Block a user
security-scanner (2026.08.20-6433aee)
Published 2026-08-20 20:26:27 +00:00 by larsi
Installation
docker pull gitea.ihler.tech/larsi/security-scanner:2026.08.20-6433aeesha256:5c5a48e3d5fe703070d9a2e8b5b3b5fea54f0c21e22b284d9677853a6c59d548
Image Layers
| # debian.sh --arch 'amd64' out/ 'trixie' '@1785715200' |
| ENV PATH=/usr/local/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin |
| ENV LANG=C.UTF-8 |
| RUN /bin/sh -c set -eux; apt-get update; apt-get install -y --no-install-recommends ca-certificates netbase tzdata ; apt-get dist-clean # buildkit |
| ENV GPG_KEY=A035C8C19219BA821ECEA86B64E628F8D684696D |
| ENV PYTHON_VERSION=3.11.16 |
| ENV PYTHON_SHA256=91bcdebfdde239a003ae93738a7fce0f9230fee5c4bc2b86f6e6e8c6f98aabe8 |
| RUN /bin/sh -c set -eux; savedAptMark="$(apt-mark showmanual)"; apt-get update; apt-get install -y --no-install-recommends dpkg-dev gcc gnupg libbluetooth-dev libbz2-dev libc6-dev libdb-dev libffi-dev libgdbm-dev liblzma-dev libncursesw5-dev libreadline-dev libsqlite3-dev libssl-dev make tk-dev uuid-dev wget xz-utils zlib1g-dev ; wget -O python.tar.xz "https://www.python.org/ftp/python/${PYTHON_VERSION%%[a-z]*}/Python-$PYTHON_VERSION.tar.xz"; echo "$PYTHON_SHA256 *python.tar.xz" | sha256sum -c -; wget -O python.tar.xz.asc "https://www.python.org/ftp/python/${PYTHON_VERSION%%[a-z]*}/Python-$PYTHON_VERSION.tar.xz.asc"; GNUPGHOME="$(mktemp -d)"; export GNUPGHOME; gpg --batch --keyserver hkps://keys.openpgp.org --recv-keys "$GPG_KEY"; gpg --batch --verify python.tar.xz.asc python.tar.xz; gpgconf --kill all; rm -rf "$GNUPGHOME" python.tar.xz.asc; mkdir -p /usr/src/python; tar --extract --directory /usr/src/python --strip-components=1 --file python.tar.xz; rm python.tar.xz; cd /usr/src/python; gnuArch="$(dpkg-architecture --query DEB_BUILD_GNU_TYPE)"; ./configure --build="$gnuArch" --enable-loadable-sqlite-extensions --enable-optimizations --enable-option-checking=fatal --enable-shared $(test "${gnuArch%%-*}" != 'riscv64' && echo '--with-lto') --with-ensurepip ; nproc="$(nproc)"; EXTRA_CFLAGS="$(dpkg-buildflags --get CFLAGS)"; LDFLAGS="$(dpkg-buildflags --get LDFLAGS)"; LDFLAGS="${LDFLAGS:-} -Wl,--strip-all"; make -j "$nproc" "EXTRA_CFLAGS=${EXTRA_CFLAGS:-}" "LDFLAGS=${LDFLAGS:-}" ; rm python; make -j "$nproc" "EXTRA_CFLAGS=${EXTRA_CFLAGS:-}" "LDFLAGS=${LDFLAGS:-} -Wl,-rpath='\$\$ORIGIN/../lib'" python ; make install; cd /; rm -rf /usr/src/python; find /usr/local -depth \( \( -type d -a \( -name test -o -name tests -o -name idle_test \) \) -o \( -type f -a \( -name '*.pyc' -o -name '*.pyo' -o -name 'libpython*.a' \) \) \) -exec rm -rf '{}' + ; ldconfig; apt-mark auto '.*' > /dev/null; apt-mark manual $savedAptMark; find /usr/local -type f -executable -not \( -name '*tkinter*' \) -exec ldd '{}' ';' | awk '/=>/ { so = $(NF-1); if (index(so, "/usr/local/") == 1) { next }; gsub("^/(usr/)?", "", so); printf "*%s\n", so }' | sort -u | xargs -rt dpkg-query --search | awk 'sub(":$", "", $1) { print $1 }' | sort -u | xargs -r apt-mark manual ; apt-get purge -y --auto-remove -o APT::AutoRemove::RecommendsImportant=false; apt-get dist-clean; export PYTHONDONTWRITEBYTECODE=1; python3 --version; pip3 install --disable-pip-version-check --no-cache-dir --no-compile 'setuptools==79.0.1' 'wheel==0.46.3' ; pip3 --version # buildkit |
| RUN /bin/sh -c set -eux; for src in idle3 pip3 pydoc3 python3 python3-config; do dst="$(echo "$src" | tr -d 3)"; [ -s "/usr/local/bin/$src" ]; [ ! -e "/usr/local/bin/$dst" ]; ln -svT "$src" "/usr/local/bin/$dst"; done # buildkit |
| CMD ["python3"] |
| SHELL [/bin/bash -o pipefail -c] |
| RUN /bin/bash -o pipefail -c apt-get update && apt-get upgrade -y && apt-get install -y --no-install-recommends curl git openssh-client make jq rsync && curl -fsSL https://deb.nodesource.com/setup_20.x | bash - && apt-get install -y --no-install-recommends nodejs && rm -rf /var/lib/apt/lists/* # buildkit |
| RUN /bin/bash -o pipefail -c curl -fsSL "https://dl.k8s.io/release/$(curl -fsSL https://dl.k8s.io/release/stable.txt)/bin/linux/amd64/kubectl" -o /usr/local/bin/kubectl && chmod +x /usr/local/bin/kubectl # buildkit |
| COPY /usr/bin/helm /usr/local/bin/helm # buildkit |
| RUN /bin/bash -o pipefail -c helm version # buildkit |
| RUN /bin/bash -o pipefail -c pip install --no-cache-dir 'wheel>=0.46.2' 'jaraco.context>=6.1.0' ansible-core ansible-lint yamllint requests # buildkit |
| RUN /bin/bash -o pipefail -c npm install -g @anthropic-ai/claude-code # buildkit |
| RUN /bin/bash -o pipefail -c useradd -m -s /bin/bash agent # buildkit |
| USER agent |
| USER root |
| ARG TRIVY_VERSION=0.71.2 |
| ARG GITLEAKS_VERSION=8.18.4 |
| ARG HADOLINT_VERSION=2.12.0 |
| RUN |3 TRIVY_VERSION=0.71.2 GITLEAKS_VERSION=8.18.4 HADOLINT_VERSION=2.12.0 /bin/bash -o pipefail -c set -eux; curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh | sh -s -- -b /usr/local/bin "v${TRIVY_VERSION}"; curl -sfL "https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz" | tar -xz -C /usr/local/bin gitleaks; curl -sfL -o /usr/local/bin/hadolint "https://github.com/hadolint/hadolint/releases/download/v${HADOLINT_VERSION}/hadolint-Linux-x86_64"; chmod +x /usr/local/bin/hadolint # buildkit |
| RUN |3 TRIVY_VERSION=0.71.2 GITLEAKS_VERSION=8.18.4 HADOLINT_VERSION=2.12.0 /bin/bash -o pipefail -c pip install --no-cache-dir --break-system-packages checkov # buildkit |
| RUN |3 TRIVY_VERSION=0.71.2 GITLEAKS_VERSION=8.18.4 HADOLINT_VERSION=2.12.0 /bin/bash -o pipefail -c trivy --version && gitleaks version && hadolint --version && checkov --version # buildkit |
| USER agent |
Details
2026-08-20 20:26:27 +00:00
Versions (5)
View all
Container
0
OCI / Docker
linux/amd64
469 MiB
2026.08.29-1bfbc12
2026-08-29
latest
2026-08-29
2026.08.20-6433aee
2026-08-20
2026.08.07-fbf2062
2026-08-07
2026.08.07-f78f8d4
2026-08-07