2024-02-11 17:47:00 +01:00
|
|
|
# Main stage
|
[Snyk] Security upgrade alpine from 3.20.3 to 3.21.2 (#2669)
![snyk-top-banner](https://redirect.github.com/andygongea/OWASP-Benchmark/assets/818805/c518c423-16fe-447e-b67f-ad5a49b5d123)
### Snyk has created this PR to fix 1 vulnerabilities in the dockerfile
dependencies of this project.
Keeping your Docker base image up-to-date means you’ll benefit from
security fixes in the latest version of your chosen image.
#### Snyk changed the following file(s):
- `Dockerfile`
We recommend upgrading to `alpine:3.21.2`, as this image has only **0**
known vulnerabilities. To do this, merge this pull request, then verify
your application still works as expected.
#### Vulnerabilities that will be fixed with an upgrade:
| | Issue | Score |
:-------------------------:|:-------------------------|:-------------------------
![low
severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/l.png
'low severity') | CVE-2024-9143
<br/>[SNYK-ALPINE320-OPENSSL-8235201](https://snyk.io/vuln/SNYK-ALPINE320-OPENSSL-8235201)
| **54**
![low
severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/l.png
'low severity') | CVE-2024-9143
<br/>[SNYK-ALPINE320-OPENSSL-8235201](https://snyk.io/vuln/SNYK-ALPINE320-OPENSSL-8235201)
| **54**
---
> [!IMPORTANT]
>
> - Check the changes in this PR to ensure they won't cause issues with
your project.
> - Max score is 1000. Note that the real score may have changed since
the PR was raised.
> - This PR was automatically created by Snyk using the credentials of a
real user.
---
**Note:** _You are seeing this because you or someone else with access
to this repository has authorized Snyk to open fix PRs._
For more information: <img
src="https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6InJyWmxZcEdHY2RyTHZsb0lYd0dUcVg4WkFRTnNCOUEwIiwiYW5vbnltb3VzSWQiOiJhYmYwMzliMi05OTRlLTRkMmMtYWZjOS04YzIwNWYxOWUwNTQiLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6ImFiZjAzOWIyLTk5NGUtNGQyYy1hZmM5LThjMjA1ZjE5ZTA1NCJ9fQ=="
width="0" height="0"/>
🧐 [View latest project
report](https://app.snyk.io/org/frooodle/project/6c268b92-2569-4b08-8058-1f8f5d4acd0d?utm_source=github&utm_medium=referral&page=fix-pr)
📜 [Customise PR
templates](https://docs.snyk.io/scan-using-snyk/pull-requests/snyk-fix-pull-or-merge-requests/customize-pr-templates?utm_source=github&utm_content=fix-pr-template)
🛠 [Adjust project
settings](https://app.snyk.io/org/frooodle/project/6c268b92-2569-4b08-8058-1f8f5d4acd0d?utm_source=github&utm_medium=referral&page=fix-pr/settings)
📚 [Read about Snyk's upgrade
logic](https://docs.snyk.io/scan-with-snyk/snyk-open-source/manage-vulnerabilities/upgrade-package-versions-to-fix-vulnerabilities?utm_source=github&utm_content=fix-pr-template)
---
**Learn how to fix vulnerabilities with free interactive lessons:**
🦉 [Learn about vulnerability in an interactive lesson of Snyk
Learn.](https://learn.snyk.io/?loc=fix-pr)
[//]: #
'snyk:metadata:{"customTemplate":{"variablesUsed":[],"fieldsUsed":[]},"dependencies":[{"name":"alpine","from":"3.20.3","to":"3.21.2"}],"env":"prod","issuesToFix":["SNYK-ALPINE320-OPENSSL-8235201","SNYK-ALPINE320-OPENSSL-8235201"],"prId":"abf039b2-994e-4d2c-afc9-8c205f19e054","prPublicId":"abf039b2-994e-4d2c-afc9-8c205f19e054","packageManager":"dockerfile","priorityScoreList":[54],"projectPublicId":"6c268b92-2569-4b08-8058-1f8f5d4acd0d","projectUrl":"https://app.snyk.io/org/frooodle/project/6c268b92-2569-4b08-8058-1f8f5d4acd0d?utm_source=github&utm_medium=referral&page=fix-pr","prType":"fix","templateFieldSources":{"branchName":"default","commitMessage":"default","description":"default","title":"default"},"templateVariants":["updated-fix-title","priorityScore"],"type":"auto","upgrade":["SNYK-ALPINE320-OPENSSL-8235201","SNYK-ALPINE320-OPENSSL-8235201"],"vulns":["SNYK-ALPINE320-OPENSSL-8235201"],"patch":[],"isBreakingChange":false,"remediationStrategy":"vuln"}'
---------
Co-authored-by: snyk-bot <snyk-bot@snyk.io>
2025-01-12 16:53:10 +01:00
|
|
|
FROM alpine:3.21.2@sha256:56fa17d2a7e7f168a043a2712e63aed1f8543aeafdcee47c58dcffe38ed51099
|
2024-02-11 17:47:00 +01:00
|
|
|
|
2024-03-04 21:51:49 +01:00
|
|
|
# Copy necessary files
|
|
|
|
COPY scripts /scripts
|
|
|
|
COPY pipeline /pipeline
|
2024-04-29 00:33:55 +02:00
|
|
|
COPY src/main/resources/static/fonts/*.ttf /usr/share/fonts/opentype/noto/
|
2024-05-05 13:18:52 +02:00
|
|
|
#COPY src/main/resources/static/fonts/*.otf /usr/share/fonts/opentype/noto/
|
2024-03-04 21:51:49 +01:00
|
|
|
COPY build/libs/*.jar app.jar
|
|
|
|
|
|
|
|
ARG VERSION_TAG
|
|
|
|
|
2024-12-22 01:09:52 +01:00
|
|
|
LABEL org.opencontainers.image.title="Stirling-PDF"
|
2024-12-22 01:11:06 +01:00
|
|
|
LABEL org.opencontainers.image.description="A powerful locally hosted web-based PDF manipulation tool supporting 50+ operations including merging, splitting, conversion, OCR, watermarking, and more."
|
2024-12-22 01:09:52 +01:00
|
|
|
LABEL org.opencontainers.image.source="https://github.com/Stirling-Tools/Stirling-PDF"
|
|
|
|
LABEL org.opencontainers.image.licenses="MIT"
|
|
|
|
LABEL org.opencontainers.image.vendor="Stirling-Tools"
|
|
|
|
LABEL org.opencontainers.image.url="https://www.stirlingpdf.com"
|
|
|
|
LABEL org.opencontainers.image.documentation="https://docs.stirlingpdf.com"
|
|
|
|
LABEL maintainer="Stirling-Tools"
|
|
|
|
LABEL org.opencontainers.image.authors="Stirling-Tools"
|
|
|
|
LABEL org.opencontainers.image.version="${VERSION_TAG}"
|
|
|
|
LABEL org.opencontainers.image.keywords="PDF, manipulation, merge, split, convert, OCR, watermark"
|
|
|
|
|
2024-03-04 21:51:49 +01:00
|
|
|
# Set Environment Variables
|
|
|
|
ENV DOCKER_ENABLE_SECURITY=false \
|
|
|
|
VERSION_TAG=$VERSION_TAG \
|
|
|
|
JAVA_TOOL_OPTIONS="$JAVA_TOOL_OPTIONS -XX:MaxRAMPercentage=75" \
|
2024-05-22 23:58:01 +02:00
|
|
|
HOME=/home/stirlingpdfuser \
|
|
|
|
PUID=1000 \
|
2024-03-08 21:49:19 +01:00
|
|
|
PGID=1000 \
|
|
|
|
UMASK=022
|
2024-03-04 21:51:49 +01:00
|
|
|
|
2024-12-22 01:09:52 +01:00
|
|
|
|
2024-02-11 17:47:00 +01:00
|
|
|
# JDK for app
|
|
|
|
RUN echo "@testing https://dl-cdn.alpinelinux.org/alpine/edge/main" | tee -a /etc/apk/repositories && \
|
|
|
|
echo "@testing https://dl-cdn.alpinelinux.org/alpine/edge/community" | tee -a /etc/apk/repositories && \
|
|
|
|
echo "@testing https://dl-cdn.alpinelinux.org/alpine/edge/testing" | tee -a /etc/apk/repositories && \
|
2024-05-22 23:58:01 +02:00
|
|
|
apk upgrade --no-cache -a && \
|
2024-02-11 17:47:00 +01:00
|
|
|
apk add --no-cache \
|
|
|
|
ca-certificates \
|
|
|
|
tzdata \
|
|
|
|
tini \
|
|
|
|
bash \
|
|
|
|
curl \
|
2024-11-26 21:50:35 +01:00
|
|
|
qpdf \
|
2024-03-09 15:03:46 +01:00
|
|
|
shadow \
|
2024-05-23 00:02:55 +02:00
|
|
|
su-exec \
|
|
|
|
openssl \
|
|
|
|
openssl-dev \
|
|
|
|
openjdk21-jre \
|
2024-02-11 17:47:00 +01:00
|
|
|
# Doc conversion
|
2024-05-22 23:58:01 +02:00
|
|
|
libreoffice \
|
2024-03-29 22:02:33 +01:00
|
|
|
# pdftohtml
|
|
|
|
poppler-utils \
|
2024-08-20 17:17:54 +02:00
|
|
|
# OCR MY PDF (unpaper for descew and other advanced features)
|
2024-02-11 17:47:00 +01:00
|
|
|
tesseract-ocr-data-eng \
|
|
|
|
# CV
|
|
|
|
py3-opencv \
|
|
|
|
# python3/pip
|
2024-08-08 22:13:59 +02:00
|
|
|
python3 \
|
2024-08-20 17:17:54 +02:00
|
|
|
py3-pip && \
|
2024-02-11 17:47:00 +01:00
|
|
|
# uno unoconv and HTML
|
2024-08-20 17:17:54 +02:00
|
|
|
pip install --break-system-packages --no-cache-dir --upgrade unoconv WeasyPrint pdf2image pillow && \
|
2024-03-04 21:51:49 +01:00
|
|
|
mv /usr/share/tessdata /usr/share/tessdata-original && \
|
|
|
|
mkdir -p $HOME /configs /logs /customFiles /pipeline/watchedFolders /pipeline/finishedFolders && \
|
2024-02-11 17:47:00 +01:00
|
|
|
fc-cache -f -v && \
|
2024-03-04 21:51:49 +01:00
|
|
|
chmod +x /scripts/* && \
|
|
|
|
chmod +x /scripts/init.sh && \
|
|
|
|
# User permissions
|
|
|
|
addgroup -S stirlingpdfgroup && adduser -S stirlingpdfuser -G stirlingpdfgroup && \
|
2024-03-09 15:03:46 +01:00
|
|
|
chown -R stirlingpdfuser:stirlingpdfgroup $HOME /scripts /usr/share/fonts/opentype/noto /configs /customFiles /pipeline && \
|
2024-12-22 13:00:52 +01:00
|
|
|
chown stirlingpdfuser:stirlingpdfgroup /app.jar
|
2024-02-11 17:47:00 +01:00
|
|
|
|
2024-05-22 23:58:01 +02:00
|
|
|
EXPOSE 8080/tcp
|
2024-02-11 17:47:00 +01:00
|
|
|
|
|
|
|
# Set user and run command
|
|
|
|
ENTRYPOINT ["tini", "--", "/scripts/init.sh"]
|
|
|
|
CMD ["java", "-Dfile.encoding=UTF-8", "-jar", "/app.jar"]
|