airvzxf / airvzxf/ftp-deployment-action

build(dockerfile): missing OCI labels (org.opencontainers.image.source, .licenses, .version)

Ouverte Adaptée aux débutants
#207 1 commentaire 0 réactions 0 personnes assignées Voir sur GitHub
audit build pending-design pending-human priority:low
Langage dominant
Shell
Étoiles
37
Forks
9
Merge moyen
44 min
PR mergées (30 j)
47

Description

gh issue create --title "build(dockerfile): missing OCI labels (org.opencontainers.image.source, .licenses, .version)" --label "build,audit,priority:low" --body "## Finding

Dockerfile does not set OCI image labels (org.opencontainers.image.source, org.opencontainers.image.licenses, org.opencontainers.image.version, org.opencontainers.image.revision). Container registries use these to render metadata, and `docker inspect` users see them as a contract.

## Affected code

- Dockerfile — LABEL instructions (missing)

## Reproduction

1. `docker inspect | jq '.[0].Config.Labels'`.
2. Observe no OCI labels.

## Suggested fix

Add LABEL statements:

LABEL org.opencontainers.image.source=\"https://github.com/airvzxf/ftp-deployment-action\" \\
org.opencontainers.image.licenses=\"AGPL-3.0\" \\
org.opencontainers.image.version=\"\${VERSION}\"

Pass VERSION via --build-arg. Or use the GitHub Actions `docker/metadata-action` to set them at build time.

## Source

F2 audit 2026-09-03 (Dockerfile/Makefile audit). Reporter: subagent-pekodbj7.

## Related

- Part of EPIC #[epic-number]
- Closes: #NONE (no existing issue)"

Guide de contribution

Aucun guide de contribution indexé pour ce dépôt

Piste de recherche

Start in Dockerfile and review the existing image build instructions plus any repository build invocation that supplies VERSION. Build the image, then run the reported docker inspect command to check its labels. Done means the requested OCI source, license, version, and revision metadata are visible in the image configuration.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
docker, dockerfile, github-actions
Domaine
build-system, devops
Type d'issue
Fonctionnalité
Difficulté
2/5
Temps estimé
1-3 heures
Activité
Active
Clarté
Plutôt claire
Accessibilité débutants
78/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.