Copilot commented on code in PR #2270:
URL: https://github.com/apache/nifi-minifi-cpp/pull/2270#discussion_r4157804331


##########
docker/rockylinux/Dockerfile:
##########
@@ -43,8 +43,8 @@ COPY . ${MINIFI_BASE_DIR}
 
 # Install the system dependencies needed for a build
 # ccache is in EPEL
-RUN dnf -y install epel-release && dnf -y install gcc-toolset-14 
gcc-toolset-14-libatomic-devel sudo git which make libarchive ccache 
ca-certificates perl patch bison flex libtool cmake rpmdevtools && \
-    if echo "$MINIFI_OPTIONS" | grep -q "MINIFI_RUST=ON"; then dnf -y install 
rust cargo clang; fi && \
+RUN dnf -y install epel-release && dnf -y install gcc-toolset-14 
gcc-toolset-14-libatomic-devel sudo git which make libarchive ccache 
ca-certificates perl patch bison flex libtool cmake rpmdevtools expat curl && \
+    if echo "$MINIFI_OPTIONS" | grep -q "MINIFI_RUST=ON"; then dnf install -y 
clang && curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | 
CARGO_HOME=${MINIFI_BASE_DIR}/.cargo RUSTUP_HOME=${MINIFI_BASE_DIR}/.rustup sh 
-s -- -y --no-modify-path; fi && \

Review Comment:
   This executes a mutable remote installer as root and lets rustup select 
whatever `stable` toolchain is current, so identical Docker inputs can run 
different code and begin failing after an upstream release. Please pin a 
rustup-init artifact with its published checksum and pass an explicit supported 
Rust toolchain version (or add a repository `rust-toolchain.toml`) so the Rocky 
build is reproducible and the downloaded executable is integrity-checked.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to