container icon indicating copy to clipboard operation
container copied to clipboard

Use COPY instead of ADD for gu-wrapper.sh

Open jbochi opened this issue 3 years ago • 1 comments

According to Docker's best practices, COPY is preferred

Dockle also reports this as a potential vulnerability:

FATAL	- CIS-DI-0009: Use COPY instead of ADD in Dockerfile
	* Use COPY : ADD gu-wrapper.sh /usr/local/bin/gu # buildkit

jbochi avatar Aug 11 '22 15:08 jbochi

Thank you for your pull request and welcome to our community! To contribute, please sign the Oracle Contributor Agreement (OCA). The following contributors of this PR have not signed the OCA:

To sign the OCA, please create an Oracle account and sign the OCA in Oracle's Contributor Agreement Application.

When singing the OCA, please provide your GitHub username. After signing the OCA and getting an OCA approval from Oracle, this PR will be automatically updated.

Friendly ping

jbochi avatar Sep 19 '22 15:09 jbochi

+1

vladdoster avatar Oct 19 '22 14:10 vladdoster

Thank you for the contribution. @mlouriz please integrate these changes internally (once they are merged, looking into why the duplicate OCA checks)

ezzarghili avatar Oct 19 '22 15:10 ezzarghili

Thanks for the review! I'm afraid I don't have permission to merge the PR though:

image

jbochi avatar Oct 19 '22 15:10 jbochi

Thanks for the review! I'm afraid I don't have permission to merge the PR though:

image

We are looking into why the oca-check is duplicated in this PR

ezzarghili avatar Oct 19 '22 15:10 ezzarghili