[SERVER-71645] Use sudo instead of gosu for root inside container Created: 28/Nov/22  Updated: 20/Dec/22  Resolved: 09/Dec/22

Status: Closed
Project: Core Server
Component/s: None
Affects Version/s: None
Fix Version/s: None

Type: Improvement Priority: Major - P3
Reporter: Ryan Egesdahl (Inactive) Assignee: Ryan Egesdahl (Inactive)
Resolution: Won't Do Votes: 0
Labels: None
Remaining Estimate: Not Specified
Time Spent: Not Specified
Original Estimate: Not Specified

Participants:

 Description   

The gosu tool we're installing inside the container is based on an old version of Go libraries. This is causing security scans to flag a potential vulnerability. We don't really need to use gosu for any specific reason, so we should just use sudo instead if we need root.

Note: This should be investigated after SERVER-71646 is done, since it's possible that we may not need to use sudo at all.



 Comments   
Comment by Ryan Egesdahl (Inactive) [ 09/Dec/22 ]

In SERVER-71646, we found a way to eliminate the need for root access entirely, which obviates the need for this work.

Generated at Thu Feb 08 06:19:36 UTC 2024 using Jira 9.7.1#970001-sha1:2222b88b221c4928ef0de3161136cc90c8356a66.