From 2691dfcf2f574edbeb8c0477400739d8e724e13b Mon Sep 17 00:00:00 2001 From: Danny Coates Date: Thu, 22 Jun 2017 17:20:41 -0700 Subject: [PATCH] use a non-root user for npm install in docker --- Dockerfile | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 482e1ada..73d7bfb8 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,9 @@ -FROM node:8.1-alpine +FROM node:8-alpine +RUN adduser -S app COPY . /app +RUN chown -R app /app +USER app WORKDIR /app RUN mkdir static RUN npm install