Skip to content

fix: pin alpine base image, run as non-root, harden checkout credentials - #153

Merged
traefiker merged 2 commits into
traefik:masterfrom
darkweaver87:fix/aikido-iac-sast
Jul 3, 2026
Merged

traefiker merged 2 commits into
traefik:masterfrom
darkweaver87:fix/aikido-iac-sast

Conversation

@darkweaver87

Copy link
Copy Markdown
Contributor

Motivation

Resolve piceus's Aikido IaC and container SAST findings. Both Dockerfiles used FROM alpine (unpinned latest) and ran as root; they now pin the alpine base to a digest and run as user 65534 (nobody, matching production). The CI actions/checkout steps set persist-credentials: false.

The three pkg/sources file-inclusion SAST findings are intentionally left out of this PR — piceus reads untrusted third-party plugin repos, so those need a dedicated review and will be handled separately.

@darkweaver87
darkweaver87 force-pushed the fix/aikido-iac-sast branch from e2e1e86 to 470f30a Compare July 3, 2026 13:42

@bpsoraggi bpsoraggi left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@traefiker
traefiker force-pushed the fix/aikido-iac-sast branch from 470f30a to 8edfa73 Compare July 3, 2026 13:48
@traefiker
traefiker merged commit 1723484 into traefik:master Jul 3, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants