no-seccomp-unconfined
disallow disabling seccomp confinement via a devcontainer.json’s or Feature’s “securityOpt” property, or a “–security-opt seccomp=unconfined” entry in a devcontainer.json’s “runArgs”
Why
“seccomp=unconfined” turns off syscall filtering entirely, exposing the whole kernel API — including the calls the default profile blocks precisely because they have been used to break out of containers. The setting is most often copied from debugger instructions, where granting the “SYS_PTRACE” capability is enough on current runtimes.
Bad
{
"image": "mcr.microsoft.com/devcontainers/base:ubuntu",
"securityOpt": ["seccomp=unconfined"]
}
Good
{
"image": "mcr.microsoft.com/devcontainers/base:ubuntu",
"capAdd": ["SYS_PTRACE"]
}