Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

add containerRunOptions #327

Merged
merged 4 commits into from
Mar 15, 2023

Conversation

coopernetes
Copy link
Contributor

@coopernetes coopernetes commented Dec 9, 2022

* largely picked up from GoogleContainerTools#82, add privileged, capabilities and host
  volume mounts. these are passed into HostConfig if set
* added "user" field which corresponds -u/--user arg in docker

wasn't tested for other drivers and more tests likely needed
@coopernetes coopernetes marked this pull request as draft February 25, 2023 16:52
* github.com/containerd/containerd - resolve CVE-2022-23471,
  CVE-2023-25153 & CVE-2023-25173
* golang.org/x/net - resolve CVE-2022-41717
@coopernetes coopernetes marked this pull request as ready for review February 25, 2023 21:35
@loosebazooka
Copy link
Member

@coopernetes is this okay to merge?

@coopernetes
Copy link
Contributor Author

@loosebazooka yep, good to go! Thanks

@loosebazooka loosebazooka merged commit c614b89 into GoogleContainerTools:main Mar 15, 2023
@coopernetes coopernetes deleted the run-options branch March 18, 2023 19:37
ddl-ebrown added a commit to ddl-ebrown/container-structure-test that referenced this pull request Oct 24, 2023
 - Support for --cap-add was added as part of
   GoogleContainerTools#327

 - This rounds out the feature set to also include support for
   --cap-drop

 - Updates tests to drop "chown" capability and verify doing so works

 - closes GoogleContainerTools#389
ddl-ebrown added a commit to ddl-ebrown/container-structure-test that referenced this pull request Feb 29, 2024
 - Support for --cap-add was added as part of
   GoogleContainerTools#327

 - This rounds out the feature set to also include support for
   --cap-drop

 - Updates tests to drop "chown" capability and verify doing so works

 - closes GoogleContainerTools#389
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
2 participants