Git safe.directory Can Turn Provenance into UNKNOWN
A production checkout owned by another identity can be readable on disk while Git refuses to trust it.
A production checkout owned by another identity can be readable on disk while Git refuses to trust it.
Dropping container privileges is only safe when mounts, ownership and startup scripts are designed for the new identity.
A protected parent directory can block a perfectly readable child file because directory execute controls traversal.
A file can have the right contents and still be unusable when directory traversal or group permissions are wrong.
A configuration file copied with the wrong mode can behave differently depending on the build context and base image defaults.