You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
In the security review, this is INFO-2: Excessive Docker container capabilities Build process. The action plan notes that
Docker containers used to build an application are launched with Docker’s default set of capabilities
Proposed solution
We could investigate (by iteratively removing capabilities) which ones are truly needed for the build process to succeed. This MAY differ by phase (e.g., analyze which requires registry/docker socket vs detect/build). We might be able to learn some things from what kpack is doing.
The text was updated successfully, but these errors were encountered:
Description
In the security review, this is
INFO-2: Excessive Docker container capabilities Build process
. The action plan notes thatProposed solution
We could investigate (by iteratively removing capabilities) which ones are truly needed for the build process to succeed. This MAY differ by phase (e.g., analyze which requires registry/docker socket vs detect/build). We might be able to learn some things from what kpack is doing.
The text was updated successfully, but these errors were encountered: