[
https://issues.apache.org/jira/browse/NUTCH-3213?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18116971#comment-18116971
]
ASF GitHub Bot commented on NUTCH-3213:
---------------------------------------
github-actions[bot] commented on PR #968:
URL: https://github.com/apache/nutch/pull/968#issuecomment-5740124911
## Apache Yetus test-patch report
| |
|------------|
| -1 overall |
| | | |
|
|
|------|--------------|---------|-------------------------------------------------------------|---------------------------------------------------------------------|
| Vote | Subsystem | Runtime | Log
| Comment
|
| | | |
| Prechecks
|
| +1 | dupname | 0m 0s |
| No case conflicting files found.
|
| +1 | @author | 0m 1s |
| The patch does not contain any @author tags.
|
| | | |
| master Compile Tests
|
| | | |
| Patch Compile Tests
|
| +1 | codespell | 0m 1s |
| No new issues.
|
| +1 | detsecrets | 0m 28s |
| No new issues.
|
| -1 | blanks | 0m 0s | [/blanks-tabs.txt](/blanks-tabs.txt)\</\>
| The patch 2 line(s) with tabs.
|
| -1 | hadolint | 0m 0s |
[/results-hadolint.txt](/results-hadolint.txt)\</\> | The patch
generated 1 new + 1 unchanged - 8 fixed = 2 total (was 9) |
| -1 | markdownlint | 0m 1s |
[/results-markdownlint.txt](/results-markdownlint.txt)\</\> | The patch
generated 3 new + 5 unchanged - 1 fixed = 8 total (was 6) |
| +1 | shellcheck | 0m 0s |
| No new issues.
|
| +1 | shelldocs | 0m 0s |
| No new issues.
|
| | | |
| Other Tests
|
| +1 | asflicense | 0m 1s |
| The patch does not generate ASF License warnings.
|
| | | 0m 38s |
|
|
| |
|
|----------------|------------------------------------------------------------------------------------------------------------------|
| Subsystem | Report/Notes
|
| GITHUB PR | https://github.com/apache/nutch/pull/968
|
| Optional Tests | dupname asflicense codespell detsecrets hadolint
shellcheck shelldocs markdownlint |
| uname | Linux c436871a17d2 6.17.0-1022-azure \#22-Ubuntu SMP Mon
Jul 27 17:24:03 UTC 2026 x86_64 x86_64 x86_64 GNU/Linux |
| Build tool | nobuild
|
| Personality | /github/workspace/.yetus/personality.sh
|
| git revision | master / ee07a8afa80a65cfffef850d290458a794c3f95d
|
| modules | C: . U: .
|
| versions | git=2.34.1 hadolint=2.12.0 codespell=2.4.1
detsecrets=1.5.0 markdownlint=0.44.0 shellcheck=0.10.0 |
| Powered by | Apache Yetus 0.15.1 https://yetus.apache.org
|
This message was automatically generated.
<!
> Harden Docker image: non-root USER and Dockerfile lint (SonarCloud)
> -------------------------------------------------------------------
>
> Key: NUTCH-3213
> URL: https://issues.apache.org/jira/browse/NUTCH-3213
> Project: Nutch
> Issue Type: Improvement
> Components: docker
> Affects Versions: 1.23
> Reporter: Lewis John McGibbney
> Assignee: Lewis John McGibbney
> Priority: Major
> Fix For: 1.24
>
>
> SonarCloud Docker analysis of docker/Dockerfile reports 8 OPEN issues
> (visible on PR analysis after docker was added to sonar.sources). They are
> independent of NUTCH-3130.
> *Security*
> * docker:S6471: alpine defaults to root; no USER instruction. CWE-250. The
> image CMD is /bin/bash and nutch/crawl are on PATH as root. docker/README.md
> already recommends a dedicated low-privilege user.
> *Maintainability*
> * docker:S6595: RUN apk update is a separate layer (stale/index bloat).
> * docker:S7031: consecutive RUN instructions (apk, rc files, clone, ln).
> * docker:S6570: unquoted $HOME and $NUTCH_HOME (word-splitting/globbing).
> *Proposed fix*
> * Single RUN: apk --no-cache add (no standalone apk update), create nutch
> user/group, clone+ant runtime, symlinks, chown.
> * Quote all shell variable expansions.
> * USER nutch before CMD. Move install prefix off /root (e.g. /opt/nutch) so
> NUTCH_HOME is owned by the runtime user. Document the path change in
> docker/README.md (breaking for anyone mounting /root/nutch_source).
> * Keep ENV JAVA_HOME; drop redundant .bashrc/.ashrc writes or write a quoted
> /etc/profile.d snippet during the same RUN.
> See:
> https://sonarcloud.io/project/issues?id=apache_nutch&pullRequest=967
--
This message was sent by Atlassian Jira
(v8.20.10#820010)