Skip to content

v1.4.8-testnet #74

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 2 commits into
base: master
Choose a base branch
from
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -4,8 +4,8 @@ RUN adduser --disabled-password --gecos "" --no-create-home --uid 1000 cronos

RUN mkdir -p /home/cronos/data && mkdir -p /home/cronos/config
RUN apt-get update -y && apt-get install wget curl procps net-tools jq lz4 -y
RUN cd /tmp && wget --no-check-certificate https://github.com/crypto-org-chain/cronos/releases/download/v1.4.7/cronos_1.4.7_Linux_x86_64.tar.gz && tar -xvf cronos_1.4.7_Linux_x86_64.tar.gz \
&& rm cronos_1.4.7_Linux_x86_64.tar.gz && mv ./* /home/cronos/
RUN cd /tmp && wget --no-check-certificate https://github.com/crypto-org-chain/cronos/releases/download/v1.4.8/cronos_1.4.8-testnet_Linux_x86_64.tar.gz && tar -xvf cronos_1.4.8-testnet_Linux_x86_64.tar.gz \
&& rm cronos_1.4.8-testnet_Linux_x86_64.tar.gz && mv ./* /home/cronos/
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛠️ Refactor suggestion

Wildcard mv ./* may relocate unrelated /tmp files

After extraction, mv ./* /home/cronos/ moves everything currently in /tmp, which can unintentionally include unrelated temporary artefacts. Limit the move to the extracted directory contents:

-&& rm cronos_1.4.8-testnet_Linux_x86_64.tar.gz && mv ./* /home/cronos/
+&& rm cronos_1.4.8-testnet_Linux_x86_64.tar.gz \
+&& mv cronos_1.4.8-testnet_Linux_x86_64/* /home/cronos/ \
+&& rmdir cronos_1.4.8-testnet_Linux_x86_64
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
&& rm cronos_1.4.8-testnet_Linux_x86_64.tar.gz && mv ./* /home/cronos/
&& rm cronos_1.4.8-testnet_Linux_x86_64.tar.gz \
&& mv cronos_1.4.8-testnet_Linux_x86_64/* /home/cronos/ \
&& rmdir cronos_1.4.8-testnet_Linux_x86_64
🧰 Tools
🪛 Checkov (3.2.334)

[HIGH] 7-8: Ensure that certificate validation isn't disabled with wget

(CKV2_DOCKER_3)

🤖 Prompt for AI Agents
In Dockerfile at line 8, the command `mv ./* /home/cronos/` moves all files in
the current directory, which may include unrelated temporary files. Modify this
to move only the extracted directory or specific extracted files by replacing
the wildcard with the exact extracted folder name or pattern to avoid moving
unrelated files.

Comment on lines +7 to +8
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛠️ Refactor suggestion

ENTRYPOINT path mismatch – container may not start

With the corrected move, cronosd ends up in /home/cronos/ (or in bin/ depending on tar layout). Align one of the two:

-ENTRYPOINT ["/home/cronos/bin/cronosd"]
+ENTRYPOINT ["/home/cronos/cronosd"]
# or preserve hierarchy:
+# RUN mv cronos_1.4.8-testnet_Linux_x86_64/bin/* /home/cronos/bin/
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
RUN cd /tmp && wget --no-check-certificate https://github.com/crypto-org-chain/cronos/releases/download/v1.4.8/cronos_1.4.8-testnet_Linux_x86_64.tar.gz && tar -xvf cronos_1.4.8-testnet_Linux_x86_64.tar.gz \
&& rm cronos_1.4.8-testnet_Linux_x86_64.tar.gz && mv ./* /home/cronos/
# unchanged download & extraction step
RUN cd /tmp && \
wget --no-check-certificate https://github.com/crypto-org-chain/cronos/releases/download/v1.4.8/cronos_1.4.8-testnet_Linux_x86_64.tar.gz && \
tar -xvf cronos_1.4.8-testnet_Linux_x86_64.tar.gz && \
rm cronos_1.4.8-testnet_Linux_x86_64.tar.gz && \
mv ./* /home/cronos/
# adjust ENTRYPOINT to match the moved binary
ENTRYPOINT ["/home/cronos/cronosd"]
🧰 Tools
🪛 Checkov (3.2.334)

[HIGH] 7-8: Ensure that certificate validation isn't disabled with wget

(CKV2_DOCKER_3)

🤖 Prompt for AI Agents
In the Dockerfile around lines 7 to 8, the RUN command moves extracted files to
/home/cronos/, but the ENTRYPOINT path likely points elsewhere causing container
startup issues. To fix this, verify where the cronosd binary is located after
extraction (either directly in /home/cronos/ or in a subdirectory like bin/) and
update the ENTRYPOINT path accordingly to match that location, ensuring the
container can start correctly.

RUN chown -R cronos:cronos /home/cronos && chmod 1777 /tmp

USER root
Expand Down