From e1e1004f676e1d7ca6989c65005d53ec79c8b41c Mon Sep 17 00:00:00 2001 From: Cristian Magherusan-Stanciu Date: Sat, 30 May 2026 19:05:40 +0200 Subject: [PATCH] sec: digest-pin Dockerfile.dev base image (closes #421) Align the digest-pin comment block with the production Dockerfile: explain the supply-chain rationale, use `docker buildx imagetools inspect` as the refresh command, reference Renovate/Dependabot, and note the digest must stay in sync with the builder stage. --- Dockerfile.dev | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/Dockerfile.dev b/Dockerfile.dev index df8077b3e..22528951e 100644 --- a/Dockerfile.dev +++ b/Dockerfile.dev @@ -1,7 +1,11 @@ # Development Dockerfile with hot reload using Air -# TODO: Pin to SHA256 digest for reproducible builds: -# docker buildx imagetools inspect golang:1.26.5-alpine3.24 -FROM golang:1.26.5-alpine3.24 AS development +# Image pinned to a SHA256 digest for reproducible builds; a registry +# tag mutation (Docker Hub allows re-tagging) cannot poison this build. +# To refresh: `docker buildx imagetools inspect golang:1.26.5-alpine3.24` +# (or use the Docker Hub API tags endpoint) and update the digest below. +# A Renovate / Dependabot config can automate this if desired. +# Keep this digest in sync with the builder stage in Dockerfile. +FROM golang:1.26.5-alpine3.24@sha256:0178a641fbb4858c5f1b48e34bdaabe0350a330a1b1149aabd498d0699ff5fb2 AS development # Install development tools and Air for hot reload RUN apk add --no-cache \