fix(container): resolve hadolint findings and align hadolint/Dependabot pinning - #41
Merged
Merged
Conversation
hadolint-action 3.4.0 ships a newer hadolint that flags two findings in the Containerfile, turning the Lint job red on the pending bump (#40): - DL3066: `USER hlds` is non-numeric and `useradd -r` picks an arbitrary system uid at build time. Create the user with an explicit uid/gid (10001) and reference it numerically in USER. Beyond satisfying the rule, this makes bind-mount ownership deterministic under rootless Podman instead of varying with whatever uid the build happened to get. - DL3025: the HEALTHCHECK CMD was shell-form. The check needs a shell for the glob and `||`, so it becomes exec-form `/bin/sh -c "..."`. Verified clean against hadolint 2.15.1. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01VprdNaZ8s9F63tqzxhy5Ng
Contributor
There was a problem hiding this comment.
Pull request overview
This pull request updates the container build to satisfy newer hadolint checks by making the runtime user identity deterministic and converting the HEALTHCHECK to exec/JSON form, keeping CI lint green for the upcoming hadolint-action bump.
Changes:
- Pin the
hldsruntime user/group to a fixed UID/GID (10001) and switchUSERto numeric form (10001:10001). - Convert
HEALTHCHECK CMDfrom shell-form to exec/JSON form using/bin/sh -cto preserve globbing and|| exit 1. - Record both changes under
CHANGELOG.md→[Unreleased]→Changed.
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
| Containerfile | Pins hlds UID/GID and updates USER + HEALTHCHECK to satisfy hadolint findings (DL3066, DL3025). |
| CHANGELOG.md | Documents the UID/GID pinning and HEALTHCHECK exec-form conversion under Unreleased changes. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Follow-ups to the hadolint fix in the previous commit: - Bump hadolint/hadolint-action v3.3.0 -> v3.4.0 in ci.yml. This is the bump Dependabot proposed in #40; landing it here supersedes that PR, which Dependabot closes automatically once the version reaches main. - Pin `just lint` to ghcr.io/hadolint/hadolint:v2.15.0-debian, the exact image v3.4.0 bundles, instead of tracking :latest. Local linting and CI now share a ruleset, so a hadolint release can no longer turn CI red without `just check` catching it first. - Ignore minor/patch Dependabot updates for actions/*, docker/* and github/codeql-action. Those are pinned at the major tag deliberately, so PRs like #39 (codeql-action v4 -> v4.37.4) only narrow the pin. Exactly-pinned actions (hadolint, shellcheck, trivy, sbom-action) still get the full range of updates. Verified: justfile parses under just 1.58.0 and the lint recipe renders the pinned image; the v2.15.0-debian tag resolves on ghcr.io; both YAML files parse. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01VprdNaZ8s9F63tqzxhy5Ng
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
hadolint/hadolint-action3.4.0 ships a newer hadolint binary (2.14.0 → 2.15.0) that flags two findings inContainerfile, turning the Lint job red on the pending action bump in #40. Both findings are latent in the repo rather than caused by Dependabot —just lintranhadolint/hadolint:latestand would have hit them too as soon as that image refreshed.This fixes the findings at the source, lands the action bump, and closes the two gaps that let the situation arise: local and CI running different hadolint versions, and Dependabot opening PRs that only narrow deliberate major-tag pins.
Type of Change
Related Issues
Supersedes #40 — this PR contains that action bump, so Dependabot will close it automatically once the version reaches
main.Makes #39 unnecessary — the new ignore rule stops
github/codeql-actionpin-narrowing PRs; #39 can be closed.Changes Made
Containerfile— the two hadolint findingsDL3066—useradd -rpicked an arbitrary system uid at build time andUSER hldsreferenced it by name. The user is now created with an explicit uid/gid (groupadd --system --gid 10001+useradd --system --uid 10001 --gid 10001) andUSERis numeric (10001:10001). Beyond satisfying the rule, this makes bind-mount ownership deterministic under rootless Podman instead of varying with whatever uid a given build happened to get.DL3025— theHEALTHCHECKCMDwas shell-form. The check needs a shell for the/proc/[0-9]*glob and the|| exit 1, so it becomes exec-form["/bin/sh", "-c", "..."]rather than dropping the shell.ci.yml/justfile— keeping local and CI on one rulesethadolint/hadolint-actionv3.3.0 → v3.4.0 (the bump proposed in Bump hadolint/hadolint-action from 3.3.0 to 3.4.0 #40).just lintnow pinsghcr.io/hadolint/hadolint:v2.15.0-debian— the exact image v3.4.0 bundles — instead of tracking:latest. A future hadolint release can no longer turn CI red withoutjust checkcatching it first. The two pins are coupled by a comment in thejustfile; nothing enforces it automatically, since Dependabot's docker ecosystem scans Dockerfiles and won't see ajustfile.dependabot.yml— stop pin-narrowing PRsactions/*,docker/*andgithub/codeql-action, all of which are pinned at the major tag on purpose. Actions pinned exactly (hadolint-action,action-shellcheck,trivy-action,sbom-action— the last two necessarily, being 0.x) still get the full range of updates.Testing Performed
just buildjust checkjust upManual Testing:
Containerfile— exits 0 with no findings (it previously reportedDL3066at theUSERline andDL3025at theHEALTHCHECK).justfileparses under just 1.58.0;just --dry-run lintrenderspodman run --rm -i ghcr.io/hadolint/hadolint:v2.15.0-debian < Containerfile, and that tag resolves on ghcr.io (manifest HTTP 200).dependabot.ymlandci.ymlparse as YAML; GitHub's own.github/dependabot.ymlcheck passed on this PR, so the ignore syntax is accepted.No container runtime was available in the environment where this was prepared, so
just buildandjust upwere not run — thebuild-and-scanjob on this PR does a real image build and covers the former. The uid change affects ownership of/hldsand/home/hlds, which is the one thing a build exercises that lint does not, so that job going green is the check that matters here. Server joinability is unverified.Checklist