fix(quick-261009-p0m): Review-Befunde WR-01/02/04/05, IN-01/02/03/04 (Abbild-Bau, Semgrep im Container, Zeitbudget, ZAP-Haken)
- WR-01: prisma generate als eigener Schritt mit Pruefung im api-Abbild, Bau scheitert ohne Client; Startprobe als .gitea/scripts/image-start-check.sh versioniert - WR-02: Semgrep im offiziellen Container, per Digest angepinnt (kein pipx/PyPI mehr) - WR-04: Zeitbudget 1500 s, Limits je Werkzeug, Ergebniszeile sofort nach jedem Werkzeug - WR-05: Authorization-Ersetzung der ZAP-Pruefung nur fuer das Ziel - IN-01: yarn/npm per Platzhalter entfernt und Abwesenheit geprueft (api und web) - IN-02: Kommentar zu doppelten Kopfzeilen in next.config.ts richtiggestellt - IN-03: Berichtsordner Modus 700, Zugangsdaten nur als base64 (keine curl-Konfiguration) - IN-04: flacher Klon wird bei gitleaks als unvollstaendig gemeldet Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
+15
-2
@@ -37,6 +37,11 @@ COPY apps/api/package.json ./apps/api/
|
||||
COPY packages/shared/package.json ./packages/shared/
|
||||
COPY apps/api/prisma ./apps/api/prisma/
|
||||
RUN pnpm install --frozen-lockfile --prod --filter=@tessera/api...
|
||||
# Der Prisma-Client entsteht im postinstall von apps/api, der Fehler verschluckt
|
||||
# (`prisma generate || true`). Deshalb hier noch einmal ausdruecklich erzeugen und pruefen:
|
||||
# fehlt der Client, scheitert der Bau -- statt eines Abbilds, das erst beim Start stirbt.
|
||||
RUN apps/api/node_modules/.bin/prisma generate --schema apps/api/prisma/schema.prisma \
|
||||
&& find node_modules/.pnpm -path '*/.prisma/client/index.js' | grep -q .
|
||||
|
||||
# quick-261009-p0m: Laufzeitstufe direkt vom Node-Abbild (ohne das vorbereitete pnpm
|
||||
# der Stufe base). Die Paketverwaltungen des Node-Abbilds (npm, npx, corepack, yarn)
|
||||
@@ -49,8 +54,16 @@ ARG APP_CHANNEL
|
||||
ARG APP_COMMIT
|
||||
ARG APP_BUILD_TIME
|
||||
ENV APP_VERSION=$APP_VERSION APP_CHANNEL=$APP_CHANNEL APP_COMMIT=$APP_COMMIT APP_BUILD_TIME=$APP_BUILD_TIME
|
||||
RUN rm -rf /usr/local/lib/node_modules/npm /usr/local/lib/node_modules/corepack /opt/yarn-v1.22.22 \
|
||||
/usr/local/bin/npm /usr/local/bin/npx /usr/local/bin/corepack /usr/local/bin/yarn /usr/local/bin/yarnpkg
|
||||
# Die Ordner-/Dateinamen werden mit Platzhaltern gesucht (yarn-v1.22.22 wechselt mit dem
|
||||
# Node-Abbild); die letzte Zeile laesst den Bau scheitern, falls eines der Werkzeuge
|
||||
# bleibt -- sonst verpufft die Absicherung still bei einem neuen Basisabbild.
|
||||
RUN rm -rf /usr/local/lib/node_modules/npm /usr/local/lib/node_modules/corepack /opt/yarn* \
|
||||
/usr/local/bin/npm /usr/local/bin/npx /usr/local/bin/corepack /usr/local/bin/yarn* \
|
||||
&& for c in npm npx corepack yarn yarnpkg; do \
|
||||
if command -v "$c" >/dev/null 2>&1; then echo "FEHLER: $c ist noch im Abbild" >&2; exit 1; fi; \
|
||||
done \
|
||||
&& [ -z "$(ls -d /opt/yarn* /usr/local/lib/node_modules/npm /usr/local/lib/node_modules/corepack 2>/dev/null)" ] \
|
||||
&& node --version
|
||||
RUN addgroup --system --gid 1001 nestjs && \
|
||||
adduser --system --uid 1001 nestjs && \
|
||||
mkdir -p /app/user-files && \
|
||||
|
||||
Reference in New Issue
Block a user