Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .devcontainer/devcontainer.json
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@
"build": {
"dockerfile": "../dockerfile"
},
"postCreateCommand": "git config --global --add safe.directory /workspaces/uk-controller-plugin",
"postCreateCommand": "git config --global --add safe.directory /workspaces/uk-controller-plugin && yarn install",
"containerUser": "ubuntu",
"remoteUser": "ubuntu"
}
16 changes: 16 additions & 0 deletions dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,7 @@
ARG WINDOWS_CRT_VERSION=14.29.16.11
# Old known working = 10.0.20348
ARG WINDOWS_SDK_VERSION=10.0.26100
ARG NODE_VERSION=24

ADD "https://github.com/Jake-Shadle/xwin/releases/download/${XWIN_VERSION}/xwin-${XWIN_VERSION}-${XWIN_TRIPLE}.tar.gz" \
/tmp/xwin.tar.gz
Expand Down Expand Up @@ -134,6 +135,21 @@
ENV CURL_LIBRARYDIR=/opt/curl/build/lib/
ENV CURL_DEBUG_LIBRARYDIR=/opt/curl/build/lib/

# Node.js and Yarn (classic), used by semantic-release and to refresh yarn.lock.
RUN <<-EOF
set -eux

export DEBIAN_FRONTEND=noninteractive
apt update
apt install -y --no-install-recommends curl ca-certificates gnupg

Check warning on line 144 in dockerfile

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Sort these package names alphanumerically.

See more on https://sonarcloud.io/project/issues?id=VATSIM-UK_uk-controller-plugin&issues=AaDoO67qXR70GwIMKtOM&open=AaDoO67qXR70GwIMKtOM&pullRequest=644
curl -fsSL "https://deb.nodesource.com/setup_${NODE_VERSION}.x" | bash -

Check warning on line 145 in dockerfile

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Not enforcing HTTPS here might allow for redirections to insecure websites. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=VATSIM-UK_uk-controller-plugin&issues=AaDoO67qXR70GwIMKtOO&open=AaDoO67qXR70GwIMKtOO&pullRequest=644

Check failure on line 145 in dockerfile

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Avoid executing downloaded artifacts directly without verification.

See more on https://sonarcloud.io/project/issues?id=VATSIM-UK_uk-controller-plugin&issues=AaDoO67qXR70GwIMKtON&open=AaDoO67qXR70GwIMKtON&pullRequest=644
apt install -y nodejs

Check warning on line 146 in dockerfile

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Make sure automatically installing recommended packages is safe here.

See more on https://sonarcloud.io/project/issues?id=VATSIM-UK_uk-controller-plugin&issues=AaDoO67qXR70GwIMKtOP&open=AaDoO67qXR70GwIMKtOP&pullRequest=644
npm install -g yarn@1.22.22

Check warning on line 147 in dockerfile

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Omitting "--ignore-scripts" allows lifecycle scripts to run during package installation.

See more on https://sonarcloud.io/project/issues?id=VATSIM-UK_uk-controller-plugin&issues=AaDoO67qXR70GwIMKtOQ&open=AaDoO67qXR70GwIMKtOQ&pullRequest=644
apt autoremove -y
apt clean -y
rm -rf /var/lib/apt/lists/*
EOF

USER ubuntu

CMD ["/bin/bash"]
4 changes: 4 additions & 0 deletions docs/CONTAINER_BUILD.md
Original file line number Diff line number Diff line change
Expand Up @@ -67,3 +67,7 @@ that the line endings in the Dockerfile are LF, and are not converted to CRLF.

By default, Git is not installed within the container. Git operations should be
performed on the host machine, or Git installed in the container.

The container includes Node.js 24 and Yarn 1.22.22, used by the release tooling
(`semantic-release`) and to refresh `yarn.lock`. In the Dev Container, `yarn
install` runs automatically after the container is created.
Loading