Class: Dash::Dockerfile::Rules::RootUser
- Inherits:
-
Base
- Object
- Base
- Dash::Dockerfile::Rules::RootUser
- Defined in:
- lib/dash/dockerfile/rules/root_user.rb
Overview
A final stage that sets no USER runs as whatever its base image left it as — root, for nearly every official image — and so does anything that gets a shell in it.
Constant Summary collapse
- SUGGESTION =
"create a non-root user and add a USER line before the entrypoint, unless the base image already switched"
Instance Method Summary collapse
Instance Method Details
#findings ⇒ Object
6 7 8 9 10 11 |
# File 'lib/dash/dockerfile/rules/root_user.rb', line 6 def findings stage = document.final_stage or return [] return [] if stage.instructions.any? { |instruction| instruction.name == "USER" } [ note(at(stage.instructions.first), "the final stage sets no USER, so the container runs as whatever the base image does — usually root", SUGGESTION) ] end |