- Remove secrets from Dockerfile build args, pass as runtime env vars only - Add non-root user to Docker container - Add SKU format validation to prevent S3 key injection - Sanitize error responses in sanity-lookup route - Fix zod import to use @medusajs/framework/zod - Clean up .env.template defaults and .dockerignore
13 lines
101 B
Text
13 lines
101 B
Text
.git
|
|
.medusa
|
|
.env
|
|
.env.*
|
|
.DS_Store
|
|
node_modules
|
|
dist
|
|
coverage
|
|
.cache
|
|
.vscode
|
|
.idea
|
|
.claude
|
|
CLAUDE.md
|