Skip to content

fix(container): resolve hadolint findings and align hadolint/Dependabot pinning - #41

Merged
KevinTCoughlin merged 2 commits into
mainfrom
claude/next-steps-e78raf
Aug 9, 2026
Merged

KevinTCoughlin merged 2 commits into
mainfrom
claude/next-steps-e78raf

Conversation

@KevinTCoughlin

@KevinTCoughlin KevinTCoughlin commented Aug 9, 2026 •

Copy link
Copy Markdown
Owner

Description

hadolint/hadolint-action 3.4.0 ships a newer hadolint binary (2.14.0 → 2.15.0) that flags two findings in Containerfile, turning the Lint job red on the pending action bump in #40. Both findings are latent in the repo rather than caused by Dependabot — just lint ran hadolint/hadolint:latest and would have hit them too as soon as that image refreshed.

This fixes the findings at the source, lands the action bump, and closes the two gaps that let the situation arise: local and CI running different hadolint versions, and Dependabot opening PRs that only narrow deliberate major-tag pins.

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Documentation update
  • Configuration change
  • Infrastructure/CI update

Related Issues

Supersedes #40 — this PR contains that action bump, so Dependabot will close it automatically once the version reaches main.
Makes #39 unnecessary — the new ignore rule stops github/codeql-action pin-narrowing PRs; #39 can be closed.

Changes Made

Containerfile — the two hadolint findings

  • DL3066 — useradd -r picked an arbitrary system uid at build time and USER hlds referenced it by name. The user is now created with an explicit uid/gid (groupadd --system --gid 10001 + useradd --system --uid 10001 --gid 10001) and USER is numeric (10001:10001). Beyond satisfying the rule, this makes bind-mount ownership deterministic under rootless Podman instead of varying with whatever uid a given build happened to get.
  • DL3025 — the HEALTHCHECK CMD was shell-form. The check needs a shell for the /proc/[0-9]* glob and the || exit 1, so it becomes exec-form ["/bin/sh", "-c", "..."] rather than dropping the shell.

ci.yml / justfile — keeping local and CI on one ruleset

  • Bumped hadolint/hadolint-action v3.3.0 → v3.4.0 (the bump proposed in Bump hadolint/hadolint-action from 3.3.0 to 3.4.0 #40).
  • just lint now pins ghcr.io/hadolint/hadolint:v2.15.0-debian — the exact image v3.4.0 bundles — instead of tracking :latest. A future hadolint release can no longer turn CI red without just check catching it first. The two pins are coupled by a comment in the justfile; nothing enforces it automatically, since Dependabot's docker ecosystem scans Dockerfiles and won't see a justfile.

dependabot.yml — stop pin-narrowing PRs

  • Ignore minor/patch updates for actions/*, docker/* and github/codeql-action, all of which are pinned at the major tag on purpose. Actions pinned exactly (hadolint-action, action-shellcheck, trivy-action, sbom-action — the last two necessarily, being 0.x) still get the full range of updates.

Testing Performed

  • Container builds successfully: just build
  • Lint checks pass: just check
  • Server starts and is joinable: just up
  • Manual testing performed (describe below)

Manual Testing:

  • Ran hadolint 2.15.1 directly against the modified Containerfile — exits 0 with no findings (it previously reported DL3066 at the USER line and DL3025 at the HEALTHCHECK).
  • justfile parses under just 1.58.0; just --dry-run lint renders podman run --rm -i ghcr.io/hadolint/hadolint:v2.15.0-debian < Containerfile, and that tag resolves on ghcr.io (manifest HTTP 200).
  • dependabot.yml and ci.yml parse as YAML; GitHub's own .github/dependabot.yml check passed on this PR, so the ignore syntax is accepted.

No container runtime was available in the environment where this was prepared, so just build and just up were not run — the build-and-scan job on this PR does a real image build and covers the former. The uid change affects ownership of /hlds and /home/hlds, which is the one thing a build exercises that lint does not, so that job going green is the check that matters here. Server joinability is unverified.

Checklist

  • I have performed a self-review of my own changes
  • I have tested that the server starts and accepts connections
  • I have updated documentation if needed
  • My changes generate no new warnings during build

hadolint-action 3.4.0 ships a newer hadolint that flags two findings in
the Containerfile, turning the Lint job red on the pending bump (#40):

- DL3066: `USER hlds` is non-numeric and `useradd -r` picks an arbitrary
  system uid at build time. Create the user with an explicit uid/gid
  (10001) and reference it numerically in USER. Beyond satisfying the
  rule, this makes bind-mount ownership deterministic under rootless
  Podman instead of varying with whatever uid the build happened to get.
- DL3025: the HEALTHCHECK CMD was shell-form. The check needs a shell for
  the glob and `||`, so it becomes exec-form `/bin/sh -c "..."`.

Verified clean against hadolint 2.15.1.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VprdNaZ8s9F63tqzxhy5Ng
Copilot AI lite review requested due to automatic review settings August 9, 2026 07:04

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This pull request updates the container build to satisfy newer hadolint checks by making the runtime user identity deterministic and converting the HEALTHCHECK to exec/JSON form, keeping CI lint green for the upcoming hadolint-action bump.

Changes:

  • Pin the hlds runtime user/group to a fixed UID/GID (10001) and switch USER to numeric form (10001:10001).
  • Convert HEALTHCHECK CMD from shell-form to exec/JSON form using /bin/sh -c to preserve globbing and || exit 1.
  • Record both changes under CHANGELOG.md → [Unreleased] → Changed.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.

File Description
Containerfile Pins hlds UID/GID and updates USER + HEALTHCHECK to satisfy hadolint findings (DL3066, DL3025).
CHANGELOG.md Documents the UID/GID pinning and HEALTHCHECK exec-form conversion under Unreleased changes.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Follow-ups to the hadolint fix in the previous commit:

- Bump hadolint/hadolint-action v3.3.0 -> v3.4.0 in ci.yml. This is the
  bump Dependabot proposed in #40; landing it here supersedes that PR,
  which Dependabot closes automatically once the version reaches main.
- Pin `just lint` to ghcr.io/hadolint/hadolint:v2.15.0-debian, the exact
  image v3.4.0 bundles, instead of tracking :latest. Local linting and
  CI now share a ruleset, so a hadolint release can no longer turn CI
  red without `just check` catching it first.
- Ignore minor/patch Dependabot updates for actions/*, docker/* and
  github/codeql-action. Those are pinned at the major tag deliberately,
  so PRs like #39 (codeql-action v4 -> v4.37.4) only narrow the pin.
  Exactly-pinned actions (hadolint, shellcheck, trivy, sbom-action)
  still get the full range of updates.

Verified: justfile parses under just 1.58.0 and the lint recipe renders
the pinned image; the v2.15.0-debian tag resolves on ghcr.io; both YAML
files parse.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VprdNaZ8s9F63tqzxhy5Ng
Copilot AI review requested due to automatic review settings August 9, 2026 07:09
@KevinTCoughlin KevinTCoughlin changed the title fix(container): pin hlds uid/gid and JSON-form HEALTHCHECK fix(container): resolve hadolint findings and align hadolint/Dependabot pinning Aug 9, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 5 out of 5 changed files in this pull request and generated no new comments.

@KevinTCoughlin
KevinTCoughlin marked this pull request as ready for review August 9, 2026 07:46
@KevinTCoughlin
KevinTCoughlin merged commit 4389043 into main Aug 9, 2026
5 checks passed
@KevinTCoughlin
KevinTCoughlin deleted the claude/next-steps-e78raf branch August 9, 2026 18:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants