security(ocr): run OCR container as non-root user (CIS Docker §4.1) #611

Merged
marcel merged 12 commits from feat/issue-459-ocr-non-root into main 2026-05-17 19:06:47 +02:00
Showing only changes of commit 53bd574660 - Show all commits

View File

@@ -26,8 +26,7 @@ def test_htrmopo_dir_default_is_fixed_path():
importlib.reload(ensure_blla_model)
result = ensure_blla_model.HTRMOPO_DIR
importlib.reload(ensure_blla_model)
assert "~" not in result
assert not result.startswith("/.")
assert result == "/app/models/.htrmopo"
# ─── Model already loadable ───────────────────────────────────────────────────