-
Notifications
You must be signed in to change notification settings - Fork 2
feat: INFRA-6296 Cronos testnet image upgrade v1.5.4 #90
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Signed-off-by: Dmitrii Spichakov <dmitrii.spichakov@chainstack.com>
WalkthroughThis PR bumps the Cronos binary version in the Dockerfile from v1.5.3 to v1.5.4. The change updates the download URL, tarball filename, and the corresponding extraction and cleanup commands. No control flow or logic modifications are present. Changes
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~2 minutes Possibly related PRs
Suggested reviewers
Poem
Pre-merge checks and finishing touches✅ Passed checks (3 passed)
✨ Finishing touches🧪 Generate unit tests (beta)
Tip 📝 Customizable high-level summaries are now available in beta!You can now customize how CodeRabbit generates the high-level summary in your pull requests — including its content, structure, tone, and formatting.
Example instruction:
Note: This feature is currently in beta for Pro-tier users, and pricing will be announced later. Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Actionable comments posted: 1
📜 Review details
Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro
📒 Files selected for processing (1)
Dockerfile(1 hunks)
🧰 Additional context used
🪛 Checkov (3.2.334)
Dockerfile
[high] 11-12: Ensure that certificate validation isn't disabled with wget
(CKV2_DOCKER_3)
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (1)
- GitHub Check: guardrails/scan
| RUN cd /tmp && wget --no-check-certificate https://github.com/crypto-org-chain/cronos/releases/download/v1.5.4/cronos_1.5.4-testnet_Linux_x86_64.tar.gz && tar -xvf cronos_1.5.4-testnet_Linux_x86_64.tar.gz \ | ||
| && rm cronos_1.5.4-testnet_Linux_x86_64.tar.gz && mv ./* /home/cronos/ |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Remove --no-check-certificate to validate SSL certificates.
The --no-check-certificate flag disables SSL/TLS certificate validation on the download from GitHub. This is a security posture gap that should be removed, as GitHub's certificates are valid and need not be bypassed.
Apply this diff to enable certificate validation:
-RUN cd /tmp && wget --no-check-certificate https://github.com/crypto-org-chain/cronos/releases/download/v1.5.4/cronos_1.5.4-testnet_Linux_x86_64.tar.gz && tar -xvf cronos_1.5.4-testnet_Linux_x86_64.tar.gz \
+RUN cd /tmp && wget https://github.com/crypto-org-chain/cronos/releases/download/v1.5.4/cronos_1.5.4-testnet_Linux_x86_64.tar.gz && tar -xvf cronos_1.5.4-testnet_Linux_x86_64.tar.gz \
&& rm cronos_1.5.4-testnet_Linux_x86_64.tar.gz && mv ./* /home/cronos/The version upgrade itself (v1.5.3 → v1.5.4) is correctly applied to the tarball filename and download URL.
📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.
| RUN cd /tmp && wget --no-check-certificate https://github.com/crypto-org-chain/cronos/releases/download/v1.5.4/cronos_1.5.4-testnet_Linux_x86_64.tar.gz && tar -xvf cronos_1.5.4-testnet_Linux_x86_64.tar.gz \ | |
| && rm cronos_1.5.4-testnet_Linux_x86_64.tar.gz && mv ./* /home/cronos/ | |
| RUN cd /tmp && wget https://github.com/crypto-org-chain/cronos/releases/download/v1.5.4/cronos_1.5.4-testnet_Linux_x86_64.tar.gz && tar -xvf cronos_1.5.4-testnet_Linux_x86_64.tar.gz \ | |
| && rm cronos_1.5.4-testnet_Linux_x86_64.tar.gz && mv ./* /home/cronos/ |
🧰 Tools
🪛 Checkov (3.2.334)
[high] 11-12: Ensure that certificate validation isn't disabled with wget
(CKV2_DOCKER_3)
🤖 Prompt for AI Agents
In Dockerfile around lines 11-12, the wget invocation disables SSL validation
via --no-check-certificate; remove that flag so wget performs normal TLS
certificate verification when downloading the GitHub tarball. Update the RUN
line to call wget without --no-check-certificate (keep the same URL, tar and
cleanup steps) so the download validates GitHub's certificate by default.
Cronos testnet image upgrade v1.5.4
INFRA-6296 Cronos v1.5.4 Upgrades across clusters
Summary by CodeRabbit
✏️ Tip: You can customize this high-level summary in your review settings.