Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
197 commits
Select commit Hold shift + click to select a range
bba699f
fix(query): fix EFS Volume With Disabled Transit Encryption queries f…
cx-artur-ribeiro Mar 17, 2026
d4541b4
fix(analyzer): add failed utf conversions to unwanted files (#7997)
cx-miguel-dasilva Mar 18, 2026
91d0561
Upgrade Trivy action to version 0.35.0
cx-eli-shalnev Mar 24, 2026
8ac5b5f
fix(dockerhub): add token login to DockerHub (#8024)
cx-artur-ribeiro Apr 2, 2026
8db6ffb
feat(testing): add arm64 testing infra (#7998)
cx-miguel-dasilva Apr 8, 2026
5301907
feat(tests): improving E2E HTML report and output on remediation test…
cx-ricardo-jesus Apr 10, 2026
5a482da
fix(workflows): update github actions to use SHA (#8035)
cx-bruno-silva Apr 13, 2026
501217a
feat(action): added validation for searchLine field in actions (#7994)
cx-ricardo-jesus Apr 13, 2026
50040ad
Change to use actions role (#8040)
cx-joao-reigota Apr 20, 2026
236917f
ci(secrets): use aws oidc (#8041)
cx-rafael-carvalho Apr 21, 2026
d996ab7
fix(query): fix FP results on "IAM policy allows for data exfiltratio…
cx-andre-pereira Apr 22, 2026
b7fc8b2
[StepSecurity] Apply security best practices (#8060)
stepsecurity-app[bot] May 22, 2026
12e9263
[StepSecurity] Apply security best practices (#8063)
stepsecurity-app[bot] May 30, 2026
0004b2a
chore: remove Dependabot configuration
cx-ohad-israeli Jun 10, 2026
b0f6612
Remove old SBOM (#8071)
cx-yevgeny-kuznetsov Jun 16, 2026
cc8580e
fix(vulnerabilities): update dockerfile and fix trivy vulnerabilities…
cx-artur-ribeiro Jul 7, 2026
0f24765
First tests
cx-andre-pereira Mar 23, 2026
ea2e49d
First commit with changes to all dockerfile queries for case insesiti…
cx-andre-pereira Mar 23, 2026
4c7e05d
Fixes for queries that require extra commands and some expected resul…
cx-andre-pereira Mar 24, 2026
3787bc4
Small fix to update instruction alone query
cx-andre-pereira Mar 24, 2026
2de274d
Test changes for payload compatibility
cx-andre-pereira Apr 7, 2026
79fa0eb
Testings possible fix for parsing issue (multiple From statements)
cx-andre-pereira Apr 7, 2026
c0a3d1a
Removed needless check
cx-andre-pereira Apr 7, 2026
cb0c25e
Fixes
cx-andre-pereira Apr 7, 2026
bd2b9a1
Mini fix for linting
cx-andre-pereira Apr 7, 2026
cb2606f
Added id to distinguish repeated FROM statements on the same image (l…
cx-andre-pereira Apr 7, 2026
2da0fd6
Linting fix 2
cx-andre-pereira Apr 7, 2026
70e8926
Best of both worlds solution, fallback to the implementation that cha…
cx-andre-pereira Apr 7, 2026
6a52b8d
slight changes to query
cx-andre-pereira Apr 8, 2026
61d0dde
SimID now depends on number of duplicate FROM statements prior to the…
cx-andre-pereira Apr 8, 2026
643e868
If it is decided that altered image name can be kept queries can stay…
cx-andre-pereira Apr 8, 2026
f609616
Revert accidental line change in positive3
cx-andre-pereira Apr 8, 2026
faff97b
Small fix unit test
cx-andre-pereira Apr 8, 2026
74aae89
SearchKey values in results are now sanitized of extra ^hintLine adde…
cx-andre-pereira Apr 8, 2026
50d7215
Moved auxiliary functions to common library and adjusted all queries …
cx-andre-pereira Apr 9, 2026
3bc4bbd
Files that should have been in previous commit
cx-andre-pereira Apr 9, 2026
69037e6
Fix E2E testcase
cx-andre-pereira Apr 9, 2026
0ebb8c5
Adjusted expected results for same alias in different forms query
cx-andre-pereira Apr 9, 2026
cbe5d4a
E2E fixture fix and typo fix
cx-andre-pereira Apr 9, 2026
9dc1460
Unit test to ensure line hint is being used on docker_detect
cx-andre-pereira Apr 10, 2026
5ab61dd
Added unit test to docker parser to ensure duplicate FROMs are distin…
cx-andre-pereira Apr 10, 2026
b4af7b1
Added unit test to vulnerability builder to ensure line hint is remov…
cx-andre-pereira Apr 10, 2026
83d4700
Changed identification of docker files to be case insensitive on file…
cx-andre-pereira Mar 11, 2026
3c4c2f9
removed legacy redundant function 'isDockerfile' from analyzer
cx-andre-pereira Mar 11, 2026
429d080
Improved dockerfile identification to account for relevant folder nam…
cx-andre-pereira Mar 11, 2026
e8cea97
Fixed 'dockerfile' keyword not being recognized as a valid file exten…
cx-andre-pereira Mar 12, 2026
eb7288e
Minor optimization
cx-andre-pereira Mar 12, 2026
7a11489
Initial test files/cases plus minor changes to supported dockerfile f…
cx-andre-pereira Mar 12, 2026
7449c73
Added new helper function 'isDockerfileExtension' to get_extension ut…
cx-andre-pereira Mar 12, 2026
8f1717f
reverted accidental query change, fixed linting errors, fixed test er…
cx-andre-pereira Mar 12, 2026
a14529a
linting fix and optimized case of file named dockerfile without exten…
cx-andre-pereira Mar 12, 2026
2a37a48
More changes to fix go lint, d variable so 'dockerfile' is not used t…
cx-andre-pereira Mar 12, 2026
7ab06e5
Added samples for case insensitive testing on dockerfiles, added E2E …
cx-andre-pereira Mar 13, 2026
273df03
fix for E2E
cx-andre-pereira Mar 13, 2026
766f751
Changed relevant functions to always treat/set the extension of valid…
cx-andre-pereira Mar 15, 2026
692546c
Removed last mention of 'dockerfile' without dot notation
cx-andre-pereira Mar 16, 2026
67df153
Changed 'gitignore' check for better check order in 'GetExtension' fu…
cx-andre-pereira Mar 16, 2026
8eb63e4
Slightly more restrictive check to FROM command to ensure it has a tr…
cx-andre-pereira Mar 16, 2026
e080511
Updates to functions, removed unnecessary if statement on scan.go and…
cx-andre-pereira Mar 17, 2026
41bdb54
fix previous commit
cx-andre-pereira Mar 17, 2026
b4615b4
fix analyzer uni tests
cx-andre-pereira Mar 17, 2026
84ac6fe
simplified new if condition
cx-andre-pereira Mar 17, 2026
90d55ed
lint fix
cx-andre-pereira Mar 17, 2026
92a26ac
fixed analyze unit tests, with names ending in 'gitignore' no longer …
cx-andre-pereira Mar 17, 2026
c9e8930
Case-insensitive unit tests for dockerfile samples
cx-andre-pereira Mar 17, 2026
3647d75
Slight changes to new test
cx-andre-pereira Mar 17, 2026
20acc5e
Slight simplification of new docker/parser unit test
cx-andre-pereira Mar 17, 2026
9d9c96f
Mini fix on insensitive_sample
cx-andre-pereira Mar 19, 2026
f87e435
Changed E2E to 106 to fix merge conflict
cx-andre-pereira Mar 19, 2026
1fc0250
fix E2E tests
cx-andre-pereira Mar 19, 2026
3d88d25
Final E2E fix
cx-andre-pereira Mar 19, 2026
1c1619c
Update to 'Docker' related documentation
cx-andre-pereira Mar 20, 2026
ba3ce5a
Requested change - made extDockerfile a constant
cx-andre-pereira Mar 23, 2026
9e4ca75
Fixed E2E 106 fixture 'RESULT' file name
cx-andre-pereira Mar 23, 2026
d42dc7e
Refactor to 'get_extension' and 'analyzer' to reduce redudancy
cx-andre-pereira Mar 23, 2026
21d82ee
Lint error fix
cx-andre-pereira Mar 23, 2026
da7d529
Newline removed (lint)
cx-andre-pereira Mar 23, 2026
85d9ec2
Renamed variable to prevent confusing shadowing
cx-andre-pereira Mar 23, 2026
8efbd3c
Requested E2E change
cx-andre-pereira Mar 26, 2026
36f49e4
Removed .ubi8 and .debian extensions checks
cx-andre-pereira Mar 30, 2026
e8c7503
Fallback on debian and ubi removal from docker/parser to test E2E
cx-andre-pereira Mar 31, 2026
6311b27
E2E test 2
cx-andre-pereira Mar 31, 2026
2399363
New 'python' samples to test for edge case 'from' statements on files…
cx-andre-pereira Apr 13, 2026
ddbd668
New samples and improved, tailored regex for dockerfile FROM statemen…
cx-andre-pereira Apr 14, 2026
ce1680c
Removed duplicated sample(negative) that was in positive test fixture…
cx-andre-pereira Apr 14, 2026
2fa5fd6
Final fix for E2E plus the test file removal that should have been in…
cx-andre-pereira Apr 14, 2026
20e3d7c
Updates E2E fixtures
cx-andre-pereira Apr 16, 2026
788d0df
First fix attempt on validate-search-line script
cx-andre-pereira Apr 16, 2026
cb54625
Removed need to do -1 when calling line hint function and updated doc…
cx-andre-pereira Apr 17, 2026
1400b6d
Fixed expected and actual values for using_platform_with_from query
cx-andre-pereira Apr 17, 2026
a8eb48f
Fix E2E results
cx-andre-pereira Apr 17, 2026
1b71791
Made UrlRegex a constant
cx-andre-pereira Apr 20, 2026
3901170
New samples, changed fockerfile syntax identification to aproach to e…
cx-andre-pereira Apr 21, 2026
7e63ee9
Linter fix
cx-andre-pereira Apr 21, 2026
393382d
The actual linter fix
cx-andre-pereira Apr 21, 2026
b9da284
Fixed dokcerfile lib from statement function LineHint value so multil…
cx-andre-pereira Apr 22, 2026
58a95d2
Fix E2E 107
cx-andre-pereira Apr 22, 2026
a574547
First tests
cx-andre-pereira Mar 23, 2026
79d1133
First commit with changes to all dockerfile queries for case insesiti…
cx-andre-pereira Mar 23, 2026
a3434e3
Fixes for queries that require extra commands and some expected resul…
cx-andre-pereira Mar 24, 2026
311cfb1
Small fix to update instruction alone query
cx-andre-pereira Mar 24, 2026
d4348e9
Test changes for payload compatibility
cx-andre-pereira Apr 7, 2026
a477804
Testings possible fix for parsing issue (multiple From statements)
cx-andre-pereira Apr 7, 2026
4ef06c5
Removed needless check
cx-andre-pereira Apr 7, 2026
c0df1b3
Fixes
cx-andre-pereira Apr 7, 2026
f226837
Mini fix for linting
cx-andre-pereira Apr 7, 2026
2ed6a93
Added id to distinguish repeated FROM statements on the same image (l…
cx-andre-pereira Apr 7, 2026
6ae576f
Linting fix 2
cx-andre-pereira Apr 7, 2026
f8f0024
Best of both worlds solution, fallback to the implementation that cha…
cx-andre-pereira Apr 7, 2026
fe21f24
slight changes to query
cx-andre-pereira Apr 8, 2026
11c7d48
SimID now depends on number of duplicate FROM statements prior to the…
cx-andre-pereira Apr 8, 2026
696faef
If it is decided that altered image name can be kept queries can stay…
cx-andre-pereira Apr 8, 2026
7619033
Revert accidental line change in positive3
cx-andre-pereira Apr 8, 2026
fb64182
Small fix unit test
cx-andre-pereira Apr 8, 2026
a10d9fa
SearchKey values in results are now sanitized of extra ^hintLine adde…
cx-andre-pereira Apr 8, 2026
d8772be
Moved auxiliary functions to common library and adjusted all queries …
cx-andre-pereira Apr 9, 2026
656d3dc
Files that should have been in previous commit
cx-andre-pereira Apr 9, 2026
0d021dc
Fix E2E testcase
cx-andre-pereira Apr 9, 2026
118ef04
Adjusted expected results for same alias in different forms query
cx-andre-pereira Apr 9, 2026
50f8197
E2E fixture fix and typo fix
cx-andre-pereira Apr 9, 2026
ab60adf
Unit test to ensure line hint is being used on docker_detect
cx-andre-pereira Apr 10, 2026
e664f57
Added unit test to docker parser to ensure duplicate FROMs are distin…
cx-andre-pereira Apr 10, 2026
785e807
Added unit test to vulnerability builder to ensure line hint is remov…
cx-andre-pereira Apr 10, 2026
e8c1c79
Changed identification of docker files to be case insensitive on file…
cx-andre-pereira Mar 11, 2026
602ce1f
removed legacy redundant function 'isDockerfile' from analyzer
cx-andre-pereira Mar 11, 2026
21f9ded
Improved dockerfile identification to account for relevant folder nam…
cx-andre-pereira Mar 11, 2026
b22c5b9
Fixed 'dockerfile' keyword not being recognized as a valid file exten…
cx-andre-pereira Mar 12, 2026
3c613f3
Minor optimization
cx-andre-pereira Mar 12, 2026
1776662
Initial test files/cases plus minor changes to supported dockerfile f…
cx-andre-pereira Mar 12, 2026
fb941b2
Added new helper function 'isDockerfileExtension' to get_extension ut…
cx-andre-pereira Mar 12, 2026
6414f8f
reverted accidental query change, fixed linting errors, fixed test er…
cx-andre-pereira Mar 12, 2026
887c5ef
linting fix and optimized case of file named dockerfile without exten…
cx-andre-pereira Mar 12, 2026
f1970db
More changes to fix go lint, d variable so 'dockerfile' is not used t…
cx-andre-pereira Mar 12, 2026
69af0d4
Added samples for case insensitive testing on dockerfiles, added E2E …
cx-andre-pereira Mar 13, 2026
fe0744a
fix for E2E
cx-andre-pereira Mar 13, 2026
3101be4
Changed relevant functions to always treat/set the extension of valid…
cx-andre-pereira Mar 15, 2026
c53f0b0
Removed last mention of 'dockerfile' without dot notation
cx-andre-pereira Mar 16, 2026
84e4355
Changed 'gitignore' check for better check order in 'GetExtension' fu…
cx-andre-pereira Mar 16, 2026
3d37cb6
Slightly more restrictive check to FROM command to ensure it has a tr…
cx-andre-pereira Mar 16, 2026
478709f
Updates to functions, removed unnecessary if statement on scan.go and…
cx-andre-pereira Mar 17, 2026
1a5109d
fix previous commit
cx-andre-pereira Mar 17, 2026
b816c1c
fix analyzer uni tests
cx-andre-pereira Mar 17, 2026
6158a4e
simplified new if condition
cx-andre-pereira Mar 17, 2026
b6b0b2b
lint fix
cx-andre-pereira Mar 17, 2026
03fc2db
fixed analyze unit tests, with names ending in 'gitignore' no longer …
cx-andre-pereira Mar 17, 2026
a3a713e
Case-insensitive unit tests for dockerfile samples
cx-andre-pereira Mar 17, 2026
b9679e0
Slight changes to new test
cx-andre-pereira Mar 17, 2026
f1a449f
Slight simplification of new docker/parser unit test
cx-andre-pereira Mar 17, 2026
39b26a5
Mini fix on insensitive_sample
cx-andre-pereira Mar 19, 2026
e239141
Changed E2E to 106 to fix merge conflict
cx-andre-pereira Mar 19, 2026
b9335bd
fix E2E tests
cx-andre-pereira Mar 19, 2026
464c9aa
Final E2E fix
cx-andre-pereira Mar 19, 2026
080d358
Update to 'Docker' related documentation
cx-andre-pereira Mar 20, 2026
3ba8bfe
Requested change - made extDockerfile a constant
cx-andre-pereira Mar 23, 2026
fc5f5a7
Fixed E2E 106 fixture 'RESULT' file name
cx-andre-pereira Mar 23, 2026
60e6549
Refactor to 'get_extension' and 'analyzer' to reduce redudancy
cx-andre-pereira Mar 23, 2026
34153a2
Lint error fix
cx-andre-pereira Mar 23, 2026
70a731a
Newline removed (lint)
cx-andre-pereira Mar 23, 2026
e3244e4
Renamed variable to prevent confusing shadowing
cx-andre-pereira Mar 23, 2026
f6ff0c8
Requested E2E change
cx-andre-pereira Mar 26, 2026
14c020f
Removed .ubi8 and .debian extensions checks
cx-andre-pereira Mar 30, 2026
79670c2
Fallback on debian and ubi removal from docker/parser to test E2E
cx-andre-pereira Mar 31, 2026
5142d56
E2E test 2
cx-andre-pereira Mar 31, 2026
aeb3162
Final fix E2E, the E2E itself was incorrect, payload included invalid…
cx-andre-pereira Mar 31, 2026
1bc90f1
New 'python' samples to test for edge case 'from' statements on files…
cx-andre-pereira Apr 13, 2026
2bec8be
New samples and improved, tailored regex for dockerfile FROM statemen…
cx-andre-pereira Apr 14, 2026
5e0324a
Removed duplicated sample(negative) that was in positive test fixture…
cx-andre-pereira Apr 14, 2026
0c14e5f
Final fix for E2E plus the test file removal that should have been in…
cx-andre-pereira Apr 14, 2026
cac520e
Fix previous merge with #7995
cx-andre-pereira Apr 16, 2026
6120824
Updates E2E fixtures
cx-andre-pereira Apr 16, 2026
83fc8d5
First fix attempt on validate-search-line script
cx-andre-pereira Apr 16, 2026
a4ce30a
Removed need to do -1 when calling line hint function and updated doc…
cx-andre-pereira Apr 17, 2026
07b553c
Fixed expected and actual values for using_platform_with_from query
cx-andre-pereira Apr 17, 2026
59b292e
Fix E2E results
cx-andre-pereira Apr 17, 2026
43820fc
Made UrlRegex a constant
cx-andre-pereira Apr 20, 2026
d8cc9f7
New samples, changed fockerfile syntax identification to aproach to e…
cx-andre-pereira Apr 21, 2026
3e84273
Linter fix
cx-andre-pereira Apr 21, 2026
be7a1d9
The actual linter fix
cx-andre-pereira Apr 21, 2026
42c4ccd
E2E fix
cx-andre-pereira Apr 22, 2026
c1b3bb9
Fixed dokcerfile lib from statement function LineHint value so multil…
cx-andre-pereira Apr 22, 2026
b3082db
Fix E2E 107
cx-andre-pereira Apr 22, 2026
d8980d6
fix changed files to pre-rebase state
cx-andre-pereira Jul 8, 2026
9141785
Fixed value attribution that should have been comparison
cx-andre-pereira Jul 27, 2026
12c983e
bug(security): fix security vulnerability findings (#8084)
cx-miguel-dasilva Jul 28, 2026
45b2c89
fix(parser): fixed looping behavior triggered during dockerfile parsi…
cx-andre-pereira Jul 28, 2026
e00a0f5
fix(query): updated "SQL DB Instance With SSL Disabled" Terraform que…
cx-andre-pereira Jul 28, 2026
448e0c6
fix(query): the "Image Version Using Latest" dockerfile query was not…
cx-andre-pereira Jul 28, 2026
275c4e9
updated query to support parameters (#8086)
cx-ricardo-jesus Jul 28, 2026
79b21bf
fix(queries): fixed FN on run/script block injection query for github…
cx-ricardo-jesus Jul 28, 2026
4a3ed73
fix(query): fixed FP for sql server database without auditing for arm…
cx-ricardo-jesus Jul 28, 2026
d10f038
fix(query): fix FP on unpinned package version in pip install for doc…
cx-ricardo-jesus Jul 28, 2026
ae6f63f
Merge branch 'master' into Dockerfile_queries_fix_for_case_insensitivity
cx-andre-pereira Jul 28, 2026
f2d92f2
Re added changes that were undone during rebase / force push
cx-andre-pereira Jul 28, 2026
1164e44
Merge branch 'Dockerfile_queries_fix_for_case_insensitivity' of https…
cx-andre-pereira Jul 28, 2026
90ab1b4
merge master
cx-andre-pereira Aug 17, 2026
14e6993
renamed tests and changed expected results to accomodate for PR 8099
cx-andre-pereira Aug 17, 2026
0cbedb5
Merge branch 'master' into Dockerfile_queries_fix_for_case_insensitivity
cx-andre-pereira Aug 18, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,9 @@ def get_changed_queries():
dirs = []
for f in files:
if f.endswith("/query.rego"):
if f.startswith("assets/queries/dockerfile/"):
print(f" [SKIP] {f}: Dockerfile queries do not support searchLine")
continue
dirs.append(REPO_ROOT / Path(f).parent)
return dirs

Expand Down
14 changes: 13 additions & 1 deletion assets/libraries/dockerfile.rego
Original file line number Diff line number Diff line change
Expand Up @@ -69,4 +69,16 @@ check_multi_stage(imageName, images) {

sortedIndex := sort(unsortedIndex)
imageName == sortedIndex[minus(count(sortedIndex), 1)].Name
}
}

get_original_from_command(commands) = from_command {
commands[i].Cmd == "from"
from_command := {
"Value": substring(commands[i].Original, 0, 4),
"LineHint" : commands[i]._kics_line - 1
}
}

add_line_hint(raw_search_key, lineHint) = searchKey {
searchKey := sprintf("%s^%d", [raw_search_key, lineHint])
}
10 changes: 6 additions & 4 deletions assets/queries/dockerfile/add_instead_of_copy/query.rego
Original file line number Diff line number Diff line change
Expand Up @@ -3,14 +3,16 @@ package Cx
import data.generic.dockerfile as dockerLib

CxPolicy[result] {
resource := input.document[i].command[name][_]
resource.Cmd == "add"
stage := input.document[i].command[name]

not dockerLib.arrayContains(resource.Value, {".tar", ".tar."})
resource = stage[s]
stage[s].Cmd == "add"
not dockerLib.arrayContains(stage[s].Value, {".tar", ".tar."})

from_command := dockerLib.get_original_from_command(stage)
result := {
"documentId": input.document[i].id,
"searchKey": sprintf("FROM={{%s}}.{{%s}}", [name, resource.Original]),
"searchKey": dockerLib.add_line_hint(sprintf("%s={{%s}}.{{%s}}", [from_command.Value, name, resource.Original]), from_command.LineHint),
"issueType": "IncorrectValue",
"keyExpectedValue": sprintf("'COPY' %s", [resource.Value[0]]),
"keyActualValue": sprintf("'ADD' %s", [resource.Value[0]]),
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
from openjdk:10-jdk
volume /tmp
arg JAR_FILE
copy ${JAR_FILE} app.jar
entrypoint ["java","-Djava.security.egd=file:/dev/./urandom","-jar","/app.jar"]
add http://source.file/package.file.tar.gz /temp
run tar -xjf /temp/package.file.tar.gz \
&& make -C /tmp/package.file \
&& rm /tmp/ package.file.tar.gz
# trigger validation
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
from openjdk:10-jdk
volume /tmp
add http://source.file/package.file.tar.gz /temp
run tar -xjf /temp/package.file.tar.gz \
&& make -C /tmp/package.file \
&& rm /tmp/ package.file.tar.gz
arg JAR_FILE
add ${JAR_FILE} app.jar
entrypoint ["java","-Djava.security.egd=file:/dev/./urandom","-jar","/app.jar"]
Original file line number Diff line number Diff line change
@@ -1,7 +1,14 @@
[
{
"queryName": "Add Instead of Copy",
"severity": "MEDIUM",
"line": 8
}
]
{
"queryName": "Add Instead of Copy",
"severity": "MEDIUM",
"line": 8,
"fileName": "positive1.dockerfile"
},
{
"queryName": "Add Instead of Copy",
"severity": "MEDIUM",
"line": 8,
"fileName": "positive2.dockerfile"
}
]
Original file line number Diff line number Diff line change
Expand Up @@ -10,9 +10,11 @@ CxPolicy[result] {
runCommands := dockerLib.getCommands(command.Value[0])
containsApkAddWithoutNoCache(runCommands)

stage := input.document[i].command[name]
from_command := dockerLib.get_original_from_command(stage)
result := {
"documentId": input.document[i].id,
"searchKey": sprintf("FROM={{%s}}.{{%s}}", [name, command.Original]),
"searchKey": dockerLib.add_line_hint(sprintf("%s={{%s}}.{{%s}}", [from_command.Value, name, command.Original]), from_command.LineHint),
"issueType": "IncorrectValue",
"keyExpectedValue": "'RUN' should not contain 'apk add' command without '--no-cache' switch",
"keyActualValue": "'RUN' contains 'apk add' command without '--no-cache' switch",
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
from gliderlabs/alpine:3.3
run apk add --no-cache python
workdir /app
onbuild COPY . /app
onbuild RUN virtualenv /env && /env/bin/pip install -r /app/requirements.txt
expose 8080
cmd ["/env/bin/python", "main.py"]
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
from gliderlabs/alpine:3.3
run apk add --update-cache python
workdir /app
onbuild COPY . /app
onbuild RUN virtualenv /env && /env/bin/pip install -r /app/requirements.txt
expose 8080
cmd ["/env/bin/python", "main.py"]
Original file line number Diff line number Diff line change
Expand Up @@ -10,5 +10,11 @@
"severity": "INFO",
"line": 2,
"fileName": "positive2.dockerfile"
},
{
"queryName": "Apk Add Using Local Cache Path",
"severity": "INFO",
"line": 2,
"fileName": "positive3.dockerfile"
}
]
]
Original file line number Diff line number Diff line change
@@ -1,5 +1,7 @@
package Cx

import data.generic.dockerfile as dockerLib

CxPolicy[result] {
resource := input.document[i].command[name][_]
resource.Cmd == "run"
Expand All @@ -10,9 +12,12 @@ CxPolicy[result] {

not hasClean(resource.Value[0], aptGet[0])

stage := input.document[i].command[name]
from_command := dockerLib.get_original_from_command(stage)
run_command := substring(resource.Original, 0, 3)
result := {
"documentId": input.document[i].id,
"searchKey": sprintf("FROM={{%s}}.RUN={{%s}}", [name, commands]),
"searchKey": dockerLib.add_line_hint(sprintf("%s={{%s}}.%s={{%s}}", [from_command.Value, name, run_command, commands]), from_command.LineHint),
"issueType": "IncorrectValue", #"MissingAttribute" / "RedundantAttribute"
"keyExpectedValue": "After using apt-get install, the apt-get lists should be deleted",
"keyActualValue": "After using apt-get install, the apt-get lists were not deleted",
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
from busyboxneg1
run apt-get update && apt-get install --no-install-recommends -y python \
&& apt-get clean \
&& rm -rf /var/lib/apt/lists/*

from busyboxneg2
run apt-get update && apt-get install --no-install-recommends -y python && apt-get clean

from busyboxneg3
run apt-get update && apt-get install --no-install-recommends -y python \
&& apt-get clean

from busyboxneg4
run apt-get update && apt-get install --no-install-recommends -y python \
&& rm -rf /var/lib/apt/lists/*
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
from busybox1
run apt-get update && apt-get install --no-install-recommends -y python

from busybox2
run apt-get install python

from busybox3
run apt-get update && apt-get install --no-install-recommends -y python
run rm -rf /var/lib/apt/lists/*

from busybox4
run apt-get update && apt-get install --no-install-recommends -y python
run rm -rf /var/lib/apt/lists/*
run apt-get clean
Original file line number Diff line number Diff line change
@@ -1,32 +1,56 @@
[
{
"queryName": "Apt Get Install Lists Were Not Deleted",
"severity": "INFO",
"line": 2,
"fileName": "positive.dockerfile"
},
{
"queryName": "Apt Get Install Lists Were Not Deleted",
"severity": "INFO",
"line": 5,
"fileName": "positive.dockerfile"
},
{
"queryName": "Apt Get Install Lists Were Not Deleted",
"severity": "INFO",
"line": 8,
"fileName": "positive.dockerfile"
},
{
"queryName": "Apt Get Install Lists Were Not Deleted",
"severity": "INFO",
"line": 12,
"fileName": "positive.dockerfile"
},
{
"queryName": "Apt Get Install Lists Were Not Deleted",
"severity": "INFO",
"line": 2,
"fileName": "positive2.dockerfile"
}
]
{
"queryName": "Apt Get Install Lists Were Not Deleted",
"severity": "INFO",
"line": 2,
"fileName": "positive.dockerfile"
},
{
"queryName": "Apt Get Install Lists Were Not Deleted",
"severity": "INFO",
"line": 5,
"fileName": "positive.dockerfile"
},
{
"queryName": "Apt Get Install Lists Were Not Deleted",
"severity": "INFO",
"line": 8,
"fileName": "positive.dockerfile"
},
{
"queryName": "Apt Get Install Lists Were Not Deleted",
"severity": "INFO",
"line": 12,
"fileName": "positive.dockerfile"
},
{
"queryName": "Apt Get Install Lists Were Not Deleted",
"severity": "INFO",
"line": 2,
"fileName": "positive2.dockerfile"
},
{
"queryName": "Apt Get Install Lists Were Not Deleted",
"severity": "INFO",
"line": 2,
"fileName": "positive3.dockerfile"
},
{
"queryName": "Apt Get Install Lists Were Not Deleted",
"severity": "INFO",
"line": 5,
"fileName": "positive3.dockerfile"
},
{
"queryName": "Apt Get Install Lists Were Not Deleted",
"severity": "INFO",
"line": 8,
"fileName": "positive3.dockerfile"
},
{
"queryName": "Apt Get Install Lists Were Not Deleted",
"severity": "INFO",
"line": 12,
"fileName": "positive3.dockerfile"
}
]
Original file line number Diff line number Diff line change
Expand Up @@ -18,9 +18,12 @@ CxPolicy[result] {
packageName := packages[j]
analyzePackages(j, packageName, packages, length)

stage := input.document[i].command[name]
from_command := dockerLib.get_original_from_command(stage)
run_command := substring(resource.Original, 0, 3)
result := {
"documentId": input.document[i].id,
"searchKey": sprintf("FROM={{%s}}.RUN={{%s}}", [name, commands]),
"searchKey": dockerLib.add_line_hint(sprintf("%s={{%s}}.%s={{%s}}", [from_command.Value, name, run_command, commands]), from_command.LineHint),
"searchValue": packageName,
"issueType": "MissingAttribute",
"keyExpectedValue": sprintf("Package '%s' has version defined", [packageName]),
Expand All @@ -44,9 +47,11 @@ CxPolicy[result] {
regex.match("^[a-zA-Z]", packageName) == true
not dockerLib.withVersion(packageName)

stage := input.document[i].command[name]
from_command := dockerLib.get_original_from_command(stage)
result := {
"documentId": input.document[i].id,
"searchKey": sprintf("FROM={{%s}}.{{%s}}", [name, resource.Original]),
"searchKey": dockerLib.add_line_hint(sprintf("%s={{%s}}.{{%s}}", [from_command.Value, name, resource.Original]), from_command.LineHint),
"searchValue": packageName,
"issueType": "IncorrectValue",
"keyExpectedValue": sprintf("Package '%s' has version defined", [packageName]),
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
from busybox
run apt-get install python=2.7
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
from busybox
run apt-get install python
run ["apt-get", "install", "python"]

from busybox2
run apt-get install -y -t python

from busybox3
run apt-get update && apt-get install -y \
python-qt4 \
python-pyside \
python-pip \
python3-pip \
python3-pyqt5
Original file line number Diff line number Diff line change
Expand Up @@ -94,5 +94,53 @@
"severity": "MEDIUM",
"line": 9,
"fileName": "positive2.dockerfile"
},
{
"queryName": "Apt Get Install Pin Version Not Defined",
"severity": "MEDIUM",
"line": 2,
"fileName": "positive3.dockerfile"
},
{
"queryName": "Apt Get Install Pin Version Not Defined",
"severity": "MEDIUM",
"line": 3,
"fileName": "positive3.dockerfile"
},
{
"queryName": "Apt Get Install Pin Version Not Defined",
"severity": "MEDIUM",
"line": 6,
"fileName": "positive3.dockerfile"
},
{
"queryName": "Apt Get Install Pin Version Not Defined",
"severity": "MEDIUM",
"line": 9,
"fileName": "positive3.dockerfile"
},
{
"queryName": "Apt Get Install Pin Version Not Defined",
"severity": "MEDIUM",
"line": 9,
"fileName": "positive3.dockerfile"
},
{
"queryName": "Apt Get Install Pin Version Not Defined",
"severity": "MEDIUM",
"line": 9,
"fileName": "positive3.dockerfile"
},
{
"queryName": "Apt Get Install Pin Version Not Defined",
"severity": "MEDIUM",
"line": 9,
"fileName": "positive3.dockerfile"
},
{
"queryName": "Apt Get Install Pin Version Not Defined",
"severity": "MEDIUM",
"line": 9,
"fileName": "positive3.dockerfile"
}
]
Loading
Loading