Skip to content

15 auto publish docker image on dockerhub - #16

Merged
MathiasVDA merged 4 commits into
mainfrom
15-auto-publish-docker-image-on-dockerhub
Dec 7, 2025
Merged

MathiasVDA merged 4 commits into
mainfrom
15-auto-publish-docker-image-on-dockerhub

Conversation

@MathiasVDA

Copy link
Copy Markdown
Collaborator

No description provided.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adds automated Docker image publishing to DockerHub with a complete web-based YASGUI (SPARQL GUI) deployment setup.

  • Implements a GitHub Actions workflow to build and publish Docker images on pushes to main and releases
  • Creates a multi-stage Dockerfile to build and serve the YASGUI application using Nginx
  • Adds static web assets (HTML, CSS, JS, images) for the YASGUI interface with custom branding

Reviewed changes

Copilot reviewed 9 out of 11 changed files in this pull request and generated 7 comments.

Show a summary per file
File Description
.github/workflows/push-docker.yml GitHub Actions workflow for building and pushing Docker images to DockerHub on main branch pushes and releases
docker/Dockerfile Multi-stage Dockerfile that builds the Node.js app and serves it with nginx-unprivileged
docker/change-default-endpoint.sh Shell script to configure YASGUI default SPARQL endpoint via environment variable
docker/src/index.html Main HTML file for the YASGUI web interface with footer and branding
docker/src/main.js JavaScript for footer toggle functionality and YASGUI initialization with endpoint configuration
docker/src/main.css Stylesheet for the YASGUI interface including responsive footer design
docker/src/manifest.json Web app manifest for PWA-like installation support
docker/src/robots.txt Robots.txt file allowing all crawlers
docker/src/logo.svg Matdata logo in SVG format
docker/src/favicon.png Favicon image for the application
.dockerignore Updated to exclude .vscode and .github directories from Docker context

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread docker/src/main.js
Comment thread docker/src/index.html
<link rel="stylesheet" href="yasgui.min.css">

<!-- Font Awesome for icons -->
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css">

Copilot AI Dec 7, 2025

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Loading Font Awesome from a CDN without Subresource Integrity (SRI) creates a security risk. If the CDN is compromised, malicious code could be injected. Consider adding the integrity and crossorigin attributes to ensure the resource hasn't been tampered with.

Suggested change
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css">
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css" integrity="sha512-papm6H1Yzsa3sGJNZaG0/gt0XiY8h1NIsDPKySx1VHa4EraseFH8blYNx+a3Pl6xNcNehJIK/gB1LsY5cqK8Ug==" crossorigin="anonymous">

Copilot uses AI. Check for mistakes.
Comment thread docker/Dockerfile
Comment on lines +11 to +14
exec "$@"

# Execute the original Docker entrypoint script
exec /docker-entrypoint.sh No newline at end of file

Copilot AI Dec 7, 2025

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The script has two exec statements that will cause an issue. Line 11 exec "$@" will replace the current process with the command passed as arguments, so line 14 exec /docker-entrypoint.sh will never be executed. You should either:

  1. Remove line 11 if you want to always execute the nginx entrypoint, or
  2. Remove line 14 if you want to execute the command passed to this script

Based on the context (this is used as a Docker entrypoint), line 14 should likely be exec /docker-entrypoint.sh "$@" and line 11 should be removed.

Suggested change
exec "$@"
# Execute the original Docker entrypoint script
exec /docker-entrypoint.sh
# Execute the original Docker entrypoint script
exec /docker-entrypoint.sh "$@"

Copilot uses AI. Check for mistakes.
Comment thread .github/workflows/push-docker.yml Outdated
Comment thread docker/src/main.js
Comment thread docker/change-default-endpoint.sh Outdated

# Replace the default endpoint in the bundle.js file
echo "Switching YASGUI default endpoint to: $YASGUI_DEFAULT_ENDPOINT"
sed -i "s|https://change.to.default.endpoint/sparql|$YASGUI_DEFAULT_ENDPOINT|g" /usr/share/nginx/html/*.js

Copilot AI Dec 7, 2025

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The sed command builds its substitution script using the untrusted environment variable YASGUI_DEFAULT_ENDPOINT directly inside double quotes (sed -i "s|https://change.to.default.endpoint/sparql|$YASGUI_DEFAULT_ENDPOINT|g" ...), which allows command injection if the variable contains a double quote (e.g., an attacker-controlled endpoint like "; rm -rf / #). An attacker who can influence YASGUI_DEFAULT_ENDPOINT could break out of the quoted string and execute arbitrary shell commands in the container context. To fix this, avoid interpolating the raw variable into the sed script (e.g., use single quotes around the sed expression and safely escape the replacement, or use a small script/utility to edit the file without invoking sh-interpreted metacharacters).

Suggested change
sed -i "s|https://change.to.default.endpoint/sparql|$YASGUI_DEFAULT_ENDPOINT|g" /usr/share/nginx/html/*.js
sed -i "s|https://change.to.default.endpoint/sparql|$(printf '%s' "$YASGUI_DEFAULT_ENDPOINT" | sed 's/[&/\]/\\&/g')|g" /usr/share/nginx/html/*.js

Copilot uses AI. Check for mistakes.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good suggestion!

@MathiasVDA
MathiasVDA merged commit 10603fb into main Dec 7, 2025
2 checks passed
@MathiasVDA
MathiasVDA deleted the 15-auto-publish-docker-image-on-dockerhub branch December 7, 2025 20:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Auto publish docker image on Dockerhub

3 participants