NoNewPrivileges on most containers. drop all caps on a few others

This commit is contained in:
zenfyr 2026-01-11 14:11:56 +07:00
commit b3e4af5aca
Signed by: melontini
SSH key fingerprint: SHA256:TtcIcnTnoAB5mqHofsaOxIgiMzfVBxej1AXT7DQdrTE
36 changed files with 80 additions and 1 deletions

View file

@ -8,6 +8,8 @@ AutoUpdate=registry
Environment=PORT=7000
Environment=URL=https://b.twitch.synth.download
PublishPort=127.0.0.1:43072:7000
# Security
NoNewPrivileges=true
[Service]
Restart=always

View file

@ -13,6 +13,8 @@ Environment=SAFETWITCH_HTTPS=true
Environment=SAFETWITCH_DEFAULT_LOCALE=en
Environment=SAFETWITCH_FALLBACK_LOCALE=en
PublishPort=127.0.0.1:24682:8280
# Security
NoNewPrivileges=true
[Service]
Restart=always