Comment on [deleted]

<- View Parent
DoPeopleLookHere@sh.itjust.works ⁨1⁩ ⁨day⁩ ago

Hokay. So docker does run as root. Podman can run rootless, but docker does run as root.

So if you have any vulnerabilities in your code, like say remote code execution, than your app already has access to root.

Also, don’t pretend like your shit don’t stink. My code has bugs. And I’ve been at this a a decade. Your vibe coded thing isnt going to be secure because you probably don’t even know how to make it secure if you don’t know docker runs as root.

Here’s where I interject my opnion

Its fine to do this for yourself. If you wanted to hear how great your AI produced slop go to LinkedIn.

When you share things to be used by others, you have a responsibility yourself. How will you monitor and package up security updates? What kind of depenecinies do you have? Are they up to date? Do they have any CVEs?

There’s so much more to publishing than good intentions. Its fine to do something like this for yourself. But to publish and then absolve yourself of any responsibility is not a way to get taken seriously.

source
Sort:hotnewtop