What changed, and why it matters
This commit removes a Docker command-line flag that made the build container run as the current host user instead of the container's default user. The stated goal is to fix build permission problems. In itself, the change does not add a known vulnerability, but it means the build will now run as whatever user is configured inside the builder image. If that image runs as root, files created in the mounted workspace could end up owned by root, and any build-time scripts or tools will execute with the container user's privileges. There is no direct evidence in the commit that this is a security fix or that it introduces an exploitable flaw.
Review the builder image to confirm whether it runs as root or a dedicated build user. If it runs as root, consider adding a non-root `USER` in `Dockerfile.builder` and setting appropriate file ownership/permissions in the workflow, rather than dropping the `--user` flag. Verify that build artifacts published in releases are not owned by root and that the change does not weaken the CI/CD supply-chain posture.
Security signals we found
Removal of `--user` flag from Docker build invocations
Build container may now run as root depending on builder image configuration
Potential for root-owned artifacts in mounted workspace
No security framing or advisory references in commit
Evidence from the diff
The patch deletes --user "$(id -u):$(id -g)" from five docker run invocations in .github/workflows/release.yml and trims trailing whitespace in Dockerfile.builder. Previously the release workflow forced the container to run with the GitHub Actions runner’s UID/GID, which is a common hardening pattern to avoid root-owned build artifacts and limit privilege inside the container. Removing it delegates user selection to the builder image. The Dockerfile does not show a USER directive, so the default root user in debian:bullseye would be used unless another layer changes it. The commit message frames this as resolving permission issues, not a security issue. No CVE, advisory, or researcher attribution is present in the supplied materials.
Changed components
.github/workflows/release.ymlDockerfile.builderghcr.io/magicgrants/skylight-wallet-builder:latest container imageInspect captured patch +1 / −7
diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml
index a415940..711c5f9 100644
--- a/.github/workflows/release.yml
+++ b/.github/workflows/release.yml
@@ -50,7 +50,6 @@ jobs:
run: |
VERSION='${{ needs.version.outputs.version }}'
docker run --rm \
- --user "$(id -u):$(id -g)" \
-v "$PWD:/workspace" \
-w /workspace \
ghcr.io/magicgrants/skylight-wallet-builder:latest \
@@ -94,7 +93,6 @@ jobs:
run: |
VERSION='${{ needs.version.outputs.version }}'
docker run --rm \
- --user "$(id -u):$(id -g)" \
-v "$PWD:/workspace" \
-w /workspace \
ghcr.io/magicgrants/skylight-wallet-builder:latest \
@@ -138,7 +136,6 @@ jobs:
run: |
VERSION='${{ needs.version.outputs.version }}'
docker run --rm \
- --user "$(id -u):$(id -g)" \
-v "$PWD:/workspace" \
-w /workspace \
ghcr.io/magicgrants/skylight-wallet-builder:latest \
@@ -182,7 +179,6 @@ jobs:
run: |
VERSION='${{ needs.version.outputs.version }}'
docker run --rm \
- --user "$(id -u):$(id -g)" \
-v "$PWD:/workspace" \
-w /workspace \
ghcr.io/magicgrants/skylight-wallet-builder:latest \
@@ -215,7 +211,6 @@ jobs:
run: |
VERSION='${{ needs.version.outputs.version }}'
docker run --rm \
- --user "$(id -u):$(id -g)" \
-v "$PWD:/workspace" \
-w /workspace \
ghcr.io/magicgrants/skylight-wallet-builder:latest \
diff --git a/Dockerfile.builder b/Dockerfile.builder
index 8de0596..b4d18b9 100644
--- a/Dockerfile.builder
+++ b/Dockerfile.builder
@@ -1,6 +1,6 @@
# Using Debian Bullseye for maximum AppImage compatibility (GLIBC 2.31)
FROM debian:bullseye-20251117@sha256:ee239c601913c0d3962208299eef70dcffcb7aac1787f7a02f6d3e2b518755e6
-
+
ARG TARGETARCH
ARG FLUTTER_VERSION=3.38.7
@@ -78,4 +78,3 @@ RUN git clone https://github.com/flutter/flutter.git -b ${FLUTTER_VERSION} --dep
find /flutter -name "*.zip" -delete
WORKDIR /workspace
-
Why this scored 13/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.