diff --git a/Dockerfile b/Dockerfile index 6151f15f..97db272c 100644 --- a/Dockerfile +++ b/Dockerfile @@ -127,6 +127,9 @@ ARG MEET_STATIC_ROOT=/data/static RUN mkdir -p /usr/local/etc/gunicorn COPY docker/files/usr/local/etc/gunicorn/meet.py /usr/local/etc/gunicorn/meet.py +# Remove pip to reduce attack surface in production +RUN pip uninstall -y pip + # Un-privileged user running the application ARG DOCKER_USER USER ${DOCKER_USER}