eu-digital-identity-wallet / eudi-srv-web-issuing-eudiw-py

APIs and code of the eudiw provider backend PID, mDL and EAA issuer following OID4VCI
Apache License 2.0
18 stars 20 forks source link

Dockerfile security and feed-back #66

Open bjornmolin opened 1 month ago

bjornmolin commented 1 month ago

We have some comments on your Dockerfile.

For security

Comments

janderssonse commented 1 month ago

Plus one to the suggestions above. Have a look at chainguard or alike small images bases: https://images.chainguard.dev/directory/image/python/overview for minimized attack vectors etc.

janderssonse commented 1 month ago

I also think that https://github.com/eu-digital-identity-wallet/eudi-srv-web-issuing-eudiw-py/issues/49 should be reopened because it is not solved.