Harden a Dockerfile

Solve in your browser

Edit the files below. The Objectives tick green live as you work. Hit Check when they all pass and your verified proof page is issued automatically.

Objectives

  • Not met: The base image is pinned to a specific tag or digest (not latest)
  • Not met: The container runs as a non-root USER
  • Not met: No secret is baked into an ENV/ARG layer

0 of 3 objectives met.

Objectives update live as you edit. Hitting Check commits your proof.

No account needed to explore. When you're ready, browse the rest of the challenges or sign in to save a solve as a verified proof.