-
Notifications
You must be signed in to change notification settings - Fork 18
Open
Description
Repo: cordum
Problem
SECURITY.md claims minimal distroless images, but Dockerfile uses Alpine.
Proposed
- Switch runtime stage to distroless static (nonroot) and keep CA certs.
Acceptance
- Built binaries run with distroless runtime image.
- Docs updated to reflect base image.
References
- Dockerfile
- SECURITY.md
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels