mirror of
https://github.com/nektos/act.git
synced 2026-04-26 01:15:51 +03:00
[PR #1760] [CLOSED] Don't bind host docker daemon socket #2115
Labels
No labels
area/action
area/cli
area/docs
area/image
area/runner
area/workflow
backlog
confirmed/not-planned
kind/bug
kind/discussion
kind/external
kind/feature-request
kind/question
meta/duplicate
meta/invalid
meta/need-more-info
meta/resolved
meta/wontfix
meta/workaround
needs-work
pull-request
review/not-planned
size/M
size/XL
size/XXL
stale
stale-exempt
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/act#2115
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
📋 Pull Request Information
Original PR: https://github.com/nektos/act/pull/1760
Author: @vicamo
Created: 4/24/2023
Status: ❌ Closed
Base:
master← Head:for-upstream/dont-bind-host-docker-socket📝 Commits (1)
43045e3Don't bind host docker daemon socket📊 Changes
1 file changed (+1 additions, -3 deletions)
View changed files
📝
pkg/runner/run_context.go(+1 -3)📄 Description
Binding host docker daemon socket into executor containers can be a terrible security hole. Don't do this unless explicitly specified through customized mounts.
To exploit this issue, run following test job:
See also #1744 , #1756, #1757.
🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.