As a best security practice, the Dockerfile should ensure that the last USER is not root (see here for reference).
Dockerfile
root