Skip to content

Harden Dockerfile against filewrites #444

@whotwagner

Description

@whotwagner

Context

The highest threat is that an attacker gains access and sends custom javascript to the clients in order to read secrets. In order to mitigate the risk, the dockerfile should be hardened so that the appuser is not able to write files that are served by the webserver.

Alternatives

none

Has the feature been requested before?

no

If the feature request is approved, would you be willing to submit a PR?

Yes

Metadata

Metadata

Assignees

No one assigned

    Labels

    SECURITYSECURITY related. Might need to check the Threat ModelenhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions