diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 6b82d5d..587d57b 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -9,6 +9,23 @@ updates: labels: - "dependencies" - "github-actions" + # actions/*, docker/* and github/codeql-action are pinned at the major tag + # on purpose, so minor/patch PRs against them only narrow the pin. Actions + # pinned exactly (hadolint, shellcheck, trivy, sbom-action) still get the + # full range of updates. + ignore: + - dependency-name: "actions/*" + update-types: + - "version-update:semver-minor" + - "version-update:semver-patch" + - dependency-name: "docker/*" + update-types: + - "version-update:semver-minor" + - "version-update:semver-patch" + - dependency-name: "github/codeql-action" + update-types: + - "version-update:semver-minor" + - "version-update:semver-patch" - package-ecosystem: "docker" directory: "/" diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index b244d55..c1d7ef5 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -19,7 +19,7 @@ jobs: - uses: actions/checkout@v7 - name: Lint Containerfile with hadolint - uses: hadolint/hadolint-action@v3.3.0 + uses: hadolint/hadolint-action@v3.4.0 with: dockerfile: Containerfile diff --git a/CHANGELOG.md b/CHANGELOG.md index 679ec01..f05daf0 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -3,6 +3,11 @@ ## [Unreleased] ### Changed +- `hlds` user is now created with a fixed uid/gid (10001) and `USER` references it numerically, making bind-mount ownership deterministic under rootless Podman and resolving hadolint `DL3066` +- `HEALTHCHECK` `CMD` converted to JSON/exec notation (`/bin/sh -c ...`), resolving hadolint `DL3025` +- Bumped `hadolint/hadolint-action` in `ci.yml` from v3.3.0 to v3.4.0 (hadolint 2.14.0 → 2.15.0) +- `just lint` pins `ghcr.io/hadolint/hadolint:v2.15.0-debian` instead of tracking `:latest`, so local linting and CI run the same ruleset +- Dependabot no longer opens minor/patch PRs for `actions/*`, `docker/*` and `github/codeql-action`, which are pinned at the major tag on purpose - Bumped AMX Mod X pin from build 5478 to 5479 - Bumped shellcheck pin in `ci.yml` from v0.10.0 to v0.11.0 - README stack list resynced to the versions actually pinned in the Containerfile (ReHLDS 3.15.0.896, ReGameDLL_CS 5.30.0.814, ReAPI 5.29.0.358, AMX Mod X build 5479) diff --git a/Containerfile b/Containerfile index 83dd06d..5c5cd31 100644 --- a/Containerfile +++ b/Containerfile @@ -187,7 +187,9 @@ RUN dpkg --add-architecture i386 && \ /var/tmp/* \ && (find / -xdev -perm /6000 -type f -exec chmod a-s {} + 2>/dev/null || true) -RUN useradd --no-log-init -r -s /usr/sbin/nologin hlds +# Fixed uid/gid so bind-mount ownership is deterministic under rootless Podman +RUN groupadd --system --gid 10001 hlds && \ + useradd --no-log-init --system --uid 10001 --gid 10001 -s /usr/sbin/nologin hlds COPY --from=builder --chown=hlds:hlds /hlds /hlds COPY --chmod=755 entrypoint.sh /entrypoint.sh @@ -203,12 +205,12 @@ LABEL org.opencontainers.image.title="CS 1.6 ScoutzKnivez Server" \ org.opencontainers.image.licenses="MIT" \ org.opencontainers.image.vendor="KevinTCoughlin" -USER hlds +USER 10001:10001 WORKDIR /hlds EXPOSE 27015/udp 27015/tcp HEALTHCHECK --interval=30s --timeout=5s --start-period=60s --retries=3 \ - CMD grep -qs hlds_linux /proc/[0-9]*/comm || exit 1 + CMD ["/bin/sh", "-c", "grep -qs hlds_linux /proc/[0-9]*/comm || exit 1"] ENTRYPOINT ["/entrypoint.sh"] diff --git a/justfile b/justfile index 435a6bc..4ae4f18 100644 --- a/justfile +++ b/justfile @@ -1,3 +1,7 @@ +# Keep in sync with the hadolint version bundled by hadolint/hadolint-action +# in .github/workflows/ci.yml, so `just lint` and CI agree on the ruleset. +HADOLINT_IMAGE := "ghcr.io/hadolint/hadolint:v2.15.0-debian" + default: @just --list @@ -38,7 +42,7 @@ install: # Lint Containerfile with hadolint lint: - podman run --rm -i hadolint/hadolint < Containerfile + podman run --rm -i {{HADOLINT_IMAGE}} < Containerfile # Lint shell scripts with shellcheck shellcheck: