Skip to content

Commit e1e1004

Browse files
committed
sec: digest-pin Dockerfile.dev base image (closes #421)
Align the digest-pin comment block with the production Dockerfile: explain the supply-chain rationale, use `docker buildx imagetools inspect` as the refresh command, reference Renovate/Dependabot, and note the digest must stay in sync with the builder stage.
1 parent 8f9347e commit e1e1004

1 file changed

Lines changed: 7 additions & 3 deletions

File tree

‎Dockerfile.dev‎

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,11 @@
11
# Development Dockerfile with hot reload using Air
2-
# TODO: Pin to SHA256 digest for reproducible builds:
3-
# docker buildx imagetools inspect golang:1.26.5-alpine3.24
4-
FROM golang:1.26.5-alpine3.24 AS development
2+
# Image pinned to a SHA256 digest for reproducible builds; a registry
3+
# tag mutation (Docker Hub allows re-tagging) cannot poison this build.
4+
# To refresh: `docker buildx imagetools inspect golang:1.26.5-alpine3.24`
5+
# (or use the Docker Hub API tags endpoint) and update the digest below.
6+
# A Renovate / Dependabot config can automate this if desired.
7+
# Keep this digest in sync with the builder stage in Dockerfile.
8+
FROM golang:1.26.5-alpine3.24@sha256:0178a641fbb4858c5f1b48e34bdaabe0350a330a1b1149aabd498d0699ff5fb2 AS development
59

610
# Install development tools and Air for hot reload
711
RUN apk add --no-cache \

0 commit comments

Comments
 (0)