OCI image builder (buildah+forgejo) made to be usable in a locked-down OCI container container.
Adding capabilities after removing capabilities is more robust and makes logically more sense, the reverse order was confusing. This also allows dropping the exception from removal. |
||
|---|---|---|
| .forgejo/workflows | ||
| Dockerfile | ||
| entrypoint.sh | ||
| LICENSE | ||