|
|
||
|---|---|---|
| installations | ||
| .gitignore | ||
| README.md | ||
| install-semgrep-skill.bat | ||
| install-semgrep-skill.sh | ||
| setup-opencode-config.bat | ||
| setup-opencode-config.sh | ||
README.md
CodeGuard
opencode(vscode插件安装)
opencode CLI安装
1. Linux x64
- 下载opencode-linux-x64.tar.gz安装包
- 在下载文件夹,执行命令
tar -zxvf opencode-linux-x64.tar.gz chmod +x opencodesudo mv opencode /usr/local/bin/- 验证是否安装好了:执行
opencode --version显示版本号(例如:1.2.21),证明安装好了 - vscode中安装opencode插件
2. Windows 安装
2.1 方式一(联网安装):
winget install --id SST.opencode- vscode中安装opencode插件,通过"从VSIX安装"方式安装插件,插件安装包处于installations目录
2.2 方式二(离线安装):
- 打开opencode-cli文件夹(处于项目installations目录),其中存在opencode.exe以及配置文件opencode.json
- 配置私有化模型:编辑
opencode.json文件,根据你的本地部署情况修改以下配置:baseURL: 改为你的vLLM服务地址(默认:http://localhost:8000/v1)apiKey: 根据你的服务设置修改(默认:EMPTY)models: 根据实际部署的模型名称修改(默认:MiniMax-M2.5)
- 设置环境变量,实现opencode命令可在任意位置的CMD窗口直接运行,步骤如下:
(1)在window搜索栏输入"编辑系统环境变量"
(2)点击下方"环境变量"按钮
(3)在"系统变量"区域,找到并选中变量Path,点击"编辑"
(4)点击"新建",输入opencode.exe所在的完整目录路径(例如 C:\Users\admin\Desktop\CodeGuard\installations\opencode-cli) (5)逐一点击"确定"关闭所有窗口 - 设置配置文件:将 opencode.json文件复制至如下目录
C:\Users\你的用户名\.config\opencode\(注意,首次双击运行opencode.exe,会在自动生成该目录) - 在任意CMD终端中输入
opencode指令,如果显示opencode欢迎界面,说明安装成功 - vscode中安装opencode插件:
通过"从VSIX安装"方式安装插件,插件安装包处于installations目录
安装完成后vscode打开任意文件,在弹出的Tab页面右上角,点击opencode图标,即可在当前项目工作目录下使用opencode
2.3 配置本地模型
前提:本地或内网部署的模型服务API端点
http://127.0.0.1:11434/v1,以Ollama为例,配置步骤如下
(1)编辑配置文件
OpenCode 的配置文件位于 C:\Users\你的用户名\.config\opencode\opencode.json , 如果文件不存在,创建opencode.json,,写入如下示例内容,指向本地模型服务:
{
"$schema": "https://opencode.ai/config.json",
"provider": {
"ollama": {
"npm": "@ai-sdk/openai-compatible",
"name": "Ollama (local)",
"options": {
"baseURL": "http://localhost:11434/v1",
},
"models": {
"qwen3:1.7b": {
"_launch": true,
"name": "qwen3:1.7b"
},
"qwen2.5-coder:1.5b": {
"_launch": true,
"name": "qwen2.5-coder:1.5b"
}
}
}
}
}
配置说明
* ollama: 自定义提供商 ID(可自定义名称)
* npm: 指定 AI SDK 包,Ollama 使用 OpenAI 兼容 API,所以使用 @ai-sdk/openai-compatible
* baseURL: 本地 Ollama 服务地址,可替换为vLLM等其他服务,
* apiKey: 如果自定义模型设置了apiKey,则指定;没有设置,则删除这一行的配置
* models: 模型映射,键为 Ollama 模型名称(执行`ollama list`查看),值为显示名称
(2)切换所用模型
在 opencode CLI 、 VSCode opencode插件页面输入框输入/models,按回车,方向键选择刚配置的本地模型,按回车使用该模型。
Semgrep
安装步骤
在互联网机器上:
mkdir semgrep_offline
cd semgrep_offline
pip download semgrep -d wheels
执行完上述命令后,得到目录结构如下:
semgrep_offline/ ├─ wheels/ │ ├─ semgrep-xxx.whl │ ├─ click-xxx.whl │ ├─ requests-xxx.whl │ └─ ...
在离线机器上:
cd semgrep_offline
python -m venv semgrep
semgrep\Scripts\activate
pip install --no-index --find-links=./wheels semgrep
安装完之后通过命令查看安装情况:
semgrep --version
将虚拟环境加入环境变量:
D:\tools\semgrep_env\venv\Scripts
服务私有化部署(Linux服务器)
最终的Dockerfile
############################################################################### # Overview ############################################################################### # Dockerfile to build the semgrep/semgrep:canary docker image # (see .github/workflows/build-test-docker.jsonnet). # # First, we build a fully *static* 'semgrep-core' binary on Alpine. This # binary does not even depend on Glibc because Alpine uses Musl instead # which can be statically linked. # # Then 'semgrep-core' alone is copied to another Alpine-based container # which takes care of the 'semgrep-cli' (a.k.a. pysemgrep) Python wrapping. # # We use Alpine because it allows to generate small Docker images. # We use this two-steps process because *building* semgrep-core itself # requires lots of tools (ocamlc, gcc, make, etc.), with big containers, # but those tools are not necessary when *running* semgrep. # This is a standard practice in the Docker world. # See https://docs.docker.com/build/building/multi-stage/ # We use static linking because we can and removing external library # dependencies is usually simpler (especially since the docker container # where we build semgrep-core is not the same container where we run it). # # In case of problems, if you need to debug the docker image, run 'docker build .', # identify the SHA of the build image and run 'docker run -it /bin/bash' # to interactively explore the docker image before that failing point.###############################################################################
Step0: copy the source files
###############################################################################
We do this in a separate stage to maximize docker cache hits, as the cache is
invalidated when copied files change. So doing this allows us only to use the
cache if an unrelated file such as a workflow or readme changes.
I.e. if we don't touch the core ml files, then we don't need to rebuild the core
or rerun the ocaml tests. This saves us a ton of time in CI
See: https://docs.docker.com/build/cache/optimize/#keep-the-context-small
NOTE!!!: do not add files here unless they are necessary for building the core
ONLY! cli and test files should be added at later stages
coupling: if you add a file here, you probably want to add it in
semgrep.nix and the pro dockerfile
FROM ghcr.io/astral-sh/uv:0.9.26 as uv
FROM scratch AS build-files WORKDIR /src COPY dune dune-project ./ COPY cli/src/semgrep/semgrep_interfaces/ ./cli/src/semgrep/semgrep_interfaces/ COPY TCB ./TCB COPY interfaces ./interfaces COPY languages ./languages COPY libs ./libs COPY src ./src
###############################################################################
Step1: build semgrep-core
###############################################################################
We're now using a simple alpine:3.xx image in the FROM below.
TL;DR this used to be too slow but our use of https://depot.dev to accelerate
our docker build made this a viable and simpler option.
The possible base container candidates are:
- 'alpine', the official Alpine Docker image. This requires some
extra 'apk' commands to install opam, and extra commands to setup OCaml
with this opam from scratch. Moreover, 'opam' itself requires lots of extra
tools like gcc, make, which are not provided by default on Alpine.
In theory, this can make a docker build really slow, like 30min, especially
in Github Actions (GHA).
We build a new Semgrep Docker image on each pull-request (PR) so we don't
want to wait 30min each time just for 'docker build' to finish.
Fortunately, our use of https://depot.dev allows us to cache intermediate
steps which usually make the whole docker build to finish in a few minutes.
- 'ocaml/opam:alpine', the official OCaml/opam Docker image,
but building our Docker image would still take time without depot.dev because
of all the necessary Semgrep dependencies installed in 'make install-deps'.
Note also that ocaml/opam:alpine default user is 'opam', not 'root', which
is not without problems when used inside Github actions (GHA) or even inside
this Dockerfile.
update: we recently started to cache the ~/.opam/ directory in most of our
CI workflows and started to use the official actions/setup-ocaml@v2 which
works pretty well and allowed us to get rid of ocaml-layer.
- 'returntocorp/ocaml:alpine-xxx', which comes from
https://github.com/returntocorp/ocaml-layer/blob/master/configs/alpine.sh
We used this base container for a very long time (before switching to
basic alpine). This Docker image is prepackaged with 'ocamlc','opam', and
lots of packages that are used by semgrep-core and installed in the
'make install-deps' command. Thanks to this container, 'make install-deps'
was finishing very quickly because it was mostly a noop.
However, it was another repository to modify each time we wanted to
add a package or we wanted to switch to a different OCaml version.
Being able to control everything from a single Dockerfile is simpler.
FROM alpine:3.23 AS semgrep-core-container
优化1:使用阿里云 Alpine 镜像源(国内构建提速)
RUN sed -i 's/dl-cdn.alpinelinux.org/mirrors.aliyun.com/g' /etc/apk/repositories
Install opam and basic build tools
https://github.com/ocaml/opam/issues/5186
Why we don't have --no-cache here
hadolint ignore=DL3019
RUN apk update && apk add --no-cache bash build-base git make rsync opam
RUN git config --global url."https://gh-proxy.org/https://github.com/".insteadOf https://github.com/
coupling: if you modify the OCaml version there, you probably also need
to modify:
- .github/workflows/libs/semgrep.libsonnet
- scripts/{osx-setup-for-release,setup-m1-builder}.sh
- doc/SEMGREP_CORE_CONTRIBUTING.md
- https://github.com/Homebrew/homebrew-core/blob/master/Formula/semgrep.rb
RUN opam init --disable-sandboxing -v && opam switch create 5.3.0 ocaml-variants.5.3.0+options ocaml-option-flambda -y -v
RUN opam init --disable-sandboxing -y &&
opam switch create 5.3.0 ocaml-variants.5.3.0+options ocaml-option-flambda -yInstall semgrep-core build dependencies
WORKDIR /src/semgrep
Copy just what is needed for make install-deps below to work to maximize
docker cache hit as building and installing all the opam packages
is what takes the most time in the docker build.
coupling: if you change this you probably want to change this in semgrep-pro
COPY Makefile cygwin-env.mk semgrep.opam ./ COPY dev/required.opam dev/ COPY scripts/build-static-libcurl.sh scripts/ COPY scripts/validate-compiler-sha.sh scripts/ COPY scripts/pick-lockfile.sh scripts/ COPY opam-lockfiles/ ./opam-lockfiles COPY libs/ocaml-tree-sitter-core libs/ocaml-tree-sitter-core COPY cli/src/semgrep/semgrep_interfaces cli/src/semgrep/semgrep_interfaces
Install our fork of the compiler
RUN make pin-ocaml-fork
RUN make install-deps
RUN eval $(opam env) && make pin-ocaml-fork RUN eval $(opam env) && make install-deps
List the dependencies we've installed and their versions
RUN opam list
Copy over the core files needed for compilation
COPY --from=build-files /src .
Docker struggles to copy symlinks, so let's just make it
RUN ln -s _build/install/default/bin bin
Compile (and minimal test) semgrep-core
RUN opam exec -- make core
Sanity check
RUN ./bin/semgrep-core -version RUN ./scripts/validate-compiler-sha.sh bin/semgrep-core
Install pyro-caml for profiling
RUN opam exec -- make install-pyro-caml
###############################################################################
Step2: Combine the Python wrapper (pysemgrep) and semgrep-core binary
###############################################################################
We change container, bringing the 'semgrep-core' binary with us.
Start from scratch with a fresh Alpine image. We used to use
python:3.11-alpinebut want to avoid shipping a bunch of unneeded Pythonpackages in our production image. Instead we'll install exactly what we need.
#coupling: the 'semgrep-oss' name is used in 'make build-docker' #coupling: if you change this alpine version it might be good to change the
previous stage to the same version, and to change the alpine version in the workflows
FROM alpine:3.23 AS semgrep-oss
WORKDIR /pysemgrep
Update to the latest packages for the base image. This allows to get CVE
fixes ASAP, without waiting for new builds of the base image.
See docker-library/python#761 for an example of such an issue in the past
where the time between the CVE was discovered and the package update was
X days, but the new base image was updated only after Y days.
RUN sed -i 's/dl-cdn.alpinelinux.org/mirrors.aliyun.com/g' /etc/apk/repositories
&& apk upgrade --no-cache
&& apk add --no-cache --virtual=.run-deps\Try to limit to the minimum the number of packages to install; this reduces
the attack surface.
history: we used to install here various utilities needed by some of our
scripts under scripts/. Indeed, those scripts are run from CI jobs using the
semgrep/semgrep docker image as the container because they rely on semgrep
or semgrep-core. Those scripts must also perform different
tasks that require utilities other than semgrep (e.g., compute parsing
statistics and then run 'jq' to filter the JSON). It is convenient to add
them to the docker image, especially because the addition of those packages
does not add much to the size of the docker image (<1%). However, those utilities
can have CVEs associated with them. However, some users are already relying on
those utilities in their own CI workflows so we must strike a balance between
reducing the attack surface and not breaking existing workflows.
alt:
- we used to have an alternate semgrep-dev.Dockerfile container to use
for our benchmarks, but it complicates things
If you need more utilities, it is better to install them in the workflow instead
(see for example cron-parsing-stats.jsonnet).
See https://docs.docker.com/develop/security-best-practices/ for more info.
Here is why we need the apk packages below:
- git, git-lfs, openssh: so that the semgrep docker image can be used in
Github actions (GHA) and get git submodules and use ssh to get those
submodules
- bash: many users customize their call to semgrep via bash script
- jq: useful to process the JSON output of semgrep
- curl: useful to connect to some webhooks
- python3: to run pysemgrep
- py3-setuptools: necessary runtime dependency for opentelemetry
git git-lfs openssh \ bash jq curl python3 py3-setuptoolsWe just need the Python code in cli/.
The semgrep-core stuff would be copied from the other container
COPY cli ./
#??? ENV PIP_DISABLE_PIP_VERSION_CHECK=true
PIP_NO_CACHE_DIR=true
PYTHONIOENCODING=utf8
PYTHONUNBUFFERED=1
PIP_INDEX_URL=https://mirrors.aliyun.com/pypi/simpleLet's now simply use 'pip' to install semgrep.
Note the difference between .run-deps and .build-deps below.
We use a single command to install packages, install semgrep, and remove
packages to keep a small Docker image (classic Docker trick).
Here is why we need the apk packages below:
- build-base: ??
Using --break-system-packages so that Semgrep is installed globally in this
container. Given that Alpine doesn't even ship with Python off the shelf and
we are installing it only to run Semgrep, the risk of unintended consequences
here is minimal.
hadolint ignore=DL3013
RUN apk add --no-cache --virtual=.build-deps build-base make py3-pip &&
pip install /pysemgrep --break-system-packages &&
apk del .build-depsGet semgrep-core from step1
COPY --from=semgrep-core-container /src/semgrep/_build/default/src/main/Main.exe /usr/local/bin/semgrep-core
Get pyro-caml from step1
COPY --from=semgrep-core-container /root/.opam/5.3.0/bin/pyro-caml /usr/bin/pyro-caml
We don't need the python source anymore; 'pip install ...' above
installed them under /usr/local/lib/python3.xx/site-packages/semgrep/
RUN ln -s semgrep-core /usr/local/bin/osemgrep && rm -rf /pysemgrep
###############################################################################
Step2 bis: setup the docker image
###############################################################################
In theory we could do this in a different container
Let the user know how their container was built
COPY Dockerfile /Dockerfile
There are a few places in the CLI where we do different things
depending on whether we are run from a Docker container.
See also Semgrep_envvars.ml and Metrics_.mli.
ENV SEMGREP_IN_DOCKER=1
SEMGREP_USER_AGENT_APPEND="Docker"The command we tell people to run for testing semgrep in Docker is
docker run --rm -v "${PWD}:/src" semgrep/semgrep semgrep --config=auto
(see https://semgrep.dev/docs/getting-started/ ), hence this WORKDIR directive
WORKDIR /src
It is better to avoid running semgrep as root
See https://stackoverflow.com/questions/49193283/why-it-is-unsafe-to-run-applications-as-root-in-docker-container
Note though that the actual USER directive is done in Step 3.
RUN adduser -D -u 1000 -h /home/semgrep semgrep
&& chown semgrep /srcstay with ROOT for now (see the nonroot step below)
#USER semgrep
Workaround for rootless containers as git operations may fail due to dubious
ownership of /src
RUN printf "[safe]\n directory = /src" > ~root/.gitconfig RUN printf "[safe]\n directory = /src" > ~semgrep/.gitconfig &&
chown semgrep:semgrep ~semgrep/.gitconfigNote that we just use CMD below. Why not using ENTRYPOINT ["semgrep"] ?
so that people can simply run
docker run --rm -v "${PWD}:/src" semgrep/semgrep --helpinstead of
docker run --rm -v "${PWD}:/src" semgrep/semgrep semgrep --help?(Yes, that's 3 semgrep in a row, hmmm)
This is mainly to play well with CI providers like Gitlab. Indeed,
gitlab CI sets up all CI jobs by first running other commands in the
container; setting an ENTRYPOINT would break those commands and cause jobs
to fail on setup, and would require users to set a manual override of the
image's entrypoint in a .gitlab-ci.yml.
=> Simpler to not have any ENTRYPOINT, even it means forcing the user
to repeat multiple times semgrep in the docker command line.
Using CMD instead gives them a default command when nothing is
passed to the container, but at the same time still allows users
to run the container interactively.
For example,
docker run semgrep/semgrep
will show the help text, but
docker run -it semgrep/semgrep /bin/bash
will let users bring up a bash session.
CMD ["semgrep", "--help"] LABEL maintainer="support@semgrep.com"
###############################################################################
Step3: install semgrep-pro
###############################################################################
This builds a semgrep docker image with semgrep-pro already included,
to save time in CI as one does not need to wait 2min each time to
download it (it also reduces our cost to S3).
This step is valid only when run from Github Actions (it needs a secret)
See .github/workflows/build-test-docker.jsonnet and release.jsonnet
#coupling: the 'semgrep-cli' name is used in release.jsonnet FROM semgrep-oss AS semgrep-cli
Expects to find a secret named SEMGREP_APP_TOKEN in Github Actions. To run
locally, set the SEMGREP_APP_TOKEN environment variable and then run:
$ docker build --secret id=SEMGREP_APP_TOKEN ...
RUN --mount=type=secret,id=SEMGREP_APP_TOKEN if [ -f /run/secrets/SEMGREP_APP_TOKEN ]; then ( SEMGREP_APP_TOKEN=$(cat /run/secrets/SEMGREP_APP_TOKEN) semgrep install-semgrep-pro --debug ); else ( echo "SEMGREP_APP_TOKEN secret not set, skipping semgrep-pro install" >&2 ); fi
Clear out any detritus from the pro install (especially credentials)
RUN rm -rf /root/.semgrep
This was the final step! This is what we ship to users!
###############################################################################
optional: nonroot variant
###############################################################################
Additional build stage that sets a non-root user.
We can't make this the default in the semgrep-cli stage above because of
permissions errors on the mounted volume when using instructions for running
semgrep with docker:
docker run -v "${PWD}:/src" -i semgrep/semgrep semgrep#coupling: the 'nonroot' name is used in release.jsonnet FROM semgrep-cli AS nonroot
We need to move the core binary out of the protected /usr/local/bin dir so
the non-root user can run
semgrep install-semgrep-proand use Pro Enginealt: we could also do this work directly in the root docker image.
TODO? now that we install semgrep-pro in step4, do we still need that?
RUN rm /usr/local/bin/osemgrep &&
mkdir /home/semgrep/bin &&
mv /usr/local/bin/semgrep-core /home/semgrep/bin &&
ln -s semgrep-core /home/semgrep/bin/osemgrep &&
chown semgrep:semgrep /home/semgrep/binUpdate PATH with new core binary location
ENV PATH="$PATH:/home/semgrep/bin"
USER semgrep
###############################################################################
Other target: Build the semgrep Python wheel
###############################################################################
This is a target used for building Python wheels. Semgrep users
don't need to use this.
#coupling: 'semgrep-wheel' is used in build-test-manylinux-aarch64.jsonnet #TODO: we should switch to alpine 3.23 for consistency with the other stages FROM python:3.11-alpine AS semgrep-wheel COPY --from=uv /uv /uvx /bin/
WORKDIR /semgrep
Install some deps:
- build-base because ruamel.yaml has native code
- libffi-dev is needed for installing Python dependencies in
scripts/build-wheels.sh on arm64
RUN echo "https://mirrors.aliyun.com/alpine/v3.23/main" > /etc/apk/repositories
&& echo "https://mirrors.aliyun.com/alpine/v3.23/community" >> /etc/apk/repositories
&& apk update RUN apk add --no-cache build-base zip bash libffi-devCopy in the README, which the wheels include
COPY README.md ./README.md
Copy in the CLI
COPY cli ./cli
Copy in semgrep-core executable
COPY --from=semgrep-core-container /src/semgrep/_build/default/src/main/Main.exe cli/src/semgrep/bin/semgrep-core
Copy in scripts folder
COPY scripts/ ./scripts/
Build the source distribution and binary wheel, validate that the wheel
installs correctly. We're only checking the musllinux wheel because this is
an Alpine container. It should not be a problem because the content of the
wheels are identical.
RUN scripts/build-wheels.sh && scripts/validate-wheel.sh cli/dist/musllinux.whl
FROM scratch AS semgrep-wheel-binaries
COPY --from=semgrep-wheel /semgrep/cli/dist/musllinux.whl /
FROM semgrep-core-container AS semgrep-core-test
Git repo is need for tests
RUN git init
Copy over files needed for the core tests
COPY cli/tests/default/e2e/targets/ls ./cli/tests/default/e2e/targets/ls COPY scripts/run-core-test ./scripts/run-core-test COPY scripts/make-symlinks ./scripts/make-symlinks COPY tests ./tests #Docker struggles to copy symlinks, so let's just make it RUN ln -s _build/default/src/tests/test.exe test
RUN opam exec -- make build-core-test
CMD ["opam", "exec", "--", "make", "test", "core-test-e2e"]
Let's actually use latest so we know immediately if we're broken on latest
#hadolint ignore=DL3007 FROM ubuntu:latest AS semgrep-wheel-test COPY --from=semgrep-wheel-binaries / /wheels
RUN apt-get update
&& apt-get install --no-install-recommends -y python3-pip
&& rm -rf /var/lib/apt/lists/*
RUN pip install --break-system-packages --no-cache-dir /wheels/*.whl RUN semgrep --version #hadolint ignore=SC2016,DL4006 RUN echo '1==1' | semgrep -l python -e '$X == $X' -
git diff查看到的变更信息
commit fa925266dd3c62f1de48e393052c8288f1022166 (HEAD -> v1.154.0-ChinaBuild)
Author: zhangxunhui
Date: Sun Mar 8 17:38:36 2026 +0800
modify Dockerfile for building semgrep in China with tag v1.154.0
diff --git a/Dockerfile b/Dockerfile
index e303aa6e3..8af2fe545 100644
--- a/Dockerfile
+++ b/Dockerfile
@@ -104,12 +104,16 @@ COPY src ./src
FROM alpine:3.23 AS semgrep-core-container
+# 优化1:使用阿里云 Alpine 镜像源(国内构建提速)
+RUN sed -i 's/dl-cdn.alpinelinux.org/mirrors.aliyun.com/g' /etc/apk/repositories
Install opam and basic build tools
https://github.com/ocaml/opam/issues/5186
Why we don't have --no-cache here
hadolint ignore=DL3019
-RUN apk update && apk add bash build-base git make rsync opam
+RUN apk update && apk add --no-cache bash build-base git make rsync opam
+
+RUN git config --global url."https://gh-proxy.org/https://github.com/".insteadOf https://github.com/
coupling: if you modify the OCaml version there, you probably also need
to modify:
@@ -117,7 +121,9 @@ RUN apk update && apk add bash build-base git make rsync opam
- scripts/{osx-setup-for-release,setup-m1-builder}.sh
- doc/SEMGREP_CORE_CONTRIBUTING.md
- https://github.com/Homebrew/homebrew-core/blob/master/Formula/semgrep.rb
-RUN opam init --disable-sandboxing -v && opam switch create 5.3.0 ocaml-variants.5.3.0+options ocaml-option-flambda -y -v
+# RUN opam init --disable-sandboxing -v && opam switch create 5.3.0 ocaml-variants.5.3.0+options ocaml-option-flambda -y -v
+RUN opam init --disable-sandboxing -y && \
- opam switch create 5.3.0 ocaml-variants.5.3.0+options ocaml-option-flambda -y
Install semgrep-core build dependencies
WORKDIR /src/semgrep
@@ -137,9 +143,11 @@ COPY libs/ocaml-tree-sitter-core libs/ocaml-tree-sitter-core
COPY cli/src/semgrep/semgrep_interfaces cli/src/semgrep/semgrep_interfaces
Install our fork of the compiler
-RUN make pin-ocaml-fork
+# RUN make pin-ocaml-fork
-RUN make install-deps
+# RUN make install-deps
+RUN eval $(opam env) && make pin-ocaml-fork
+RUN eval $(opam env) && make install-deps
List the dependencies we've installed and their versions
RUN opam list
@@ -180,8 +188,9 @@ WORKDIR /pysemgrep
See docker-library/python#761 for an example of such an issue in the past
where the time between the CVE was discovered and the package update was
X days, but the new base image was updated only after Y days.
-RUN apk upgrade --no-cache && \
- apk add --no-cache --virtual=.run-deps
+RUN sed -i 's/dl-cdn.alpinelinux.org/mirrors.aliyun.com/g' /etc/apk/repositories \
- && apk upgrade --no-cache \
- && apk add --no-cache --virtual=.run-deps\
Try to limit to the minimum the number of packages to install; this reduces
the attack surface.
@@ -225,7 +234,8 @@ COPY cli ./
ENV PIP_DISABLE_PIP_VERSION_CHECK=true
PIP_NO_CACHE_DIR=true
PYTHONIOENCODING=utf8 \
- PYTHONUNBUFFERED=1
- PYTHONUNBUFFERED=1 \
- PIP_INDEX_URL=https://mirrors.aliyun.com/pypi/simple
Let's now simply use 'pip' to install semgrep.
Note the difference between .run-deps and .build-deps below.
@@ -376,6 +386,10 @@ WORKDIR /semgrep
- build-base because ruamel.yaml has native code
- libffi-dev is needed for installing Python dependencies in
scripts/build-wheels.sh on arm64
+RUN echo "https://mirrors.aliyun.com/alpine/v3.23/main" > /etc/apk/repositories \
- && echo "https://mirrors.aliyun.com/alpine/v3.23/community" >> /etc/apk/repositories \
- && apk update
RUN apk add --no-cache build-base zip bash libffi-dev
Copy in the README, which the wheels include
git config --global core.longpaths truegit clone --recurse-submodules https://github.com/semgrep/semgrep.gitgit checkout v1.154.0git config core.symlinks true(非常重要)docker build -t semgrep:latest .
skill安装
windows
install-semgrep-skill.bat
linux
bash install-semgrep-skill.sh