[
https://issues.apache.org/jira/browse/NUTCH-3213?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18116987#comment-18116987
]
ASF GitHub Bot commented on NUTCH-3213:
---------------------------------------
lewismc commented on PR #968:
URL: https://github.com/apache/nutch/pull/968#issuecomment-5740369161
I added a simple Docker image smoke. PRs (and master pushes) that touch
`docker/Dockerfile` or
[.github/workflows/docker-smoke.yml](https://github.com/apache/nutch/pull/.github/workflows/docker-smoke.yml)
now build the image and:
* confirm the default user is nutch (not root), JAVA_HOME / NUTCH_HOME, and
that nutch / crawl are on PATH
* write a seed file for https://nutch.apache.org/ and run inject + readdb
-stats (expect at least one URL)
There is no generate/fetch. The Dockerfile still clones GitHub master inside
the image (same as Hub today), so this checks the image recipe, not this PR’s
Java sources.
Ran the same steps locally against the working-tree Dockerfile: inject
reported TOTAL urls: 1. Bare nutch exits 1 (usage only), so the workflow uses
command -v nutch / crawl instead.
> Harden Docker image: non-root USER and Dockerfile lint (SonarCloud)
> -------------------------------------------------------------------
>
> Key: NUTCH-3213
> URL: https://issues.apache.org/jira/browse/NUTCH-3213
> Project: Nutch
> Issue Type: Improvement
> Components: docker
> Affects Versions: 1.23
> Reporter: Lewis John McGibbney
> Assignee: Lewis John McGibbney
> Priority: Major
> Fix For: 1.24
>
>
> SonarCloud Docker analysis of docker/Dockerfile reports 8 OPEN issues
> (visible on PR analysis after docker was added to sonar.sources). They are
> independent of NUTCH-3130.
> *Security*
> * docker:S6471: alpine defaults to root; no USER instruction. CWE-250. The
> image CMD is /bin/bash and nutch/crawl are on PATH as root. docker/README.md
> already recommends a dedicated low-privilege user.
> *Maintainability*
> * docker:S6595: RUN apk update is a separate layer (stale/index bloat).
> * docker:S7031: consecutive RUN instructions (apk, rc files, clone, ln).
> * docker:S6570: unquoted $HOME and $NUTCH_HOME (word-splitting/globbing).
> *Proposed fix*
> * Single RUN: apk --no-cache add (no standalone apk update), create nutch
> user/group, clone+ant runtime, symlinks, chown.
> * Quote all shell variable expansions.
> * USER nutch before CMD. Move install prefix off /root (e.g. /opt/nutch) so
> NUTCH_HOME is owned by the runtime user. Document the path change in
> docker/README.md (breaking for anyone mounting /root/nutch_source).
> * Keep ENV JAVA_HOME; drop redundant .bashrc/.ashrc writes or write a quoted
> /etc/profile.d snippet during the same RUN.
> See:
> https://sonarcloud.io/project/issues?id=apache_nutch&pullRequest=967
--
This message was sent by Atlassian Jira
(v8.20.10#820010)