docker-claude/.forgejo
docker-claude a79aad9fc8
Some checks failed
Build images / check-docker (push) Successful in 1s
Build images / scan (push) Failing after 50s
Build images / build-and-push (push) Has been skipped
fix(security): remove MCP credentials from managed-settings.json; bump Trivy to 0.70.0
settings.json is COPY-ed into the image at build time. Putting MCP server
config with credential env references there risks baking tokens into the
image if placeholders are ever replaced with real values. Move MCP server
config to ~/.claude/settings.json (runtime volume mount) instead.
Managed settings now contains policy only: models, permissions, telemetry.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-04-20 16:00:37 +02:00
..
workflows fix(security): remove MCP credentials from managed-settings.json; bump Trivy to 0.70.0 2026-04-20 16:00:37 +02:00