Skip to content

non root user#70

Merged
manasag merged 1 commit intomainfrom
manas/docker-user
Feb 6, 2026
Merged

non root user#70
manasag merged 1 commit intomainfrom
manas/docker-user

Conversation

@manasag
Copy link
Contributor

@manasag manasag commented Feb 6, 2026

This is to resolve trivy scan report

.hasura-connector/Dockerfile (dockerfile)                                                                                       
  =========================================                                                                                       
  Tests: 20 (SUCCESSES: 19, FAILURES: 1)                                                                                          
  Failures: 1 (HIGH: 1, CRITICAL: 0)                                                                                              
                                                                                                                                  
  DS-0002 (HIGH): Specify at least 1 USER command in Dockerfile with non-root user as argument                                    
  ════════════════════════════════════════                                                                                        
  Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as        
  non-root users, which can be done by adding a 'USER' statement to the Dockerfile.                                               

This has been tested locally for introspection, cloud build, and local build.

@manasag manasag merged commit f402c09 into main Feb 6, 2026
4 checks passed
@manasag manasag deleted the manas/docker-user branch February 6, 2026 11:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant