Skip to content

v1.4.8-testnet #74

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 2 commits into
base: master
Choose a base branch
from
Open
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -4,8 +4,8 @@ RUN adduser --disabled-password --gecos "" --no-create-home --uid 1000 cronos

RUN mkdir -p /home/cronos/data && mkdir -p /home/cronos/config
RUN apt-get update -y && apt-get install wget curl procps net-tools jq lz4 -y
RUN cd /tmp && wget --no-check-certificate https://github.com/crypto-org-chain/cronos/releases/download/v1.4.7/cronos_1.4.7_Linux_x86_64.tar.gz && tar -xvf cronos_1.4.7_Linux_x86_64.tar.gz \
&& rm cronos_1.4.7_Linux_x86_64.tar.gz && mv ./* /home/cronos/
RUN cd /tmp && wget --no-check-certificate https://github.com/crypto-org-chain/cronos/releases/download/v1.4.7/cronos_1.4.8-testnet_Linux_x86_64.tar.gz && tar -xvf cronos_1.4.8-testnet_Linux_x86_64.tar.gz \
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue

--no-check-certificate disables TLS verification

Disabling certificate checks defeats HTTPS and exposes the supply-chain to MITM attacks. Remove the flag and, ideally, verify a SHA-256 checksum or GPG signature instead.

-wget --no-check-certificate https://github.com/crypto-org-chain/…
+wget -q https://github.com/crypto-org-chain/…
+# OPTIONAL: echo "<sha256>  cronos_1.4.8-testnet_Linux_x86_64.tar.gz" | sha256sum -c -
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
RUN cd /tmp && wget --no-check-certificate https://github.com/crypto-org-chain/cronos/releases/download/v1.4.7/cronos_1.4.8-testnet_Linux_x86_64.tar.gz && tar -xvf cronos_1.4.8-testnet_Linux_x86_64.tar.gz \
RUN cd /tmp && \
wget -q https://github.com/crypto-org-chain/cronos/releases/download/v1.4.7/cronos_1.4.8-testnet_Linux_x86_64.tar.gz && \
# OPTIONAL: echo "<sha256> cronos_1.4.8-testnet_Linux_x86_64.tar.gz" | sha256sum -c - && \
tar -xvf cronos_1.4.8-testnet_Linux_x86_64.tar.gz \
🧰 Tools
🪛 Checkov (3.2.334)

[HIGH] 7-8: Ensure that certificate validation isn't disabled with wget

(CKV2_DOCKER_3)

🤖 Prompt for AI Agents
In Dockerfile at line 7, remove the --no-check-certificate flag from the wget
command to re-enable TLS verification. Additionally, after downloading the file,
add a step to verify its integrity by checking the SHA-256 checksum or
validating a GPG signature before extracting the archive. This ensures the
downloaded file is authentic and secure.

⚠️ Potential issue

Download URL points to old tag ‒ build will 404

The path still uses releases/download/v1.4.7/…1.4.8-testnet….
Because GitHub release assets are nested under the matching tag, the image will fail at build time with 404: Not Found.

-https://github.com/crypto-org-chain/cronos/releases/download/v1.4.7/cronos_1.4.8-testnet_Linux_x86_64.tar.gz
+https://github.com/crypto-org-chain/cronos/releases/download/v1.4.8-testnet/cronos_1.4.8-testnet_Linux_x86_64.tar.gz
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
RUN cd /tmp && wget --no-check-certificate https://github.com/crypto-org-chain/cronos/releases/download/v1.4.7/cronos_1.4.8-testnet_Linux_x86_64.tar.gz && tar -xvf cronos_1.4.8-testnet_Linux_x86_64.tar.gz \
RUN cd /tmp && wget --no-check-certificate https://github.com/crypto-org-chain/cronos/releases/download/v1.4.8-testnet/cronos_1.4.8-testnet_Linux_x86_64.tar.gz && tar -xvf cronos_1.4.8-testnet_Linux_x86_64.tar.gz \
🧰 Tools
🪛 Checkov (3.2.334)

[HIGH] 7-8: Ensure that certificate validation isn't disabled with wget

(CKV2_DOCKER_3)

🤖 Prompt for AI Agents
In Dockerfile at line 7, the download URL uses the old tag v1.4.7 while trying
to fetch a v1.4.8-testnet asset, causing a 404 error. Update the URL path to use
the correct tag v1.4.8 so the release asset matches the tag and the build can
successfully download the file.

&& rm cronos_1.4.8-testnet_Linux_x86_64.tar.gz && mv ./* /home/cronos/
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛠️ Refactor suggestion

Wildcard mv ./* may relocate unrelated /tmp files

After extraction, mv ./* /home/cronos/ moves everything currently in /tmp, which can unintentionally include unrelated temporary artefacts. Limit the move to the extracted directory contents:

-&& rm cronos_1.4.8-testnet_Linux_x86_64.tar.gz && mv ./* /home/cronos/
+&& rm cronos_1.4.8-testnet_Linux_x86_64.tar.gz \
+&& mv cronos_1.4.8-testnet_Linux_x86_64/* /home/cronos/ \
+&& rmdir cronos_1.4.8-testnet_Linux_x86_64
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
&& rm cronos_1.4.8-testnet_Linux_x86_64.tar.gz && mv ./* /home/cronos/
&& rm cronos_1.4.8-testnet_Linux_x86_64.tar.gz \
&& mv cronos_1.4.8-testnet_Linux_x86_64/* /home/cronos/ \
&& rmdir cronos_1.4.8-testnet_Linux_x86_64
🧰 Tools
🪛 Checkov (3.2.334)

[HIGH] 7-8: Ensure that certificate validation isn't disabled with wget

(CKV2_DOCKER_3)

🤖 Prompt for AI Agents
In Dockerfile at line 8, the command `mv ./* /home/cronos/` moves all files in
the current directory, which may include unrelated temporary files. Modify this
to move only the extracted directory or specific extracted files by replacing
the wildcard with the exact extracted folder name or pattern to avoid moving
unrelated files.

RUN chown -R cronos:cronos /home/cronos && chmod 1777 /tmp

USER root
Expand Down