perf: make no-new-privileges true when use docker

This commit is contained in:
Soulter
2026-04-12 14:37:33 +08:00
parent 2274e0efc9
commit 68a195e12b

View File

@@ -1,15 +1,17 @@
# 当接入 QQ NapCat 时,请使用这个 compose 文件一键部署: https://github.com/NapNeko/NapCat-Docker/blob/main/compose/astrbot.yml version: '3.8'
# When connecting to OneBot v11 Napcat, please use this compose file for one-click deployment: https://github.com/NapNeko/NapCat-Docker/blob/main/compose/astrbot.yml
services: services:
astrbot: astrbot:
image: soulter/astrbot:latest image: soulter/astrbot:latest
container_name: astrbot container_name: astrbot
restart: always restart: always
ports: # mappings description: https://github.com/AstrBotDevs/AstrBot/issues/497 security_opt:
- "6185:6185" # 必选AstrBot WebUI 端口 - no-new-privileges:true
- "6199:6199" # 可选, QQ 个人号 WebSocket 端口 ports:
# - "6195:6195" # 可选, 企业微信 Webhook 端口 - "6185:6185" # AstrBot WebUI
# - "6196:6196" # 可选, QQ 官方接口 Webhook 端口 - "6199:6199" # Optional. OneBot v11 Napcat Websocket Port
environment: environment:
- TZ=Asia/Shanghai - TZ=Asia/Shanghai
volumes: volumes: