Skip to content

fix: Surround this variable with double quotes; otherwise, it can lead to une#3

Open
ciadoh wants to merge 1 commit into
masterfrom
sonar-fix/4695549f-8091-4276-8b34-df3567471cc2
Open

fix: Surround this variable with double quotes; otherwise, it can lead to une#3
ciadoh wants to merge 1 commit into
masterfrom
sonar-fix/4695549f-8091-4276-8b34-df3567471cc2

Conversation

@ciadoh

@ciadoh ciadoh commented Jun 12, 2026

Copy link
Copy Markdown
Owner

SonarQube Issue

Key: 4695549f-8091-4276-8b34-df3567471cc2
File: Dockerfile

AI Analysis & Fix

Explanation

The issue flagged by SonarQube (docker:S6570) indicates that a variable in the Dockerfile is not surrounded by double quotes. In Docker, when variables are used in commands or instructions, not quoting them can lead to unexpected behavior, especially if the variable contains spaces, special characters, or multiple words. This can cause the Docker build process to fail or produce incorrect results.

Concrete Fix

Before:

ARG my_variable=default value
RUN echo $my_variable

After:

ARG my_variable=default value
RUN echo "$my_variable"

Caveats or Edge Cases

  1. Empty Variables: If the variable can be empty and you don’t want to output quotes, you’ll need additional logic to handle this.

    ARG my_variable=
    RUN if [ -n "$my_variable" ]; then echo "$my_variable"; else echo "Variable is empty"; fi
  2. Special Characters: Be cautious with variables that might contain special characters. Quoting them usually handles most cases, but complex scenarios might require additional escaping.

    ARG my_variable=value with spaces and $special_chars
    RUN echo "$my_variable"
  3. Shell Interpretation: Remember that double quotes prevent word splitting and globbing, which might be desired in some cases. Use single quotes (') if you want to prevent any shell interpretation.

    ARG my_variable=default value
    RUN echo '$my_variable'  # Outputs the literal $my_variable

Always test your Dockerfile after making changes to ensure the build process works as expected.


Generated by TechDebt AI

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant