From 1a9f8e2d48def3271c8a4f71a3d7178d1794766e Mon Sep 17 00:00:00 2001 From: Cristian Magherusan-Stanciu Date: Mon, 3 Aug 2026 14:37:23 +0200 Subject: [PATCH] fix(ci): pin hadolint image by digest to stop drift off the rev pin The hadolint-docker pre-commit hook's upstream entry (ghcr.io/hadolint/hadolint hadolint) carries no image tag, so it floats to :latest regardless of the hadolint/hadolint repo's rev: v2.14.0 pin in .pre-commit-config.yaml, which only fixes the hook *definition*, not the Docker image it runs. Upstream publishing hadolint 2.15.1 as latest started failing pre-commit --all-files on every PR (new DL3066/DL3025 findings on unchanged Dockerfiles), since that job lints the whole merge ref rather than the PR's diff. Replace it with a local hook pinned to the immutable digest of the same v2.14.0 image so the linter version can only change via an explicit bump here. No Dockerfile changes were needed; verified Dockerfile, Dockerfile.dev, and Dockerfile.test all still build. Also corrects a stale comment in .github/workflows/pre-commit.yml that had assumed the old hook was already image-pinned via the rev. Closes #1696 --- .github/workflows/pre-commit.yml | 18 +++++++++++------- .pre-commit-config.yaml | 21 ++++++++++++++++++--- 2 files changed, 29 insertions(+), 10 deletions(-) diff --git a/.github/workflows/pre-commit.yml b/.github/workflows/pre-commit.yml index be83eb6f4..eed395c60 100644 --- a/.github/workflows/pre-commit.yml +++ b/.github/workflows/pre-commit.yml @@ -182,13 +182,17 @@ jobs: exit 1 } - # Note: the hadolint-docker pre-commit hook - # (.pre-commit-config.yaml:80) runs the official - # hadolint/hadolint:v2.14.0 Docker image. We do NOT install a host - # binary here — it would be dead code (never invoked by the hook) - # AND a supply-chain hole (latest tag, no checksum). If a future - # change switches the hook from hadolint-docker to plain hadolint, - # install a pinned + sha256-verified binary here. + # Note: the local `hadolint` pre-commit hook (.pre-commit-config.yaml:81) + # runs ghcr.io/hadolint/hadolint pinned by digest to v2.14.0. We do NOT + # install a host binary here — it would be dead code (never invoked by + # the hook) AND a supply-chain hole (latest tag, no checksum). Note: + # an earlier version of this comment claimed the hook already pinned + # the image to v2.14.0 via the hook repo's `rev:` -- it did not; that + # `rev:` only pins hadolint's *hook definition*, whose upstream entry + # (`ghcr.io/hadolint/hadolint hadolint`) has no image tag and floats to + # `:latest`. See the digest pin in .pre-commit-config.yaml for the fix. + # If a future change switches the hook to a host binary, install a + # pinned + sha256-verified binary here. - name: Install pre-commit run: pip install 'pre-commit==4.0.1' diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index b24477857..c37ad9873 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -63,11 +63,26 @@ repos: name: Check for case conflicts # Dockerfile linting - - repo: https://github.com/hadolint/hadolint - rev: v2.14.0 + # + # The upstream hadolint-docker hook (hadolint/hadolint's own + # .pre-commit-hooks.yaml) declares `entry: ghcr.io/hadolint/hadolint + # hadolint` with no image tag, so Docker resolves it to `:latest` on every + # run -- independent of the `rev:` pin above, which only pins which + # commit of the *hook definition* is used, not the Docker image it runs. + # When upstream published hadolint 2.15.1 as `latest`, CI silently + # started linting with a newer ruleset (new DL3066/DL3025 findings on + # unchanged Dockerfiles) with no corresponding change in this repo. + # + # Defined as a local hook instead, pinned to the immutable digest of the + # v2.14.0 image, so the linter version can only change via an explicit + # bump here. + - repo: local hooks: - - id: hadolint-docker + - id: hadolint name: Lint Dockerfiles + language: docker_image + entry: ghcr.io/hadolint/hadolint:v2.14.0@sha256:27086352fd5e1907ea2b934eb1023f217c5ae087992eb59fde121dce9c9ff21e hadolint + types: [dockerfile] # Markdown linting - repo: https://github.com/igorshubovych/markdownlint-cli