Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 11 additions & 7 deletions .github/workflows/pre-commit.yml
Original file line number Diff line number Diff line change
Expand Up @@ -182,13 +182,17 @@ jobs:
exit 1
}

# Note: the hadolint-docker pre-commit hook
# (.pre-commit-config.yaml:80) runs the official
# hadolint/hadolint:v2.14.0 Docker image. We do NOT install a host
# binary here — it would be dead code (never invoked by the hook)
# AND a supply-chain hole (latest tag, no checksum). If a future
# change switches the hook from hadolint-docker to plain hadolint,
# install a pinned + sha256-verified binary here.
# Note: the local `hadolint` pre-commit hook (.pre-commit-config.yaml:81)
# runs ghcr.io/hadolint/hadolint pinned by digest to v2.14.0. We do NOT
# install a host binary here — it would be dead code (never invoked by
# the hook) AND a supply-chain hole (latest tag, no checksum). Note:
# an earlier version of this comment claimed the hook already pinned
# the image to v2.14.0 via the hook repo's `rev:` -- it did not; that
# `rev:` only pins hadolint's *hook definition*, whose upstream entry
# (`ghcr.io/hadolint/hadolint hadolint`) has no image tag and floats to
# `:latest`. See the digest pin in .pre-commit-config.yaml for the fix.
# If a future change switches the hook to a host binary, install a
# pinned + sha256-verified binary here.

- name: Install pre-commit
run: pip install 'pre-commit==4.0.1'
Expand Down
21 changes: 18 additions & 3 deletions .pre-commit-config.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -63,11 +63,26 @@ repos:
name: Check for case conflicts

# Dockerfile linting
- repo: https://github.com/hadolint/hadolint
rev: v2.14.0
#
# The upstream hadolint-docker hook (hadolint/hadolint's own
# .pre-commit-hooks.yaml) declares `entry: ghcr.io/hadolint/hadolint
# hadolint` with no image tag, so Docker resolves it to `:latest` on every
# run -- independent of the `rev:` pin above, which only pins which
# commit of the *hook definition* is used, not the Docker image it runs.
# When upstream published hadolint 2.15.1 as `latest`, CI silently
# started linting with a newer ruleset (new DL3066/DL3025 findings on
# unchanged Dockerfiles) with no corresponding change in this repo.
#
# Defined as a local hook instead, pinned to the immutable digest of the
# v2.14.0 image, so the linter version can only change via an explicit
# bump here.
- repo: local
hooks:
- id: hadolint-docker
- id: hadolint
name: Lint Dockerfiles
language: docker_image
entry: ghcr.io/hadolint/hadolint:v2.14.0@sha256:27086352fd5e1907ea2b934eb1023f217c5ae087992eb59fde121dce9c9ff21e hadolint
types: [dockerfile]

# Markdown linting
- repo: https://github.com/igorshubovych/markdownlint-cli
Expand Down
Loading