diff --git a/sast-engine/Dockerfile b/sast-engine/Dockerfile deleted file mode 100644 index 5a975eb5..00000000 --- a/sast-engine/Dockerfile +++ /dev/null @@ -1,23 +0,0 @@ -FROM ubuntu:latest - -# Missing USER instruction - should trigger DOCKER-SEC-001 -# Using :latest tag - should trigger DOCKER-BP-001 - -RUN apt-get update && apt-get upgrade -y && \ - apt-get install -y nginx sudo - -# Using sudo - should trigger DOCKER-SEC-007 -RUN sudo chown -R www-data:www-data /var/www - -# No pipefail - should trigger DOCKER-BP-010 -RUN wget https://example.com/file.tar.gz | tar xz - -# Missing yum clean all -RUN yum install -y httpd - -# Last USER is root - should trigger DOCKER-SEC-009 -USER root - -EXPOSE 80 - -CMD ["nginx", "-g", "daemon off;"] diff --git a/sast-engine/docker-compose.yml b/sast-engine/docker-compose.yml deleted file mode 100644 index 2d39d472..00000000 --- a/sast-engine/docker-compose.yml +++ /dev/null @@ -1,21 +0,0 @@ -version: '3.8' - -services: - web: - image: nginx:latest - privileged: true - network_mode: host - pid: host - ipc: host - cap_add: - - SYS_ADMIN - - NET_ADMIN - security_opt: - - seccomp:unconfined - - label:disable - volumes: - - /var/run/docker.sock:/var/run/docker.sock - - app: - image: myapp:latest - container_name: myapp-prod