Repository navigation
fix(docker): suppress DL3025 for HEALTHCHECK via inline pragma - #28
Merged
Merged
Conversation
hadolint 2.15.1 (bundled by hadolint-action v3.5.0, bumped in #27) stopped honoring the top-level .hadolint.yaml ignore list for DL3025 on HEALTHCHECK CMD specifically (override ignore stays empty in verbose output regardless of config). The HEALTHCHECK CMD uses shell form intentionally (needs the || exit 1 fallback, not expressible in JSON/exec form), so suppress the rule inline instead of depending on the broken config-based ignore. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01D8MDhpdCqZCczobh8qoQBK
amartingarcia
pushed a commit
to devops-ia/steampipe
that referenced
this pull request
Oct 1, 2026
Same issue as devops-ia/powerpipe#28: hadolint 2.15.1 (bundled by hadolint-action v3.5.0, bumped in #30) stops honoring the top-level .hadolint.yaml ignore list for DL3025 on HEALTHCHECK CMD specifically. The HEALTHCHECK CMD uses shell form intentionally (needs the || exit 1 fallback, not expressible in JSON/exec form), so suppress the rule inline instead of depending on the broken config-based ignore. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01D8MDhpdCqZCczobh8qoQBK
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problema
hadolint 2.15.1 (empaquetado por
hadolint-actionv3.5.0, bump introducido en #27) empezó a detectarDL3025en elCMDdelHEALTHCHECK, pero deja de respetar la listaignore:del.hadolint.yamlpara este caso concreto (override ignoresale vacío en modo verbose pase lo que pase en el config).El
HEALTHCHECKusa forma shell intencionadamente (necesita|| exit 1, no expresable en notación JSON/exec), así que no se puede "arreglar" pasando a forma JSON sin perder ese fallback.Solución
Suprimir la regla con el pragma inline de hadolint justo encima de la instrucción, que sí es respetado de forma fiable independientemente del bug de parseo del config:
Verificado localmente con el binario de hadolint 2.15.1 (el mismo que usa
hadolint-action@v3.5.0): exit 0.Esto desbloquea #27, cuyo job
Testfalla en el pasoLint Dockerfilepor este motivo.Generated by Claude Code