-
Notifications
You must be signed in to change notification settings - Fork 2
feat: INFRA-6018 Cronos testnet image upgrade v1.5.1 #85
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Signed-off-by: Dmitrii Spichakov <dmitrii.spichakov@chainstack.com>
WalkthroughUpdates the Dockerfile to switch the Cronos binary download from v1.4.11 to v1.5.1-testnet by changing the URL, tarball filename, and extraction references. No changes to permissions, entrypoint, or other installation steps. Changes
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~2 minutes Possibly related PRs
Poem
Pre-merge checks and finishing touches✅ Passed checks (3 passed)
✨ Finishing touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Actionable comments posted: 1
📜 Review details
Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro
📒 Files selected for processing (1)
Dockerfile(1 hunks)
🧰 Additional context used
🪛 Checkov (3.2.334)
Dockerfile
[high] 11-12: Ensure that certificate validation isn't disabled with wget
(CKV2_DOCKER_3)
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (1)
- GitHub Check: guardrails/scan
| RUN cd /tmp && wget --no-check-certificate https://github.com/crypto-org-chain/cronos/releases/download/v1.5.1/cronos_1.5.1-testnet_Linux_x86_64.tar.gz && tar -xvf cronos_1.5.1-testnet_Linux_x86_64.tar.gz \ | ||
| && rm cronos_1.5.1-testnet_Linux_x86_64.tar.gz && mv ./* /home/cronos/ |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Drop --no-check-certificate to avoid MITM exposure.
Disabling TLS validation when fetching the release tarball lets any man-in-the-middle swap the binary, which is an unacceptable supply-chain risk for production images. Please keep certificate checks enabled (and ideally add checksum verification). Fix by removing the flag:
-RUN cd /tmp && wget --no-check-certificate https://github.com/crypto-org-chain/cronos/releases/download/v1.5.1/cronos_1.5.1-testnet_Linux_x86_64.tar.gz && tar -xvf cronos_1.5.1-testnet_Linux_x86_64.tar.gz \
+RUN cd /tmp && wget https://github.com/crypto-org-chain/cronos/releases/download/v1.5.1/cronos_1.5.1-testnet_Linux_x86_64.tar.gz && tar -xvf cronos_1.5.1-testnet_Linux_x86_64.tar.gz \🧰 Tools
🪛 Checkov (3.2.334)
[high] 11-12: Ensure that certificate validation isn't disabled with wget
(CKV2_DOCKER_3)
🤖 Prompt for AI Agents
In Dockerfile around lines 11-12, the wget invocation disables TLS certificate
validation via --no-check-certificate which exposes the build to MITM and
supply-chain attacks; remove the --no-check-certificate flag and instead fetch
the release over HTTPS with normal certificate checks enabled, and add
deterministic verification by downloading or embedding a trusted
checksum/signature (e.g., SHA256 or GPG signature) for the tarball and
validating it in the Dockerfile before extracting; ensure the build fails if the
checksum/signature does not match.
Cronos testnet image upgrade v1.5.1
INFRA-6018 Cronos testnet upgrade v1.5.1
Summary by CodeRabbit