openMF / ph-ee-connector-mojaloop-java

Java-based Mojaloop connector microservice
Mozilla Public License 2.0
5 stars 23 forks source link

Jit Automated PR: Specify a non-root user in your Dockerfile #21

Open jit-ci[bot] opened 5 months ago

jit-ci[bot] commented 5 months ago

Specify a non-root user in your Dockerfile

This Pull Request was automatically generated by Jit. We highly recommend that you check the suggestion and make sure everything works before merging it. An explanation of the suggested changes is available below.

What changes are proposed in this PR?

Why are these changes important?

If you don't specify at least 1 USER command in the Dockerfile, the container will run as root. If a security vulnerability is exploited in the root container, an attacker could gain complete control over the host system and any other containers running on it, potentially leading to devastating consequences.