Skip to content

MLE-32900: Exclude UBI packages from Docker NOTICE scan - #488

Open
vitalykorolev wants to merge 1 commit into
developfrom
MLE-32900_exclude-ubi-notice-packages
Open

vitalykorolev wants to merge 1 commit into
developfrom
MLE-32900_exclude-ubi-notice-packages

Conversation

@vitalykorolev

Copy link
Copy Markdown
Collaborator

Description

Black Duck NOTICE scan of Docker images must exclude the UBI base and all
packages installed from UBI repositories, but not libnsl (Rocky rpm).

  • Split dockerFiles/marklogic-deps-* into a platform stage (UBI base, all
    microdnf installs, FIPS policy) and a deps stage (adds the Rocky libnsl rpm).
  • sudo moves into the platform stage for non-rootless types via
    PLATFORM_EXTRA_PACKAGES (empty for rootless images). The server Dockerfiles
    no longer install sudo or libcap.
  • Makefile builds marklogic-platform- before the deps image.
  • Jenkinsfile saves, loads and publishes marklogic-platform-:latest-
    (internal registry only) and passes it as BASE_IMAGE_TO_EXCLUDE to the Black Duck job.

Requires the companion securityscans PR (MLE-32900).

Checklist:

  • Owner:
  • JIRA_ID as part of branch/PR name

  • Rebase the branch with upstream

  • Squashed all commits into a single commit

  • Added Tests

  • Reviewer:
  • Reviewed Tests

  • Added to Release Wiki/Jira

Split deps Dockerfiles into a platform stage containing the UBI base and all UBI-repo packages, and a deps stage containing Rocky libnsl. Publish the platform image and pass it as BASE_IMAGE_TO_EXCLUDE so the Black Duck NOTICE scan excludes UBI-repo packages, but not libnsl or MarkLogic. Keep sudo absent from rootless images.
Copilot AI balanced review requested due to automatic review settings October 7, 2026 00:17

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Server templates still perform UBI package transactions outside the platform boundary, and the new exclusion behavior lacks automated coverage.

Review effort: Balanced
Findings: 4 Medium severity

Open (4)
What changed in this PR

Splits UBI-provided dependencies into a dedicated platform image for Black Duck NOTICE exclusions.

Changes:

  • Adds platform/dependency Docker stages and relocates UBI packages.
  • Builds, archives, publishes, and scans against platform images.
  • Documents the new package-boundary convention.
File Description
Makefile Builds platform and dependency images.
Jenkinsfile Publishes and supplies platform images to Black Duck.
dockerFiles/​marklogic-server-ubi9-arm:base Inherits sudo from the platform.
dockerFiles/​marklogic-server-ubi:base Inherits sudo from the platform.
dockerFiles/​marklogic-server-ubi-rootless:base Inherits libcap from the platform.
dockerFiles/​marklogic-deps-ubi9:base Adds UBI9 platform/deps stages.
dockerFiles/​marklogic-deps-ubi9-arm:base Adds ARM platform/deps stages.
dockerFiles/​marklogic-deps-ubi:base Adds UBI8 platform/deps stages.
.github/​copilot-instructions.md Documents package-placement requirements.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread Makefile
Comment thread dockerFiles/marklogic-server-ubi-rootless:base
Comment thread dockerFiles/marklogic-server-ubi9-arm:base
Comment thread dockerFiles/marklogic-server-ubi:base

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Mutable asynchronous scan references can pair server and platform images from different concurrent builds.

Review effort: Balanced
Findings: 1 High severity

Open (1)
Resolved since last review (4)

Comment thread Jenkinsfile
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants