As a best security practice, the `Dockerfile` should ensure that the last USER is not `root` (see [here](https://docs.prismacloud.io/en/enterprise-edition/policy-reference/docker-policies/docker-policy-index/ensure-the-last-user-is-not-root) for reference).