[ 
https://issues.apache.org/jira/browse/NUTCH-3213?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18116989#comment-18116989
 ] 

ASF GitHub Bot commented on NUTCH-3213:
---------------------------------------

lewismc opened a new pull request, #968:
URL: https://github.com/apache/nutch/pull/968

   Fixes [NUTCH-3213](https://issues.apache.org/jira/browse/NUTCH-3213) which 
provides a comprehensive description of the proposed improvements. 




> Harden Docker image: non-root USER and Dockerfile lint (SonarCloud)
> -------------------------------------------------------------------
>
>                 Key: NUTCH-3213
>                 URL: https://issues.apache.org/jira/browse/NUTCH-3213
>             Project: Nutch
>          Issue Type: Improvement
>          Components: docker
>    Affects Versions: 1.23
>            Reporter: Lewis John McGibbney
>            Assignee: Lewis John McGibbney
>            Priority: Major
>             Fix For: 1.24
>
>
> SonarCloud Docker analysis of docker/Dockerfile reports 8 OPEN issues 
> (visible on PR analysis after docker was added to sonar.sources). They are 
> independent of NUTCH-3130.
> *Security*
>  * docker:S6471: alpine defaults to root; no USER instruction. CWE-250. The 
> image CMD is /bin/bash and nutch/crawl are on PATH as root. docker/README.md 
> already recommends a dedicated low-privilege user.
> *Maintainability*
>  * docker:S6595: RUN apk update is a separate layer (stale/index bloat).
>  * docker:S7031: consecutive RUN instructions (apk, rc files, clone, ln).
>  * docker:S6570: unquoted $HOME and $NUTCH_HOME (word-splitting/globbing).
> *Proposed fix*
>  * Single RUN: apk --no-cache add (no standalone apk update), create nutch 
> user/group, clone+ant runtime, symlinks, chown.
>  * Quote all shell variable expansions.
>  * USER nutch before CMD. Move install prefix off /root (e.g. /opt/nutch) so 
> NUTCH_HOME is owned by the runtime user. Document the path change in 
> docker/README.md (breaking for anyone mounting /root/nutch_source).
>  * Keep ENV JAVA_HOME; drop redundant .bashrc/.ashrc writes or write a quoted 
> /etc/profile.d snippet during the same RUN.
> See:
> https://sonarcloud.io/project/issues?id=apache_nutch&pullRequest=967



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to