as root. This unnecessary privilege increases the impact of any compromise of the application – an attacker controlling a process could gain full container control. According to CWE‑250, execution with unnecessary privileges should be avoided.

Added a non‑root USER and created the user to avoid running containers as root.

For reference: rule dockerfile.security.missing-user.missing-user, CWE-250 (Execution with Unnecessary Privileges). Rated high.

I do not know the codebase, so please check the change fits how the rest of it works. Happy to adjust it or close this if the reasoning is off.


Found with automated scanning (RedGem) and reviewed before opening. If it is not useful, closing it is completely fine.

…ay run as 'root'. This is a security hazard. If an
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant