Refactor Dockerfile and IoUtils for improved robustness#2932
Closed
RinZ27 wants to merge 1 commit intosmithy-lang:mainfrom
Closed
Refactor Dockerfile and IoUtils for improved robustness#2932RinZ27 wants to merge 1 commit intosmithy-lang:mainfrom
RinZ27 wants to merge 1 commit intosmithy-lang:mainfrom
Conversation
Contributor
|
This pull request does not contain a staged changelog entry. To create one, use the Make sure that the description is appropriate for a changelog entry and that the proper feature type is used. See |
Added a non-root user and HEALTHCHECK to the Dockerfile to follow operational best practices. Also introduced an overload for IoUtils.runCommand that accepts argument arrays, facilitating safer command execution by avoiding shell interpolation risks.
1bf2ebc to
b2d4809
Compare
Contributor
Author
|
Understood. I'll open an issue detailing the shell injection risks in |
Author
|
I've opened issue #2933 with the detailed explanation and Proof of Concept (PoC) for the shell injection vulnerability, as well as the rationale for the container hardening changes. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Improved the operational security of the Smithy container image by adding a dedicated non-root user and health checks. \n\nAdditionally, updated to support command execution via argument arrays. This provides a more robust and idiomatic way to handle subprocesses, reducing the likelihood of issues related to shell meta-character handling when executing external commands.