Skip to content

Image hardening: non-root, multi-arch, full hash-pinning, GPG verify #10

Description

@maudlin

Remaining supply-chain/hardening from ROADMAP: run images as non-root (+ document --user); multi-arch via TARGETARCH (arm64); pip --require-hashes (hash every transitive dep); GPG-verify shellcheck/PMD instead of pin-on-known-good; refresh note for the rolling dotnet-install.sh hash.

Metadata

Metadata

Assignees

No one assigned

    Labels

    dockerImages / DockerfileshardeningSupply-chain / security hardening

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions