Skip to content

Conversation

@bleggett
Copy link
Contributor

@bleggett bleggett commented Jan 28, 2026

This is a bit of a niche flag and IMO somewhat pointless as a security knob versus just properly dropping capabilities, but it is something container runtimes will conditionally set in combination with capabilities and which can be observed in a workload context, so we should plumb it thru.

@bleggett bleggett force-pushed the bleggett/add-no-new-privs branch from fcd4c5f to 1d8a5b5 Compare January 29, 2026 00:06
@bleggett bleggett force-pushed the bleggett/add-no-new-privs branch from 1d8a5b5 to 49cb1ca Compare January 29, 2026 00:13
@bleggett bleggett requested review from azenla and kaniini January 29, 2026 00:15
@bleggett bleggett merged commit 5e63dcc into edera-dev:main Jan 29, 2026
10 checks passed
@bleggett bleggett mentioned this pull request Jan 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants