Files
frigate/docker/main/rootfs
Josh Hawkins 2ef2323fbd harden root writes into unprivileged-owned paths
Restrict the sweep sentinel to a mount at or below /media/frigate so a
parent /media mount cannot bless a later-shadowed volume. Rebuild
/tmp/nginx root-owned each start so root's cp and tempio writes cannot
follow a symlink an unprivileged nginx planted in the previous run.
2026-08-27 09:28:32 -05:00
..