Commit f1707be
committed
Harden workflows and Dockerfiles: sanitize-sed, pinned images, COPY, non-root
Workflows:
- ci-comprehensive-build-test.yml: resolve merge conflict with master,
add sanitize-sed.sh sourcing to all 38 bash steps, remove pull-requests: read
- ci-docker-latest.yml: add sanitize-sed.sh sourcing to 4 test steps
- ci-docker-nixos.yml: add sanitize-sed.sh sourcing to 4 test steps
Dockerfiles:
- Dockerfile: pin ubuntu:26.04 to sha256 digest, replace git clone with COPY,
remove git from builder deps
- Dockerfile.nixos: replace git clone with COPY, add non-root iccdev user (uid 1000)1 parent 4ae0fd3 commit f1707be
File tree
5 files changed
+413
-358
lines changed- .github/workflows
5 files changed
+413
-358
lines changed
0 commit comments