GovReady / govready-q

An open source, self-service GRC tool to automate security assessments and compliance.
https://q.govready.com
Other
174 stars 53 forks source link

Fix for Dockerfile smell DL3009 #1806

Open grosa1 opened 1 year ago

grosa1 commented 1 year ago

Hi! The Dockerfile placed at "dev_env/docker/images/backend/Dockerfile" contains the best practice violation DL3009 detected by the hadolint tool.

The smell DL3009 occurs when the apt tool is used to install packages without wiping the cache and source lists. This pull request proposes a fix for that smell generated by my fixing tool. The generated patch has been manually verified before opening the pull request. To fix this smell, specifically, the instructions to clean up the apt cache and remove the /var/lib/apt/lists have been added. This helps keep the image size down.

This change is only aimed at fixing that specific smell. If the fix is not valid or useful, please briefly indicate the reason and suggestions for possible improvements.

Thanks in advance