From 991e20c70bf3d81066e83b4b3c8da757091440b3 Mon Sep 17 00:00:00 2001 From: Gunjan Sonawane Date: Wed, 2 Sep 2026 22:00:27 +0100 Subject: [PATCH 1/2] docs: add Windows Docker installation instructions Signed-off-by: Gunjan Sonawane --- docs/source/installation.rst | 61 ++++++++++++++++++++++++++++++++++-- 1 file changed, 58 insertions(+), 3 deletions(-) diff --git a/docs/source/installation.rst b/docs/source/installation.rst index 9e9f3c7d1..e67d73c43 100644 --- a/docs/source/installation.rst +++ b/docs/source/installation.rst @@ -90,7 +90,65 @@ to run on a different port than 8000. .. tip:: Set ``STAGING=False`` in ``.env`` file to disable the staging environment warning. +Windows installation with Docker +^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ +Windows users should run VulnerableCode with Docker Desktop. Native Windows +installation is not supported. + +Install and start Docker Desktop, then open PowerShell and clone the repository:: + + git clone https://github.com/aboutcode-org/vulnerablecode.git + cd vulnerablecode + +Create the configuration directory and environment file using PowerShell. The +following commands generate secure values for both required settings:: + + New-Item -ItemType Directory -Force .\vulnerablecode-config + $secretKeyBytes = New-Object byte[] 50 + $rng = [System.Security.Cryptography.RandomNumberGenerator]::Create() + $rng.GetBytes($secretKeyBytes) + $secretKey = [Convert]::ToBase64String($secretKeyBytes) + + $altchaKeyBytes = New-Object byte[] 32 + $rng.GetBytes($altchaKeyBytes) + $altchaHmacKey = -join ($altchaKeyBytes | ForEach-Object { $_.ToString("x2") }) + $rng.Dispose() + + @" + SECRET_KEY="$secretKey" + ALTCHA_HMAC_KEY="$altchaHmacKey" + "@ | Set-Content .\vulnerablecode-config\.env + +Create ``docker-compose.override.yml`` with the configuration mount for the +application, scheduler, and both RQ workers:: + + services: + vulnerablecode: + volumes: + - .\vulnerablecode-config:/etc/vulnerablecode/ + vulnerablecode_scheduler: + volumes: + - .\vulnerablecode-config:/etc/vulnerablecode/ + vulnerablecode_rqworker: + volumes: + - .\vulnerablecode-config:/etc/vulnerablecode/ + vulnerablecode_rqworker_high: + volumes: + - .\vulnerablecode-config:/etc/vulnerablecode/ + +Start and check the services:: + + docker compose up -d + docker compose ps + +VulnerableCode should then be available at:: + + http://localhost + +To stop the services:: + + docker compose down .. _local_development_installation: @@ -105,9 +163,6 @@ Supported Platforms #. **Debian-based** Linux distributions #. **macOS** 12.1 and up -.. warning:: - On **Windows** VulnerableCode can **only** :ref:`run_with_docker` and is not supported. - Pre-installation Checklist ^^^^^^^^^^^^^^^^^^^^^^^^^^ From f8ab85d36cdc8890d64a01faaeddb862039a07bd Mon Sep 17 00:00:00 2001 From: Gunjan Sonawane Date: Wed, 7 Oct 2026 12:40:57 +0530 Subject: [PATCH 2/2] docs: address Windows Docker review feedback Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: Gunjan Sonawane --- docker-compose.windows.yml | 16 +++++++++++ docs/source/installation.rst | 51 +++++++++++------------------------- 2 files changed, 32 insertions(+), 35 deletions(-) create mode 100644 docker-compose.windows.yml diff --git a/docker-compose.windows.yml b/docker-compose.windows.yml new file mode 100644 index 000000000..40ceff45c --- /dev/null +++ b/docker-compose.windows.yml @@ -0,0 +1,16 @@ +services: + vulnerablecode: + volumes: + - .\vulnerablecode-config:/etc/vulnerablecode/ + + vulnerablecode_scheduler: + volumes: + - .\vulnerablecode-config:/etc/vulnerablecode/ + + vulnerablecode_rqworker: + volumes: + - .\vulnerablecode-config:/etc/vulnerablecode/ + + vulnerablecode_rqworker_high: + volumes: + - .\vulnerablecode-config:/etc/vulnerablecode/ diff --git a/docs/source/installation.rst b/docs/source/installation.rst index e67d73c43..ca7db3784 100644 --- a/docs/source/installation.rst +++ b/docs/source/installation.rst @@ -90,6 +90,7 @@ to run on a different port than 8000. .. tip:: Set ``STAGING=False`` in ``.env`` file to disable the staging environment warning. + Windows installation with Docker ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ @@ -101,46 +102,22 @@ Install and start Docker Desktop, then open PowerShell and clone the repository: git clone https://github.com/aboutcode-org/vulnerablecode.git cd vulnerablecode -Create the configuration directory and environment file using PowerShell. The -following commands generate secure values for both required settings:: +Create the configuration directory and an environment file using PowerShell. +Replace the example values below with your own strong, unique secrets. Do not +use the example values as-is:: New-Item -ItemType Directory -Force .\vulnerablecode-config - $secretKeyBytes = New-Object byte[] 50 - $rng = [System.Security.Cryptography.RandomNumberGenerator]::Create() - $rng.GetBytes($secretKeyBytes) - $secretKey = [Convert]::ToBase64String($secretKeyBytes) - - $altchaKeyBytes = New-Object byte[] 32 - $rng.GetBytes($altchaKeyBytes) - $altchaHmacKey = -join ($altchaKeyBytes | ForEach-Object { $_.ToString("x2") }) - $rng.Dispose() - @" - SECRET_KEY="$secretKey" - ALTCHA_HMAC_KEY="$altchaHmacKey" + SECRET_KEY=replace-with-a-strong-random-secret + ALTCHA_HMAC_KEY=replace-with-a-32-byte-hex-value "@ | Set-Content .\vulnerablecode-config\.env -Create ``docker-compose.override.yml`` with the configuration mount for the -application, scheduler, and both RQ workers:: - - services: - vulnerablecode: - volumes: - - .\vulnerablecode-config:/etc/vulnerablecode/ - vulnerablecode_scheduler: - volumes: - - .\vulnerablecode-config:/etc/vulnerablecode/ - vulnerablecode_rqworker: - volumes: - - .\vulnerablecode-config:/etc/vulnerablecode/ - vulnerablecode_rqworker_high: - volumes: - - .\vulnerablecode-config:/etc/vulnerablecode/ +The repository includes ``docker-compose.windows.yml`` to mount this configuration +directory into the application, scheduler, and RQ worker containers. Start and +check the services with:: -Start and check the services:: - - docker compose up -d - docker compose ps + docker compose -f docker-compose.yml -f docker-compose.windows.yml up -d + docker compose -f docker-compose.yml -f docker-compose.windows.yml ps VulnerableCode should then be available at:: @@ -148,7 +125,7 @@ VulnerableCode should then be available at:: To stop the services:: - docker compose down + docker compose -f docker-compose.yml -f docker-compose.windows.yml down .. _local_development_installation: @@ -163,6 +140,10 @@ Supported Platforms #. **Debian-based** Linux distributions #. **macOS** 12.1 and up +.. warning:: + Native Windows installation is not supported. Windows users can run + VulnerableCode with Docker Desktop; see :ref:`run_with_docker`. + Pre-installation Checklist ^^^^^^^^^^^^^^^^^^^^^^^^^^