mirror of
https://pagure.io/fedora-kickstarts.git
synced 2024-11-27 01:23:08 +00:00
6ba647a663
Best practice is to use unprivileged service daemons inside Docker containers. But with this hardcoded root password, in the case of remote code execution, an attacker could trivially escalate their privileges to root/uid 0. And while that's uid 0 inside a container, that's a much larger attack surface. Instead, do the same thing we're doing for the Cloud images: lock the root password, create a user to make Anaconda happy, then delete the user in %post. https://bugzilla.redhat.com/show_bug.cgi?id=1175997 |
||
---|---|---|
atomic-installer | ||
custom | ||
l10n | ||
snippets | ||
templates | ||
tools | ||
.gitignore | ||
.sparkleshare | ||
AUTHORS | ||
COPYING | ||
fedora-aos.ks | ||
fedora-arm-base.ks | ||
fedora-arm-kde.ks | ||
fedora-arm-lxde.ks | ||
fedora-arm-mate.ks | ||
fedora-arm-minimal.ks | ||
fedora-arm-server.ks | ||
fedora-arm-soas.ks | ||
fedora-arm-workstation.ks | ||
fedora-arm-xbase.ks | ||
fedora-arm-xfce.ks | ||
fedora-cloud-atomic-pxetolive.ks | ||
fedora-cloud-atomic-vagrant.ks | ||
fedora-cloud-atomic.ks | ||
fedora-cloud-base-vagrant.ks | ||
fedora-cloud-base.ks | ||
fedora-cloud-bigdata.ks | ||
fedora-cloud-experimental.ks | ||
fedora-docker-base.ks | ||
fedora-install-cloud.ks | ||
fedora-install-server.ks | ||
fedora-install-workstation.ks | ||
fedora-kde-packages.ks | ||
fedora-live-base.ks | ||
fedora-live-design_suite.ks | ||
fedora-live-jam_kde.ks | ||
fedora-live-kde-base.ks | ||
fedora-live-kde.ks | ||
fedora-live-mate_compiz.ks | ||
fedora-live-minimization.ks | ||
fedora-live-workstation.ks | ||
fedora-livecd-kde.ks | ||
fedora-livecd-lxde.ks | ||
fedora-livecd-mate_compiz.ks | ||
fedora-livecd-security.ks | ||
fedora-livecd-soas.ks | ||
fedora-livecd-xfce.ks | ||
fedora-livedvd-games.ks | ||
fedora-livedvd-robotics.ks | ||
fedora-livedvd-scientific_kde.ks | ||
fedora-lxde-packages.ks | ||
fedora-mate-packages.ks | ||
fedora-repo-not-rawhide.ks | ||
fedora-repo-rawhide.ks | ||
fedora-repo.ks | ||
fedora-soas-packages.ks | ||
fedora-workstation-packages.ks | ||
fedora-xfce-packages.ks | ||
Makefile | ||
README |
The master branch is where development takes place: - it may contain kickstart files that are broken, or - spin concepts that are in the process of being approved by the Board (trademark approval), or - spin concepts that are in the process of being approved by the Spins SIG The release specific branches contain spin concepts that: - are approved (both by Board and Spin SIG) - maintained for the remainder of the release cycle git clone ssh://git.fedorahosted.org/git/spin-kickstarts.git spin-kickstarts cd spin-kickstarts # If you need a specific branch other than master: git checkout BRANCHNAME # No tag has been added yet tag HEAD with git tag VERSION git push --tags make # Publish the released tar ball make publish # Clean up the generated files: make clean