From 1059a239ca756d97e99f0ef7d5a0debc5200db7a Mon Sep 17 00:00:00 2001 From: Leon Anavi Date: Thu, 8 May 2025 16:00:27 +0300 Subject: [PATCH] .github/workflows: seccomp=unconfined Run docker without the default seccomp profile Suggested-by: Martin Steegmanns Signed-off-by: Leon Anavi --- .github/workflows/compliance.yml | 1 + .github/workflows/yocto-builds.yml | 1 + 2 files changed, 2 insertions(+) diff --git a/.github/workflows/compliance.yml b/.github/workflows/compliance.yml index f643c54..1207acb 100644 --- a/.github/workflows/compliance.yml +++ b/.github/workflows/compliance.yml @@ -24,6 +24,7 @@ jobs: - name: Do DCO check run: | docker run --rm --security-opt apparmor=unconfined \ + --security-opt seccomp=unconfined \ -v "$GITHUB_WORKSPACE:/work:ro" \ --env "BASE_REF=$GITHUB_BASE_REF" \ "dco-check-${{ github.event.number }}" diff --git a/.github/workflows/yocto-builds.yml b/.github/workflows/yocto-builds.yml index 9be0413..87b009b 100644 --- a/.github/workflows/yocto-builds.yml +++ b/.github/workflows/yocto-builds.yml @@ -67,6 +67,7 @@ jobs: - name: Build the image run: | docker run --rm --security-opt apparmor=unconfined \ + --security-opt seccomp=unconfined \ -v "$GITHUB_WORKSPACE:/work:ro" \ -v "$DL_DIR:$DL_DIR:rw" \ -v "$SSTATE_DIR:$SSTATE_DIR:rw" \