Repository navigation
15 auto publish docker image on dockerhub - #16
Conversation
There was a problem hiding this comment.
Pull request overview
This PR adds automated Docker image publishing to DockerHub with a complete web-based YASGUI (SPARQL GUI) deployment setup.
- Implements a GitHub Actions workflow to build and publish Docker images on pushes to main and releases
- Creates a multi-stage Dockerfile to build and serve the YASGUI application using Nginx
- Adds static web assets (HTML, CSS, JS, images) for the YASGUI interface with custom branding
Reviewed changes
Copilot reviewed 9 out of 11 changed files in this pull request and generated 7 comments.
Show a summary per file
| File | Description |
|---|---|
.github/workflows/push-docker.yml |
GitHub Actions workflow for building and pushing Docker images to DockerHub on main branch pushes and releases |
docker/Dockerfile |
Multi-stage Dockerfile that builds the Node.js app and serves it with nginx-unprivileged |
docker/change-default-endpoint.sh |
Shell script to configure YASGUI default SPARQL endpoint via environment variable |
docker/src/index.html |
Main HTML file for the YASGUI web interface with footer and branding |
docker/src/main.js |
JavaScript for footer toggle functionality and YASGUI initialization with endpoint configuration |
docker/src/main.css |
Stylesheet for the YASGUI interface including responsive footer design |
docker/src/manifest.json |
Web app manifest for PWA-like installation support |
docker/src/robots.txt |
Robots.txt file allowing all crawlers |
docker/src/logo.svg |
Matdata logo in SVG format |
docker/src/favicon.png |
Favicon image for the application |
.dockerignore |
Updated to exclude .vscode and .github directories from Docker context |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| <link rel="stylesheet" href="yasgui.min.css"> | ||
|
|
||
| <!-- Font Awesome for icons --> | ||
| <link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css"> |
There was a problem hiding this comment.
Loading Font Awesome from a CDN without Subresource Integrity (SRI) creates a security risk. If the CDN is compromised, malicious code could be injected. Consider adding the integrity and crossorigin attributes to ensure the resource hasn't been tampered with.
| <link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css"> | |
| <link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css" integrity="sha512-papm6H1Yzsa3sGJNZaG0/gt0XiY8h1NIsDPKySx1VHa4EraseFH8blYNx+a3Pl6xNcNehJIK/gB1LsY5cqK8Ug==" crossorigin="anonymous"> |
| exec "$@" | ||
|
|
||
| # Execute the original Docker entrypoint script | ||
| exec /docker-entrypoint.sh No newline at end of file |
There was a problem hiding this comment.
The script has two exec statements that will cause an issue. Line 11 exec "$@" will replace the current process with the command passed as arguments, so line 14 exec /docker-entrypoint.sh will never be executed. You should either:
- Remove line 11 if you want to always execute the nginx entrypoint, or
- Remove line 14 if you want to execute the command passed to this script
Based on the context (this is used as a Docker entrypoint), line 14 should likely be exec /docker-entrypoint.sh "$@" and line 11 should be removed.
| exec "$@" | |
| # Execute the original Docker entrypoint script | |
| exec /docker-entrypoint.sh | |
| # Execute the original Docker entrypoint script | |
| exec /docker-entrypoint.sh "$@" |
|
|
||
| # Replace the default endpoint in the bundle.js file | ||
| echo "Switching YASGUI default endpoint to: $YASGUI_DEFAULT_ENDPOINT" | ||
| sed -i "s|https://change.to.default.endpoint/sparql|$YASGUI_DEFAULT_ENDPOINT|g" /usr/share/nginx/html/*.js |
There was a problem hiding this comment.
The sed command builds its substitution script using the untrusted environment variable YASGUI_DEFAULT_ENDPOINT directly inside double quotes (sed -i "s|https://change.to.default.endpoint/sparql|$YASGUI_DEFAULT_ENDPOINT|g" ...), which allows command injection if the variable contains a double quote (e.g., an attacker-controlled endpoint like "; rm -rf / #). An attacker who can influence YASGUI_DEFAULT_ENDPOINT could break out of the quoted string and execute arbitrary shell commands in the container context. To fix this, avoid interpolating the raw variable into the sed script (e.g., use single quotes around the sed expression and safely escape the replacement, or use a small script/utility to edit the file without invoking sh-interpreted metacharacters).
| sed -i "s|https://change.to.default.endpoint/sparql|$YASGUI_DEFAULT_ENDPOINT|g" /usr/share/nginx/html/*.js | |
| sed -i "s|https://change.to.default.endpoint/sparql|$(printf '%s' "$YASGUI_DEFAULT_ENDPOINT" | sed 's/[&/\]/\\&/g')|g" /usr/share/nginx/html/*.js |
There was a problem hiding this comment.
Good suggestion!
No description provided.