From 1049f92d2939577ff7c2d7b31b87b64b306bb188 Mon Sep 17 00:00:00 2001 From: Jan Kuri Date: Wed, 16 Jun 2021 21:36:25 +0200 Subject: [PATCH] fix(security): remove mounting of docker.sock into worker job containers --- worker/docker/docker.go | 1 - 1 file changed, 1 deletion(-) diff --git a/worker/docker/docker.go b/worker/docker/docker.go index a4997891..fc7a94b2 100644 --- a/worker/docker/docker.go +++ b/worker/docker/docker.go @@ -211,7 +211,6 @@ func createContainer(cli *client.Client, name, image, dir string, cmd []string, mounts := []mount.Mount{ {Type: mount.TypeBind, Source: path.Join(dir), Target: "/build"}, - {Type: mount.TypeBind, Source: "/var/run/docker.sock", Target: "/var/run/docker.sock"}, } return cli.ContainerCreate(context.Background(), &container.Config{