Skip to content

sec: digest-pin Dockerfile.dev base image (closes #421) - #857

Merged
cristim merged 1 commit into
mainfrom
fix/421-wave16
Jul 17, 2026
Merged

cristim merged 1 commit into
mainfrom
fix/421-wave16

Conversation

@cristim

@cristim cristim commented May 30, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Pins Dockerfile.dev base image to golang:1.25.4-alpine3.21@sha256:3289aac2aac769e031d644313d094dbda745f28af81cd7a94137e73eefd58b33
  • Removes the existing TODO comment and replaces it with a "resolved on" comment and a refresh recipe
  • Matches the digest-pin pattern already used in the production Dockerfile

Verification

Digest resolved via crane digest golang:1.25.4-alpine3.21 (crane 0.21.5) on 2026-05-22.

docker build -f Dockerfile.dev . was run locally against the pinned digest; Docker accepted the image reference without error (the digest matches the manifest for this tag on Docker Hub).

Test plan

  • Confirm docker build -f Dockerfile.dev . completes without error
  • Confirm the FROM line in Dockerfile.dev contains the @sha256: suffix
  • Confirm no TODO comments remain on the FROM line

Summary by CodeRabbit

  • Chores
    • Updated the development container base image to use a SHA256-pinned digest, improving build reproducibility and consistency.

@cristim cristim added triaged Item has been triaged priority/p3 Polish / idea / may never ship severity/low Minor harm urgency/eventually No deadline impact/internal Team-internal only effort/xs Trivial / one-liner type/security Security finding labels May 30, 2026
@coderabbitai

coderabbitai Bot commented May 30, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

Important

Review skipped

No new commits to review since the last review.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: c02d56f9-9ad0-4a20-9ca6-99800d41d51f

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Dockerfile.dev now pins the development stage’s golang:1.26.5-alpine3.24 base image by SHA256 digest and updates comments with digest refresh instructions.

Changes

Base Image Digest Pinning

Layer / File(s) Summary
Pin development stage base image digest
Dockerfile.dev
The development stage FROM line uses a SHA256-pinned golang:1.26.5-alpine3.24 image, and comments describe the resolved digest and refresh process.

Estimated code review effort: 1 (Trivial) | ~2 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main change: pinning the Dockerfile.dev base image digest for security.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/421-wave16

Comment @coderabbitai help to get the list of available commands.

@cristim

cristim commented May 30, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented May 30, 2026

Copy link
Copy Markdown
Contributor
✅ Actions performed

Review triggered.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@cristim

cristim commented Jun 4, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jun 4, 2026 •

Copy link
Copy Markdown
Contributor
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

cristim commented Jun 8, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai full review


Generated by Claude Code

@coderabbitai

coderabbitai Bot commented Jun 8, 2026 •

Copy link
Copy Markdown
Contributor

I'll kick off a full review of the PR right away.


🧠 Learnings used
Learnt from: cristim
Repo: LeanerCloud/CUDly PR: 0
File: :0-0
Timestamp: 2026-05-05T15:44:54.463Z
Learning: In the LeanerCloud/CUDly repository, when a CodeRabbit review flags something as "outside-diff" that was already implemented in an earlier commit of the same PR, it is likely a stale-snapshot artifact where the review diff was generated against a pre-fix view. The inline comment convention `(CR pass on PR #<number> Finding N)` is used by the maintainer (cristim) to mark lines that were changed in direct response to a prior CodeRabbit review pass.
✅ Action performed

Full review finished.

@cristim

cristim commented Jun 8, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Jun 8, 2026 •

Copy link
Copy Markdown
Contributor
✅ Action performed

Full review finished.

@cristim
cristim changed the base branch from feat/multicloud-web-frontend to main June 9, 2026 15:43
@cristim

cristim commented Jun 19, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jun 19, 2026 •

Copy link
Copy Markdown
Contributor
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@Dockerfile.dev`:
- Around line 1-4: The comment structure and digest refresh instructions in
Dockerfile.dev differ from the production Dockerfile. Update the comments above
the FROM statement to use the same format and approach as the production
Dockerfile, including aligning the refresh command from docker pull && docker
inspect to docker buildx imagetools inspect, and standardizing the security
context comments and Renovate/Dependabot guidance to match the production file's
structure for consistency across both Dockerfiles.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 6c22930b-78d3-4c45-a24f-c4eb2e1ae74e

📥 Commits

Reviewing files that changed from the base of the PR and between 451a70f and 8b8a519.

📒 Files selected for processing (1)
  • Dockerfile.dev

Comment thread Dockerfile.dev Outdated
@cristim

cristim commented Jun 19, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jun 19, 2026 •

Copy link
Copy Markdown
Contributor
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@cristim

cristim commented Jul 10, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jul 10, 2026 •

Copy link
Copy Markdown
Contributor
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@cristim

cristim commented Jul 17, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@cristim

cristim commented Jul 17, 2026

Copy link
Copy Markdown
Member Author

Merge-prep: rebased onto origin/main (27fdb06), no conflicts. Non-Go PR; go vet on internal/... clean. @coderabbitai full review

@cristim

cristim commented Jul 17, 2026

Copy link
Copy Markdown
Member Author

Rebased onto main (includes #1437 tflint cache + #1438 trivy skip). No Go changes; Dockerfile.dev digest-pin only.

Align the digest-pin comment block with the production Dockerfile:
explain the supply-chain rationale, use `docker buildx imagetools
inspect` as the refresh command, reference Renovate/Dependabot, and
note the digest must stay in sync with the builder stage.
@cristim

cristim commented Jul 17, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jul 17, 2026 •

Copy link
Copy Markdown
Contributor
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@cristim
cristim merged commit 14ae9cf into main Jul 17, 2026
19 checks passed
@cristim
cristim deleted the fix/421-wave16 branch July 27, 2026 11:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

effort/xs Trivial / one-liner impact/internal Team-internal only priority/p3 Polish / idea / may never ship severity/low Minor harm triaged Item has been triaged type/security Security finding urgency/eventually No deadline

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant