Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update Dockerfile #445

Closed
wants to merge 1 commit into from
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 4 additions & 5 deletions connector/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,13 +1,12 @@
FROM gradle:7.6.0-jdk17 AS build
FROM gradle:7-jdk17 AS build

ARG BUILD_ARGS

COPY --chown=gradle:gradle . /home/gradle/project/
WORKDIR /home/gradle/project/
RUN --mount=type=cache,target=/home/gradle/.gradle/caches gradle build --no-daemon $BUILD_ARGS

# -buster is required to have apt available
FROM openjdk:17-slim-buster
FROM eclipse-temurin:17-alpine
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
FROM eclipse-temurin:17-alpine
FROM eclipse-temurin:17-jre-alpine

The runtime layer shouldn't need a full JDK. Reduces base image size from ~200 MB to ~50 MB.


ARG EDC_LAST_COMMIT_INFO_ARG="The docker container was built outside of github actions and you didn't provide the build arg EDC_LAST_COMMIT_INFO_ARG, so there's no last commit info."
ENV EDC_LAST_COMMIT_INFO=$EDC_LAST_COMMIT_INFO_ARG
Expand All @@ -19,10 +18,10 @@
ARG JVM_ARGS=""

# Install curl, then delete apt indexes to save image space
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
# Install curl, then delete apt indexes to save image space

RUN apt update \
&& apt install -y curl \
RUN apk update \
&& apk add curl \
&& rm -rf /var/cache/apt/archives /var/lib/apt/lists \
Comment on lines +21 to 23
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
RUN apk update \
&& apk add curl \
&& rm -rf /var/cache/apt/archives /var/lib/apt/lists \
RUN apk add --no-cache curl \

&& touch /emtpy-properties-file.properties

Check failure

Code scanning / Trivy

'apk add' is missing '--no-cache' High

Artifact: connector/Dockerfile
Type: dockerfile
Vulnerability DS025
Severity: HIGH
Message: '--no-cache' is missed: apk update && apk add curl && rm -rf /var/cache/apt/archives /var/lib/apt/lists && touch /emtpy-properties-file.properties
Link: DS025

WORKDIR /app

Expand Down
Loading