Repository navigation
sec: digest-pin Dockerfile.dev base image (closes #421) - #857
Conversation
|
Important Review skippedNo new commits to review since the last review. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
📝 WalkthroughWalkthrough
ChangesBase Image Digest Pinning
Estimated code review effort: 1 (Trivial) | ~2 minutes 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
|
@coderabbitai review |
✅ Action performedReview finished.
|
|
@coderabbitai full review Generated by Claude Code |
|
I'll kick off a full review of the PR right away. 🧠 Learnings used✅ Action performedFull review finished. |
|
@coderabbitai full review |
✅ Action performedFull review finished. |
|
@coderabbitai review |
✅ Action performedReview finished.
|
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@Dockerfile.dev`:
- Around line 1-4: The comment structure and digest refresh instructions in
Dockerfile.dev differ from the production Dockerfile. Update the comments above
the FROM statement to use the same format and approach as the production
Dockerfile, including aligning the refresh command from docker pull && docker
inspect to docker buildx imagetools inspect, and standardizing the security
context comments and Renovate/Dependabot guidance to match the production file's
structure for consistency across both Dockerfiles.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
|
@coderabbitai review |
✅ Action performedReview finished.
|
|
@coderabbitai review |
✅ Action performedReview finished.
|
|
@coderabbitai review |
|
Merge-prep: rebased onto origin/main (27fdb06), no conflicts. Non-Go PR; go vet on internal/... clean. @coderabbitai full review |
Align the digest-pin comment block with the production Dockerfile: explain the supply-chain rationale, use `docker buildx imagetools inspect` as the refresh command, reference Renovate/Dependabot, and note the digest must stay in sync with the builder stage.
|
@coderabbitai review |
✅ Action performedReview finished.
|
Summary
Dockerfile.devbase image togolang:1.25.4-alpine3.21@sha256:3289aac2aac769e031d644313d094dbda745f28af81cd7a94137e73eefd58b33DockerfileVerification
Digest resolved via
crane digest golang:1.25.4-alpine3.21(crane 0.21.5) on 2026-05-22.docker build -f Dockerfile.dev .was run locally against the pinned digest; Docker accepted the image reference without error (the digest matches the manifest for this tag on Docker Hub).Test plan
docker build -f Dockerfile.dev .completes without errorFROMline inDockerfile.devcontains the@sha256:suffixFROMlineSummary by CodeRabbit