Skip to content

fix(docker): suppress DL3025 for HEALTHCHECK via inline pragma - #28

Merged
amartingarcia merged 1 commit into
mainfrom
fix/hadolint-dl3025-healthcheck
Oct 1, 2026
Merged

amartingarcia merged 1 commit into
mainfrom
fix/hadolint-dl3025-healthcheck

Conversation

@amartingarcia

@amartingarcia amartingarcia commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Problema

hadolint 2.15.1 (empaquetado por hadolint-action v3.5.0, bump introducido en #27) empezó a detectar DL3025 en el CMD del HEALTHCHECK, pero deja de respetar la lista ignore: del .hadolint.yaml para este caso concreto (override ignore sale vacío en modo verbose pase lo que pase en el config).

El HEALTHCHECK usa forma shell intencionadamente (necesita || exit 1, no expresable en notación JSON/exec), así que no se puede "arreglar" pasando a forma JSON sin perder ese fallback.

Solución

Suprimir la regla con el pragma inline de hadolint justo encima de la instrucción, que sí es respetado de forma fiable independientemente del bug de parseo del config:

# hadolint ignore=DL3025
HEALTHCHECK --interval=30s --timeout=5s --start-period=30s --retries=3 \
  CMD curl -sf http://localhost:9033/ || exit 1

Verificado localmente con el binario de hadolint 2.15.1 (el mismo que usa hadolint-action@v3.5.0): exit 0.

Esto desbloquea #27, cuyo job Test falla en el paso Lint Dockerfile por este motivo.


Generated by Claude Code

hadolint 2.15.1 (bundled by hadolint-action v3.5.0, bumped in #27)
stopped honoring the top-level .hadolint.yaml ignore list for DL3025
on HEALTHCHECK CMD specifically (override ignore stays empty in
verbose output regardless of config). The HEALTHCHECK CMD uses shell
form intentionally (needs the || exit 1 fallback, not expressible in
JSON/exec form), so suppress the rule inline instead of depending on
the broken config-based ignore.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01D8MDhpdCqZCczobh8qoQBK
@amartingarcia
amartingarcia merged commit f3b23f0 into main Oct 1, 2026
7 checks passed
@amartingarcia
amartingarcia deleted the fix/hadolint-dl3025-healthcheck branch October 1, 2026 07:54
amartingarcia pushed a commit to devops-ia/steampipe that referenced this pull request Oct 1, 2026
Same issue as devops-ia/powerpipe#28: hadolint 2.15.1 (bundled by
hadolint-action v3.5.0, bumped in #30) stops honoring the top-level
.hadolint.yaml ignore list for DL3025 on HEALTHCHECK CMD specifically.
The HEALTHCHECK CMD uses shell form intentionally (needs the
|| exit 1 fallback, not expressible in JSON/exec form), so suppress
the rule inline instead of depending on the broken config-based ignore.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01D8MDhpdCqZCczobh8qoQBK
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants