[ 
https://issues.apache.org/jira/browse/NUTCH-3213?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18116971#comment-18116971
 ] 

ASF GitHub Bot commented on NUTCH-3213:
---------------------------------------

github-actions[bot] commented on PR #968:
URL: https://github.com/apache/nutch/pull/968#issuecomment-5740124911

   ## Apache Yetus test-patch report
   
   |            |
   |------------|
   | -1 overall |
   
   |      |              |         |                                            
                 |                                                              
       |
   
|------|--------------|---------|-------------------------------------------------------------|---------------------------------------------------------------------|
   | Vote | Subsystem    | Runtime | Log                                        
                 | Comment                                                      
       |
   |      |              |         |                                            
                 | Prechecks                                                    
       |
   | +1   | dupname      | 0m 0s   |                                            
                 | No case conflicting files found.                             
       |
   | +1   | @author      | 0m 1s   |                                            
                 | The patch does not contain any @author tags.                 
       |
   |      |              |         |                                            
                 | master Compile Tests                                         
       |
   |      |              |         |                                            
                 | Patch Compile Tests                                          
       |
   | +1   | codespell    | 0m 1s   |                                            
                 | No new issues.                                               
       |
   | +1   | detsecrets   | 0m 28s  |                                            
                 | No new issues.                                               
       |
   | -1   | blanks       | 0m 0s   | [/blanks-tabs.txt](/blanks-tabs.txt)\</\>  
                 | The patch 2 line(s) with tabs.                               
       |
   | -1   | hadolint     | 0m 0s   | 
[/results-hadolint.txt](/results-hadolint.txt)\</\>         | The patch 
generated 1 new + 1 unchanged - 8 fixed = 2 total (was 9) |
   | -1   | markdownlint | 0m 1s   | 
[/results-markdownlint.txt](/results-markdownlint.txt)\</\> | The patch 
generated 3 new + 5 unchanged - 1 fixed = 8 total (was 6) |
   | +1   | shellcheck   | 0m 0s   |                                            
                 | No new issues.                                               
       |
   | +1   | shelldocs    | 0m 0s   |                                            
                 | No new issues.                                               
       |
   |      |              |         |                                            
                 | Other Tests                                                  
       |
   | +1   | asflicense   | 0m 1s   |                                            
                 | The patch does not generate ASF License warnings.            
       |
   |      |              | 0m 38s  |                                            
                 |                                                              
       |
   
   |                |                                                           
                                                       |
   
|----------------|------------------------------------------------------------------------------------------------------------------|
   | Subsystem      | Report/Notes                                              
                                                       |
   | GITHUB PR      | https://github.com/apache/nutch/pull/968                  
                                                       |
   | Optional Tests | dupname asflicense codespell detsecrets hadolint 
shellcheck shelldocs markdownlint                               |
   | uname          | Linux c436871a17d2 6.17.0-1022-azure \#22-Ubuntu SMP Mon 
Jul 27 17:24:03 UTC 2026 x86_64 x86_64 x86_64 GNU/Linux |
   | Build tool     | nobuild                                                   
                                                       |
   | Personality    | /github/workspace/.yetus/personality.sh                   
                                                       |
   | git revision   | master / ee07a8afa80a65cfffef850d290458a794c3f95d         
                                                       |
   | modules        | C: . U: .                                                 
                                                       |
   | versions       | git=2.34.1 hadolint=2.12.0 codespell=2.4.1 
detsecrets=1.5.0 markdownlint=0.44.0 shellcheck=0.10.0                |
   | Powered by     | Apache Yetus 0.15.1 https://yetus.apache.org              
                                                       |
   
   This message was automatically generated.
   
   <!

> Harden Docker image: non-root USER and Dockerfile lint (SonarCloud)
> -------------------------------------------------------------------
>
>                 Key: NUTCH-3213
>                 URL: https://issues.apache.org/jira/browse/NUTCH-3213
>             Project: Nutch
>          Issue Type: Improvement
>          Components: docker
>    Affects Versions: 1.23
>            Reporter: Lewis John McGibbney
>            Assignee: Lewis John McGibbney
>            Priority: Major
>             Fix For: 1.24
>
>
> SonarCloud Docker analysis of docker/Dockerfile reports 8 OPEN issues 
> (visible on PR analysis after docker was added to sonar.sources). They are 
> independent of NUTCH-3130.
> *Security*
>  * docker:S6471: alpine defaults to root; no USER instruction. CWE-250. The 
> image CMD is /bin/bash and nutch/crawl are on PATH as root. docker/README.md 
> already recommends a dedicated low-privilege user.
> *Maintainability*
>  * docker:S6595: RUN apk update is a separate layer (stale/index bloat).
>  * docker:S7031: consecutive RUN instructions (apk, rc files, clone, ln).
>  * docker:S6570: unquoted $HOME and $NUTCH_HOME (word-splitting/globbing).
> *Proposed fix*
>  * Single RUN: apk --no-cache add (no standalone apk update), create nutch 
> user/group, clone+ant runtime, symlinks, chown.
>  * Quote all shell variable expansions.
>  * USER nutch before CMD. Move install prefix off /root (e.g. /opt/nutch) so 
> NUTCH_HOME is owned by the runtime user. Document the path change in 
> docker/README.md (breaking for anyone mounting /root/nutch_source).
>  * Keep ENV JAVA_HOME; drop redundant .bashrc/.ashrc writes or write a quoted 
> /etc/profile.d snippet during the same RUN.
> See:
> https://sonarcloud.io/project/issues?id=apache_nutch&pullRequest=967



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to