[ 
https://issues.apache.org/jira/browse/NUTCH-3213?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18116993#comment-18116993
 ] 

ASF GitHub Bot commented on NUTCH-3213:
---------------------------------------

sonarqubecloud[bot] commented on PR #968:
URL: https://github.com/apache/nutch/pull/968#issuecomment-5740434453

   ## [![Quality Gate 
Passed](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/checks/QualityGateBadge/qg-passed-20px.png
 'Quality Gate 
Passed')](https://sonarcloud.io/dashboard?id=apache_nutch&pullRequest=968) 
**Quality Gate passed**  
   Issues  
   
![](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/common/passed-16px.png
 '') [0 New 
issues](https://sonarcloud.io/project/issues?id=apache_nutch&pullRequest=968&issueStatuses=OPEN,CONFIRMED&sinceLeakPeriod=true)
  
   
![](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/common/accepted-16px.png
 '') [0 Accepted 
issues](https://sonarcloud.io/project/issues?id=apache_nutch&pullRequest=968&issueStatuses=ACCEPTED)
   
   Measures  
   
![](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/common/passed-16px.png
 '') [0 Security 
Hotspots](https://sonarcloud.io/project/security_hotspots?id=apache_nutch&pullRequest=968&issueStatuses=OPEN,CONFIRMED&sinceLeakPeriod=true)
  
   
![](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/common/passed-16px.png
 '') [58.5% Coverage on New 
Code](https://sonarcloud.io/component_measures?id=apache_nutch&pullRequest=968&metric=new_coverage&view=list)
  
   
![](https://sonarsource.github.io/sonarcloud-github-static-resources/v2/common/passed-16px.png
 '') [1.4% Duplication on New 
Code](https://sonarcloud.io/component_measures?id=apache_nutch&pullRequest=968&metric=new_duplicated_lines_density&view=list)
  
     
   <!

> Harden Docker image: non-root USER and Dockerfile lint (SonarCloud)
> -------------------------------------------------------------------
>
>                 Key: NUTCH-3213
>                 URL: https://issues.apache.org/jira/browse/NUTCH-3213
>             Project: Nutch
>          Issue Type: Improvement
>          Components: docker
>    Affects Versions: 1.23
>            Reporter: Lewis John McGibbney
>            Assignee: Lewis John McGibbney
>            Priority: Major
>             Fix For: 1.24
>
>
> SonarCloud Docker analysis of docker/Dockerfile reports 8 OPEN issues 
> (visible on PR analysis after docker was added to sonar.sources). They are 
> independent of NUTCH-3130.
> *Security*
>  * docker:S6471: alpine defaults to root; no USER instruction. CWE-250. The 
> image CMD is /bin/bash and nutch/crawl are on PATH as root. docker/README.md 
> already recommends a dedicated low-privilege user.
> *Maintainability*
>  * docker:S6595: RUN apk update is a separate layer (stale/index bloat).
>  * docker:S7031: consecutive RUN instructions (apk, rc files, clone, ln).
>  * docker:S6570: unquoted $HOME and $NUTCH_HOME (word-splitting/globbing).
> *Proposed fix*
>  * Single RUN: apk --no-cache add (no standalone apk update), create nutch 
> user/group, clone+ant runtime, symlinks, chown.
>  * Quote all shell variable expansions.
>  * USER nutch before CMD. Move install prefix off /root (e.g. /opt/nutch) so 
> NUTCH_HOME is owned by the runtime user. Document the path change in 
> docker/README.md (breaking for anyone mounting /root/nutch_source).
>  * Keep ENV JAVA_HOME; drop redundant .bashrc/.ashrc writes or write a quoted 
> /etc/profile.d snippet during the same RUN.
> See:
> https://sonarcloud.io/project/issues?id=apache_nutch&pullRequest=967



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to