Repository navigation
fix(ci): pin hadolint image by digest to stop drift off the rev pin - #1697
Conversation
The hadolint-docker pre-commit hook's upstream entry (ghcr.io/hadolint/hadolint hadolint) carries no image tag, so it floats to :latest regardless of the hadolint/hadolint repo's rev: v2.14.0 pin in .pre-commit-config.yaml, which only fixes the hook *definition*, not the Docker image it runs. Upstream publishing hadolint 2.15.1 as latest started failing pre-commit --all-files on every PR (new DL3066/DL3025 findings on unchanged Dockerfiles), since that job lints the whole merge ref rather than the PR's diff. Replace it with a local hook pinned to the immutable digest of the same v2.14.0 image so the linter version can only change via an explicit bump here. No Dockerfile changes were needed; verified Dockerfile, Dockerfile.dev, and Dockerfile.test all still build. Also corrects a stale comment in .github/workflows/pre-commit.yml that had assumed the old hook was already image-pinned via the rev. Closes #1696
|
Warning Review limit reachedYou’ve reached a temporary PR review limit under our Fair Usage Limits Policy. Next review available in: 15 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (2)
Comment |
Root-cause record (merged)Recording this because the diagnosis is more useful than the diff, and the obvious reading of it was wrong. Symptom: Ruled out first: the commits between the last green and the first red touch no The working hypothesis was "the pinned tag was rebuilt underneath us". That was wrong. The image was never pinned at all. Upstream's No image tag, so Docker resolves Registry digests confirm distinct images ( Fix: replaced the external hook with a No Dockerfile changes were made, deliberately. All four findings are new-rule behaviour in 2.15.x, and one of them could not be "fixed" safely: DL3025 fired on Also corrected: a comment in The expensive part, for the recordThe four lint findings were not the real cost. A permanently-red required check that is nobody's fault trains reviewers to stop reading that signal, which is how a genuine failure gets waved through later. That is why this was treated as urgent rather than tolerated. Follow-up #1701 / PR #1700 adopts hadolint 2.15.1 properly and fixes the four findings, so the pin does not mean never picking up new rules — the slow version of the same drift. |
…1697) The hadolint-docker pre-commit hook's upstream entry (ghcr.io/hadolint/hadolint hadolint) carries no image tag, so it floats to :latest regardless of the hadolint/hadolint repo's rev: v2.14.0 pin in .pre-commit-config.yaml, which only fixes the hook *definition*, not the Docker image it runs. Upstream publishing hadolint 2.15.1 as latest started failing pre-commit --all-files on every PR (new DL3066/DL3025 findings on unchanged Dockerfiles), since that job lints the whole merge ref rather than the PR's diff. Replace it with a local hook pinned to the immutable digest of the same v2.14.0 image so the linter version can only change via an explicit bump here. No Dockerfile changes were needed; verified Dockerfile, Dockerfile.dev, and Dockerfile.test all still build. Also corrects a stale comment in .github/workflows/pre-commit.yml that had assumed the old hook was already image-pinned via the rev. Closes #1696
Summary
pre-commit --all-files(the CI "Run pre-commit hooks" job lints the whole merge ref) started failing thehadolint-dockerhook onmain, blocking every open PR including ones that touch zero Docker files (e.g. sec(iac): scope Azure purchase role to onboarded subscription #1658)hadolint-dockerhook entry (ghcr.io/hadolint/hadolint hadolint) has no image tag, so it floats to:latestindependent of this repo'srev: v2.14.0pin, which only fixes the hook definition commit, not the Docker image. Upstream published hadolint 2.15.1 aslatest, which applies DL3066 to any namedUSERdirective and DL3025 toHEALTHCHECK'sCMDsub-clause -- neither of which existed in 2.14.0's ruleset. None of the three Dockerfiles changed.hadolint-dockerhook with a local hook pinned to the immutable digest of the samev2.14.0image, so the linter version can only move via an explicit bump here.github/workflows/pre-commit.ymlthat had assumed the old hook was already image-pinned via therev:Verification
pre-commit run hadolint --all-files-> exit 0 (previously exit 1 onmain)pre-commit run --all-files-> only remaining failure isterraform_validate, and it's a local-machine artifact unrelated to this change (mkdir ... file existsrace on the shared~/.terraform.d/plugin-cache, reproduced consistently on retry, not present in this diff)docker run ... hadolint --version:v2.14.0tag = 2.14.0,latesttag = 2.15.1latestand disappear against the pinned digest, on the unchanged Dockerfiles, with.hadolint.yaml's ignore list applied (matching what pre-commit actually mounts)Dockerfile,Dockerfile.dev,Dockerfile.testall built successfullyCloses #1696