Skip to content

Fix possible by not specifying a USER, a program in the container may run as 'root' in Dockerfile - #40

Open
begininvoke wants to merge 1 commit into
CopilotKit:mainfrom
begininvoke:redgem/security-fix-3bcdf0be
Open

Fix possible by not specifying a USER, a program in the container may run as 'root' in Dockerfile#40
begininvoke wants to merge 1 commit into
CopilotKit:mainfrom
begininvoke:redgem/security-fix-3bcdf0be

Conversation

@begininvoke

Copy link
Copy Markdown

Proposing a fix for something flagged in agent-bot/Dockerfile. It is around line 15.

The Dockerfile does not specify a USER, causing the application to run as root. Running with unnecessary root privileges increases the risk of privilege escalation; if an attacker compromises the process, they can gain full control over the container. This is a high‑severity issue (CWE‑250).

Added USER bun to run the application as a non‑root user, eliminating the security hazard of running as root.

For reference: rule dockerfile.security.missing-user.missing-user, CWE-250 (Execution with Unnecessary Privileges). Rated high.

I do not know the codebase, so please check the change fits how the rest of it works. Happy to adjust it or close this if the reasoning is off.


Found with automated scanning (RedGem) and reviewed before opening. If it is not useful, closing it is completely fine.

…ay run as 'root'. This is a security hazard. If an
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant