Even after containerisation, locking down ImageMagick to not be able to access the network would be good. https://offbyinfinity.com/2017/12/sandboxing-imagemagick-with-nsjail/ https://github.com/google/nsjail https://github.com/derwolfe/magicks-linux-seccomp-bpf
Even after containerisation, locking down ImageMagick to not be able to access the network would be good.
https://offbyinfinity.com/2017/12/sandboxing-imagemagick-with-nsjail/
https://github.com/google/nsjail
https://github.com/derwolfe/magicks-linux-seccomp-bpf