4 ms·
For Heroku, which has a read-only filesystem for /etc, we did this: https://gist.github.com/yanowitz/8329d8b27d8294ca7027f504326fd629 https://gist.github.com/ya
by yanowitz 10y ago
For Heroku, which has a read-only filesystem for /etc, we did this: https://gist.github.com/yanowitz/8329d8b27d8294ca7027f504326fd629 https://gist.github.com/yanowitz/8329d8b27d8294ca7027f504326...
- steveeq1 10y agoIt seems that heroku already took care of this security problem for us. This is a copy-and-paste of a comment that was left on the github page: seems to be the default on heroku already: Path: /etc/ImageMagick/policy.xml Policy: Coder rights: None pattern: EPHEMERAL Policy: Coder rights: None pattern: URL Policy: Coder rights: None pattern: HTTPS Policy: Coder rights: None pattern: MVG Policy: Coder rights: None pattern: MSL
- evolve2k 10y agoAm I right then in assuming then that for apps deployed on heroku that this specific reported issue is not a problem?
- steveeq1 10y agoWell, I am on heroku and I have verified that that file is on my heroku instance, so I assume so. Is there a tool I can use to verify that my website is protected?