arrow
Return

DRIVE: Dockerfile Rule Mining and Violation Detection

delete2023-12-21
delete0
delete
OA
AI
周余 (Yu Zhou)
W
Weilin Zhan
Z
Zi Li
T
Tingting Han
T
Taolue Chen *
H
Harald C. Gall
DOI:10.1145/3617173delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
A Dockerfile defines a set of instructions to build Docker images, which can then be instantiated to support containerized applications. Recent studies have revealed a considerable amount of quality issues with Dockerfiles. In this article, we propose a novel approach, Dockerfiles Rule mIning and Violation dEtection (DRIVE), to mine implicit rules and detect potential violations of such rules in Dockerfiles. DRIVE first parses Dockerfiles and transforms them to an intermediate representation. It then leverages an efficient sequential pattern mining algorithm to extract potential patterns. With heuristic-based reduction and moderate human intervention, potential rules are identified, which can then be utilized to detect potential violations of Dockerfiles. DRIVE identifies 34 semantic rules and 19 syntactic rules including 9 new semantic rules that have not been reported elsewhere. Extensive experiments on real-world Dockerfiles demonstrate the efficacy of our approach.
Keywords:
Docker
dockerfile
pattern mining
configuration files
violation detection

Journal

A
ACM Transactions on Software Engineering and Methodology
IF:
6.2
Papers:
1.2K
Citations:
3.4K

Organization

B
Birkbeck University London
Scholars:
1.8K
Papers: 1.4K
Citations: 11
U
university of london
Scholars:
21.5W
Papers: 19.7W
Citations: 305