You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Jun 27, 2021. It is now read-only.
I'm a security researcher and am doing some study of public docker images. I found some misconfigurations in your this image that may expose some risky data at runtime. The exposure I found include:
Hi,
I'm a security researcher and am doing some study of public docker images. I found some misconfigurations in your this image that may expose some risky data at runtime. The exposure I found include:
composer: /composer.lock
git: /extensions/OpenIDConnect/.gitignore
sql: /extensions/OpenIDConnect/sql/mysql/AddTable.sql
vendor: /extensions/MW-OAuth2Client/vendors/*
php internal error messages: extensions/MW-OAuth2Client/vendors/oauth2-client/vendor/phpunit/phpunit/tests/_files/DataProviderDebugTest.php
Those are all blocked in the official mediawiki docker image and here are some reference about these exposures:
https://stackoverflow.com/questions/11078572/should-i-use-phpunit-in-a-staging-production-environment
bolt/bolt#375
wp-cli/doctor-command#98
If you want, I can also help fix them. Please let me know what you think. Thanks!
Best,
~cf
The text was updated successfully, but these errors were encountered: