a4cf365098b9dd8e4c3f82239de24d02c299359e
The runtime stage of apps/server/Dockerfile now drops root privileges with 'USER node' — the non-root user (uid/gid 1000) the official Node image ships with — so the app container does not run with root privileges. The server binds port 3000 (>= 1024) and only reads the root-owned files copied above, so no extra user creation or ownership changes are required. compose.yaml header updated: T05 is in scope; T06 (read-only rootfs) and T07 (multi-arch) remain out of scope.
Description
No description provided
857 KiB
Languages
JavaScript
89%
TypeScript
9.9%
Dockerfile
1.1%