Skip to content

Conversation

@RinZ27
Copy link

@RinZ27 RinZ27 commented Jan 17, 2026

Switching from 'root' to a dedicated 'shenyu' user in the main distribution Dockerfiles.

Running application containers as root is a significant security risk. This change adheres to the principle of least privilege, reducing the attack surface in the event of a container compromise.

Changes:

  • Created 'shenyu' user/group in Alpine and CentOS-based Dockerfiles.
  • Corrected application directory ownership.
  • Updated ENTRYPOINT to run under the new user context.

@Aias00 Aias00 requested a review from Copilot January 19, 2026 10:08
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

@RinZ27 RinZ27 force-pushed the fix/docker-security-non-root branch from 7c22dfd to c366e60 Compare January 20, 2026 13:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants