Skip to content

Conversation

@Bump-Action
Copy link

@Bump-Action Bump-Action commented Nov 22, 2025

Description

Prevent resetting DD_UWSGI_EXTRA_ARGS variable in uwsgi entry point

What problem does it solve?

Allows you to passthrough your startup parameters to the uwsgi binary

@dryrunsecurity
Copy link

dryrunsecurity bot commented Nov 22, 2025

DryRun Security

🔴 Risk threshold exceeded.

This pull request modifies a sensitive file (docker/entrypoint-uwsgi.sh) with edits flagged by the scanner; review carefully and update .dryrunsecurity.yaml if these changes and authors are expected. The finding is non-blocking but marked as failing under the configured risk threshold.

🔴 Configured Codepaths Edit in docker/entrypoint-uwsgi.sh
Vulnerability Configured Codepaths Edit
Description Sensitive edits detected for this file. Sensitive file paths and allowed authors can be configured in .dryrunsecurity.yaml.
🔴 Configured Codepaths Edit in docker/entrypoint-uwsgi.sh
Vulnerability Configured Codepaths Edit
Description Sensitive edits detected for this file. Sensitive file paths and allowed authors can be configured in .dryrunsecurity.yaml.

We've notified @mtesauro.


All finding details can be found in the DryRun Security Dashboard.

@Bump-Action Bump-Action changed the base branch from master to dev November 22, 2025 16:59
@valentijnscholten valentijnscholten added this to the 2.53.0 milestone Nov 22, 2025
Copy link
Contributor

@mtesauro mtesauro left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved

Copy link
Member

@valentijnscholten valentijnscholten left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@Bump-Action Thank you for the PR. Could you change it to be DD_UWSGI_EXTRA_ARGS?

@Bump-Action
Copy link
Author

@Bump-Action Thank you for the PR. Could you change it to be DD_UWSGI_EXTRA_ARGS?

Done

@valentijnscholten valentijnscholten changed the title fix: enable uwsgi EXTRA_ARGS passthrough fix: enable uwsgi DD_UWSGI_EXTRA_ARGS passthrough Nov 28, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants