Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Image may expose PANet credentials #1

Open
Laura7089 opened this issue Jan 24, 2021 · 1 comment
Open

Image may expose PANet credentials #1

Laura7089 opened this issue Jan 24, 2021 · 1 comment
Labels
bug Something isn't working

Comments

@Laura7089
Copy link
Member

Docker build args can be inspected with the docker history command - this means that our username/password combo is not necessarily protected (though they are not present in the final image, only the go-based stage which uses papatcher).

The easiest solution to this is probably to switch the build to BuildKit; the only barrier is that docker-compose currently doesn't support the buildkit secret syntax.

@Laura7089
Copy link
Member Author

See this PR

@Laura7089 Laura7089 added the bug Something isn't working label May 7, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

1 participant