Would it be possible to exclude build files from the python-sdk?

Hi I’m working on integrating with temporal into my python project but when my trivy image scan ran it flagged a Dockerfile that was inside the python package.

The actual warning is about making sure that containers can run as non-root. But I don’t really see why the python sdk needs a dockerfile inside of it to begin with. Would it be possible to exclude this Dockerfile entirely?

sorry if this is not the best place to ask this question, so feel free to redirect me to the right forum if it is not.

This is not in the Python SDK directly, this is in a recursive submodule from the sdk-core repo which has a git subtree of api repo. The next SDK release will not have this (it has since been removed upstream).

1 Like