Mount a new tmpfs on /tmp and drop all capabilities
This mounts a new tmpfs on /tmp so any files residing there would be hidden from the sandbox. Many programs store some files in there that might be useful to an attacker.
It also drops all capabilities incase it is ever run with extra capabilities for whatever reason.
Merge request reports
Activity
enabled an automatic merge when the pipeline for a197e7b3 succeeds
It seems that something is wrong with the runner, and I can't relaunch the pipeline, meh.
Edited by jvoisinManually merged via 58773088.
Thanks you very much!
mentioned in merge request !80 (merged)
Please register or sign in to reply