Skip to content

Fix possible by not specifying a USER, a program in the container may run as 'root' in Dockerfile - #40

Closed
begininvoke wants to merge 1 commit into
CopilotKit:mainfrom
begininvoke:redgem/security-fix-3bcdf0be
Closed

Fix possible by not specifying a USER, a program in the container may run as 'root' in Dockerfile#40
begininvoke wants to merge 1 commit into
CopilotKit:mainfrom
begininvoke:redgem/security-fix-3bcdf0be

Conversation

@begininvoke

Copy link
Copy Markdown

Proposing a fix for something flagged in agent-bot/Dockerfile. It is around line 15.

The Dockerfile does not specify a USER, causing the application to run as root. Running with unnecessary root privileges increases the risk of privilege escalation; if an attacker compromises the process, they can gain full control over the container. This is a high‑severity issue (CWE‑250).

Added USER bun to run the application as a non‑root user, eliminating the security hazard of running as root.

For reference: rule dockerfile.security.missing-user.missing-user, CWE-250 (Execution with Unnecessary Privileges). Rated high.

I do not know the codebase, so please check the change fits how the rest of it works. Happy to adjust it or close this if the reasoning is off.


Found with automated scanning (RedGem) and reviewed before opening. If it is not useful, closing it is completely fine.

…ay run as 'root'. This is a security hazard. If an
@davidmckayv

Copy link
Copy Markdown
Contributor

Closing this — the finding was real when you filed it, but it has already landed.

agent-bot/Dockerfile on main now carries RUN chown bun:bun /app followed by USER bun, plus COPY --chown=bun:bun, from #42 earlier today. That version is also stronger than this one: it drops privileges before bun install rather than at the last instruction, so the install step no longer runs as root either. Merging this on top would append a second, dead USER bun after EXPOSE.

Thanks for the report.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants