Skip to content

Commit 2874707

Browse files
committed
Harden CI workflows and Dockerfiles
Workflows: - ci-comprehensive-build-test.yml: remove fuzzer job, add sanitize-sed.sh sourcing to all bash steps, remove pull-requests: read, renumber jobs 1-7 - ci-docker-latest.yml: add shell hardening prologue, sanitize-sed.sh, rename image from iccdev-latest to iccdev, SBOM and attestations - ci-docker-nixos.yml: add shell hardening prologue, sanitize-sed.sh, SBOM and attestations Dockerfiles: - Dockerfile: pin ubuntu:26.04 to sha256 digest, replace git clone with COPY, remove git from builder deps, add IccJpegDump to PATH - Dockerfile.nixos: pin nixos/nix base image to version+digest, replace git clone with COPY, add CMAKE_BUILD_TYPE=Release, add non-root iccdev user, use generic library version names in welcome script
1 parent 9f53e42 commit 2874707

File tree

5 files changed

+638
-202
lines changed

5 files changed

+638
-202
lines changed

0 commit comments

Comments
 (0)