From 5aa1cd7f401b66db3dc18c114e9e78c245cf11b9 Mon Sep 17 00:00:00 2001 From: Hector Zarate Date: Sun, 18 May 2025 14:08:11 +0200 Subject: [PATCH] feat(Dockerfile): pin versions of dependencies (#1190) * Pin versions of dependencies * no need to override default values in github build action * unpin curl,gnupg,tiny,python3,default-jre-headless * Revert "unpin curl,gnupg,tiny,python3,default-jre-headless" This reverts commit 95b0250700657ab28740b8030b658b6b6b680187. * remove pin from Libreoffice * Update build/Dockerfile Co-authored-by: Julien Neuhart --------- Co-authored-by: Julien Neuhart --- .env | 9 +- .github/actions/build-test-push/build.sh | 6 -- Makefile | 7 -- build/Dockerfile | 117 ++++++++++++----------- 4 files changed, 61 insertions(+), 78 deletions(-) diff --git a/.env b/.env index 7922de9f..7179b1f0 100644 --- a/.env +++ b/.env @@ -1,13 +1,6 @@ -GOLANG_VERSION=1.24 +GOTENBERG_VERSION=snapshot DOCKER_REGISTRY=gotenberg DOCKER_REPOSITORY=gotenberg -GOTENBERG_VERSION=snapshot -GOTENBERG_USER_GID=1001 -GOTENBERG_USER_UID=1001 -NOTO_COLOR_EMOJI_VERSION=v2.047 # See https://github.com/googlefonts/noto-emoji/releases. -PDFTK_VERSION=v3.3.3 # See https://gitlab.com/pdftk-java/pdftk/-/releases - Binary package. -PDFCPU_VERSION=v0.8.1 # See https://github.com/pdfcpu/pdfcpu/releases. -GOTENBERG_VERSION=snapshot DOCKERFILE=build/Dockerfile DOCKERFILE_CLOUDRUN=build/Dockerfile.cloudrun DOCKER_BUILD_CONTEXT='.' diff --git a/.github/actions/build-test-push/build.sh b/.github/actions/build-test-push/build.sh index 410d3abd..170ba574 100755 --- a/.github/actions/build-test-push/build.sh +++ b/.github/actions/build-test-push/build.sh @@ -129,13 +129,7 @@ join() { no_arch_tag="$DOCKER_REGISTRY/$DOCKER_REPOSITORY:$version" cmd="docker buildx build \ - --build-arg GOLANG_VERSION=$GOLANG_VERSION \ --build-arg GOTENBERG_VERSION=$version \ - --build-arg GOTENBERG_USER_GID=$GOTENBERG_USER_GID \ - --build-arg GOTENBERG_USER_UID=$GOTENBERG_USER_UID \ - --build-arg NOTO_COLOR_EMOJI_VERSION=$NOTO_COLOR_EMOJI_VERSION \ - --build-arg PDFTK_VERSION=$PDFTK_VERSION \ - --build-arg PDFCPU_VERSION=$PDFCPU_VERSION \ --platform $platform \ --load \ ${tags_flags[*]} \ diff --git a/Makefile b/Makefile index 52b8847d..c8af5593 100644 --- a/Makefile +++ b/Makefile @@ -7,13 +7,6 @@ help: ## Show the help .PHONY: build build: ## Build the Gotenberg's Docker image docker build \ - --build-arg GOLANG_VERSION=$(GOLANG_VERSION) \ - --build-arg GOTENBERG_VERSION=$(GOTENBERG_VERSION) \ - --build-arg GOTENBERG_USER_GID=$(GOTENBERG_USER_GID) \ - --build-arg GOTENBERG_USER_UID=$(GOTENBERG_USER_UID) \ - --build-arg NOTO_COLOR_EMOJI_VERSION=$(NOTO_COLOR_EMOJI_VERSION) \ - --build-arg PDFTK_VERSION=$(PDFTK_VERSION) \ - --build-arg PDFCPU_VERSION=$(PDFCPU_VERSION) \ -t $(DOCKER_REGISTRY)/$(DOCKER_REPOSITORY):$(GOTENBERG_VERSION) \ -f $(DOCKERFILE) $(DOCKER_BUILD_CONTEXT) diff --git a/build/Dockerfile b/build/Dockerfile index 69940546..96499bf3 100644 --- a/build/Dockerfile +++ b/build/Dockerfile @@ -1,7 +1,7 @@ # ARG instructions do not create additional layers. Instead, next layers will # concatenate them. Also, we have to repeat ARG instructions in each build # stage that uses them. -ARG GOLANG_VERSION +ARG GOLANG_VERSION=1.24 # ---------------------------------------------- # pdfcpu binary build stage @@ -10,7 +10,8 @@ ARG GOLANG_VERSION # default. FROM golang:$GOLANG_VERSION AS pdfcpu-binary-stage -ARG PDFCPU_VERSION +# See https://github.com/pdfcpu/pdfcpu/releases. +ARG PDFCPU_VERSION=v0.8.1 ENV CGO_ENABLED=0 # Define the working directory outside of $GOPATH (we're using go modules). @@ -32,7 +33,7 @@ RUN go build -o pdfcpu -ldflags "-s -w -X 'main.version=$PDFCPU_VERSION' -X 'git # ---------------------------------------------- FROM golang:$GOLANG_VERSION AS gotenberg-binary-stage -ARG GOTENBERG_VERSION +ARG GOTENBERG_VERSION=snapshot ENV CGO_ENABLED=0 # Define the working directory outside of $GOPATH (we're using go modules). @@ -105,18 +106,20 @@ ENV PATH="/opt/java/bin:${PATH}" # ---------------------------------------------- FROM base-image-stage -ARG GOTENBERG_VERSION -ARG GOTENBERG_USER_GID -ARG GOTENBERG_USER_UID -ARG NOTO_COLOR_EMOJI_VERSION -ARG PDFTK_VERSION +ARG GOTENBERG_VERSION=snapshot +ARG GOTENBERG_USER_GID=1001 +ARG GOTENBERG_USER_UID=1001 +# See https://github.com/googlefonts/noto-emoji/releases. +ARG NOTO_COLOR_EMOJI_VERSION=v2.047 +# See https://gitlab.com/pdftk-java/pdftk/-/releases - Binary package. +ARG PDFTK_VERSION=v3.3.3 LABEL org.opencontainers.image.title="Gotenberg" \ - org.opencontainers.image.description="A containerized API for seamless PDF conversion." \ - org.opencontainers.image.version="$GOTENBERG_VERSION" \ - org.opencontainers.image.authors="Julien Neuhart " \ - org.opencontainers.image.documentation="https://gotenberg.dev" \ - org.opencontainers.image.source="https://github.com/gotenberg/gotenberg" + org.opencontainers.image.description="A containerized API for seamless PDF conversion." \ + org.opencontainers.image.version="$GOTENBERG_VERSION" \ + org.opencontainers.image.authors="Julien Neuhart " \ + org.opencontainers.image.documentation="https://gotenberg.dev" \ + org.opencontainers.image.source="https://github.com/gotenberg/gotenberg" RUN \ # Create a non-root user. @@ -131,7 +134,7 @@ RUN \ # Note: tini is a helper for reaping zombie processes. apt-get update -qq &&\ apt-get upgrade -yqq &&\ - DEBIAN_FRONTEND=noninteractive apt-get install -y -qq --no-install-recommends curl gnupg tini python3 &&\ + DEBIAN_FRONTEND=noninteractive apt-get install -y -qq --no-install-recommends curl gnupg=2.2.40-1.1 tini=0.19.0-1 python3=3.11.2-1+b1 &&\ # Cleanup. # Note: the Debian image does automatically a clean after each install thanks to a hook. # Therefore, there is no need for apt-get clean. @@ -148,40 +151,40 @@ RUN \ apt-get upgrade -yqq &&\ DEBIAN_FRONTEND=noninteractive apt-get install -y -qq --no-install-recommends \ ./ttf-mscorefonts-installer_3.8.1_all.deb \ - culmus \ - fonts-beng \ - fonts-hosny-amiri \ - fonts-lklug-sinhala \ - fonts-lohit-guru \ - fonts-lohit-knda \ - fonts-samyak-gujr \ - fonts-samyak-mlym \ - fonts-samyak-taml \ - fonts-sarai \ - fonts-sil-abyssinica \ - fonts-sil-padauk \ - fonts-telu \ - fonts-thai-tlwg \ + culmus=0.133-1 \ + fonts-beng=2:1.3 \ + fonts-hosny-amiri=0.113-1 \ + fonts-lklug-sinhala=0.6-4 \ + fonts-lohit-guru=2.91.2-3 \ + fonts-lohit-knda=2.5.4-3 \ + fonts-samyak-gujr=1.2.2-6 \ + fonts-samyak-mlym=1.2.2-6 \ + fonts-samyak-taml=1.2.2-6 \ + fonts-sarai=1.0-3 \ + fonts-sil-abyssinica=2.100-3 \ + fonts-sil-padauk=5.000-3 \ + fonts-telu=2:1.3 \ + fonts-thai-tlwg=1:0.7.3-1 \ ttf-wqy-zenhei \ - fonts-arphic-ukai \ - fonts-arphic-uming \ - fonts-ipafont-mincho \ - fonts-ipafont-gothic \ - fonts-unfonts-core \ + fonts-arphic-ukai=0.2.20080216.2-5 \ + fonts-arphic-uming=0.2.20080216.2-11 \ + fonts-ipafont-mincho=00303-23 \ + fonts-ipafont-gothic=00303-23 \ + fonts-unfonts-core=1:1.0.2-080608-18 \ # LibreOffice recommends. - fonts-crosextra-caladea \ - fonts-crosextra-carlito \ - fonts-dejavu \ - fonts-dejavu-extra \ - fonts-liberation \ - fonts-liberation2 \ - fonts-linuxlibertine \ - fonts-noto-cjk \ - fonts-noto-core \ - fonts-noto-mono \ - fonts-noto-ui-core \ - fonts-sil-gentium \ - fonts-sil-gentium-basic &&\ + fonts-crosextra-caladea=20200211-1 \ + fonts-crosextra-carlito=20220224-1 \ + fonts-dejavu=2.37-6 \ + fonts-dejavu-extra=2.37-6 \ + fonts-liberation=1:1.07.4-11 \ + fonts-liberation2=2.1.5-1 \ + fonts-linuxlibertine=5.3.0-6 \ + fonts-noto-cjk=1:20220127+repack1-1 \ + fonts-noto-core=20201225-1 \ + fonts-noto-mono=20201225-1 \ + fonts-noto-ui-core=20201225-1 \ + fonts-sil-gentium=20081126:1.03-4 \ + fonts-sil-gentium-basic=1.102-1.1 &&\ rm -f ./ttf-mscorefonts-installer_3.8.1_all.deb &&\ # Add Color and Black-and-White Noto emoji font. # Credits: @@ -198,16 +201,16 @@ RUN \ /bin/bash -c \ 'set -e &&\ if [[ "$(dpkg --print-architecture)" == "amd64" ]]; then \ - curl https://dl.google.com/linux/linux_signing_key.pub | apt-key add - &&\ - echo "deb http://dl.google.com/linux/chrome/deb/ stable main" | tee /etc/apt/sources.list.d/google-chrome.list &&\ - apt-get update -qq &&\ - apt-get upgrade -yqq &&\ - DEBIAN_FRONTEND=noninteractive apt-get install -y -qq --no-install-recommends --allow-unauthenticated google-chrome-stable &&\ - mv /usr/bin/google-chrome-stable /usr/bin/chromium; \ + curl https://dl.google.com/linux/linux_signing_key.pub | apt-key add - &&\ + echo "deb http://dl.google.com/linux/chrome/deb/ stable main" | tee /etc/apt/sources.list.d/google-chrome.list &&\ + apt-get update -qq &&\ + apt-get upgrade -yqq &&\ + DEBIAN_FRONTEND=noninteractive apt-get install -y -qq --no-install-recommends --allow-unauthenticated google-chrome-stable &&\ + mv /usr/bin/google-chrome-stable /usr/bin/chromium; \ else \ - apt-get update -qq &&\ - apt-get upgrade -yqq &&\ - DEBIAN_FRONTEND=noninteractive apt-get install -y -qq --no-install-recommends chromium; \ + apt-get update -qq &&\ + apt-get upgrade -yqq &&\ + DEBIAN_FRONTEND=noninteractive apt-get install -y -qq --no-install-recommends chromium; \ fi' &&\ # Verify installation. chromium --version &&\ @@ -242,11 +245,11 @@ RUN \ # See https://github.com/gotenberg/gotenberg/pull/273. curl -o /usr/bin/pdftk-all.jar "https://gitlab.com/api/v4/projects/5024297/packages/generic/pdftk-java/$PDFTK_VERSION/pdftk-all.jar" &&\ chmod a+x /usr/bin/pdftk-all.jar &&\ - echo '#!/bin/bash\n\nexec java -jar /usr/bin/pdftk-all.jar "$@"' > /usr/bin/pdftk && \ + printf '#!/bin/bash\n\nexec java -jar /usr/bin/pdftk-all.jar "$@"' > /usr/bin/pdftk && \ chmod +x /usr/bin/pdftk &&\ apt-get update -qq &&\ apt-get upgrade -yqq &&\ - DEBIAN_FRONTEND=noninteractive apt-get install -y -qq --no-install-recommends qpdf exiftool &&\ + DEBIAN_FRONTEND=noninteractive apt-get install -y -qq --no-install-recommends qpdf=11.3.0-1+deb12u1 exiftool &&\ # See https://github.com/nextcloud/docker/issues/380. mkdir -p /usr/share/man/man1 &&\ # Verify installations.