Tighten container and runtime defaults by pinning upstream sources, restricting local service exposure, and updating credential and file-download handling to safer defaults.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* 重构
* 重构
* no sense
* no sense
* no sense
* no sense
* no sense
* no sense
* no sense
* no sense
* no sense
* no sense
* no sense
* no sense
* no sense
* no sense
* no sense
* no sense
* no sense
* no sense
* no sense
* tmp
* xx
* no sense
* no sense
* no sense
* no sense
* no sense
* no sense
* no sense
* no sense
* no sense
* no sense
* no sense
* no sense
* no sense
* no sense
* no sense
* no sense
* no sense
* no sense
* t
* finish image build
* fix
* addmenu
* addmenu
* fix
* fix
* fix
* fix
* fix
* fix
* fix
* fix
* fix
* fix
* fix
* fix
* fix
* fix
* finishscript
---------
Co-authored-by: ubuntu <ubuntu@localhost.localdomain>
Co-authored-by: xubiaolin <xubiaolin2014>
Co-authored-by: root <root@localhost.localdomain>