I've seen [a Open Source Security Foundation post last year on the topic](https://best.openssf.org/Compiler-Hardening-Guides/Compiler-Options-Hardening-Guide-for-C-and-C++), and I think there might be options we can enforce for IOCs built through EPICS in Docker.
I've seen a Open Source Security Foundation post last year on the topic, and I think there might be options we can enforce for IOCs built through EPICS in Docker.