Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix for Dockerfile smell DL3007 #103

Merged
merged 1 commit into from
Apr 20, 2023

Conversation

grosa1
Copy link
Contributor

@grosa1 grosa1 commented Apr 12, 2023

Hi!
The Dockerfile placed at "Dockerfile" contains the best practice violation DL3007 detected by the hadolint tool.

The smell DL3007 occurs when the tag "latest" is used instead of a specific version tag for the base image.
In this pull request, we propose a fix for that smell generated by our fixing tool. We have verified that the patch is correct before opening the pull request.
To fix this smell, specifically, we use a heuristic approach that selects the most probable version tag for the base image in order to replace the "latest" tag. In detail, it selects the most recent image tag which corresponds to the same image digest that currently corresponds to the "latest" tag.

This change is only aimed at fixing that specific smell. If the fix is not valid or useful, please briefly indicate the reason and suggestions for possible improvements.

Thanks in advance

Signed-off-by: Giovanni Rosa <g.rosa1@studenti.unimol.it>
@chandanpasunoori
Copy link
Collaborator

chandanpasunoori commented Apr 12, 2023

I appreciate the detailed pull request, happy to merge but I still feel not justified, as this only affects at build time and automatically tested in ci test

also by running in latest alpine version, its always guaranteed to be up to date with current changes/patches of os and security updates new vulnerabilities

@grosa1
Copy link
Contributor Author

grosa1 commented Apr 13, 2023

Hi @chandanpasunoori,
the patch is only for the reliability of the image in case of an update that could lead to failures in the current content of the Dockerfile.
The version tag could be less restrictive like FROM alpine3 to catch all the updates and fix the major version. Maybe it will be better in that case

@chandanpasunoori chandanpasunoori merged commit b35e746 into boz:master Apr 20, 2023
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants