From bde8cd8102cf235c2dbcd707efb9f6e8595d7a6c Mon Sep 17 00:00:00 2001 From: Claude Date: Sun, 9 Aug 2026 07:04:09 +0000 Subject: [PATCH 1/2] fix(container): pin hlds uid/gid and JSON-form HEALTHCHECK hadolint-action 3.4.0 ships a newer hadolint that flags two findings in the Containerfile, turning the Lint job red on the pending bump (#40): - DL3066: `USER hlds` is non-numeric and `useradd -r` picks an arbitrary system uid at build time. Create the user with an explicit uid/gid (10001) and reference it numerically in USER. Beyond satisfying the rule, this makes bind-mount ownership deterministic under rootless Podman instead of varying with whatever uid the build happened to get. - DL3025: the HEALTHCHECK CMD was shell-form. The check needs a shell for the glob and `||`, so it becomes exec-form `/bin/sh -c "..."`. Verified clean against hadolint 2.15.1. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01VprdNaZ8s9F63tqzxhy5Ng --- CHANGELOG.md | 2 ++ Containerfile | 8 +++++--- 2 files changed, 7 insertions(+), 3 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 679ec01..a2e6ca8 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -3,6 +3,8 @@ ## [Unreleased] ### Changed +- `hlds` user is now created with a fixed uid/gid (10001) and `USER` references it numerically, making bind-mount ownership deterministic under rootless Podman and resolving hadolint `DL3066` +- `HEALTHCHECK` `CMD` converted to JSON/exec notation (`/bin/sh -c ...`), resolving hadolint `DL3025` - Bumped AMX Mod X pin from build 5478 to 5479 - Bumped shellcheck pin in `ci.yml` from v0.10.0 to v0.11.0 - README stack list resynced to the versions actually pinned in the Containerfile (ReHLDS 3.15.0.896, ReGameDLL_CS 5.30.0.814, ReAPI 5.29.0.358, AMX Mod X build 5479) diff --git a/Containerfile b/Containerfile index 83dd06d..5c5cd31 100644 --- a/Containerfile +++ b/Containerfile @@ -187,7 +187,9 @@ RUN dpkg --add-architecture i386 && \ /var/tmp/* \ && (find / -xdev -perm /6000 -type f -exec chmod a-s {} + 2>/dev/null || true) -RUN useradd --no-log-init -r -s /usr/sbin/nologin hlds +# Fixed uid/gid so bind-mount ownership is deterministic under rootless Podman +RUN groupadd --system --gid 10001 hlds && \ + useradd --no-log-init --system --uid 10001 --gid 10001 -s /usr/sbin/nologin hlds COPY --from=builder --chown=hlds:hlds /hlds /hlds COPY --chmod=755 entrypoint.sh /entrypoint.sh @@ -203,12 +205,12 @@ LABEL org.opencontainers.image.title="CS 1.6 ScoutzKnivez Server" \ org.opencontainers.image.licenses="MIT" \ org.opencontainers.image.vendor="KevinTCoughlin" -USER hlds +USER 10001:10001 WORKDIR /hlds EXPOSE 27015/udp 27015/tcp HEALTHCHECK --interval=30s --timeout=5s --start-period=60s --retries=3 \ - CMD grep -qs hlds_linux /proc/[0-9]*/comm || exit 1 + CMD ["/bin/sh", "-c", "grep -qs hlds_linux /proc/[0-9]*/comm || exit 1"] ENTRYPOINT ["/entrypoint.sh"] From e33672dd099f29d6fe9cc8fc85d7d0b836a376a9 Mon Sep 17 00:00:00 2001 From: Claude Date: Sun, 9 Aug 2026 07:09:24 +0000 Subject: [PATCH 2/2] chore(ci): align hadolint versions and stop pin-narrowing PRs Follow-ups to the hadolint fix in the previous commit: - Bump hadolint/hadolint-action v3.3.0 -> v3.4.0 in ci.yml. This is the bump Dependabot proposed in #40; landing it here supersedes that PR, which Dependabot closes automatically once the version reaches main. - Pin `just lint` to ghcr.io/hadolint/hadolint:v2.15.0-debian, the exact image v3.4.0 bundles, instead of tracking :latest. Local linting and CI now share a ruleset, so a hadolint release can no longer turn CI red without `just check` catching it first. - Ignore minor/patch Dependabot updates for actions/*, docker/* and github/codeql-action. Those are pinned at the major tag deliberately, so PRs like #39 (codeql-action v4 -> v4.37.4) only narrow the pin. Exactly-pinned actions (hadolint, shellcheck, trivy, sbom-action) still get the full range of updates. Verified: justfile parses under just 1.58.0 and the lint recipe renders the pinned image; the v2.15.0-debian tag resolves on ghcr.io; both YAML files parse. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01VprdNaZ8s9F63tqzxhy5Ng --- .github/dependabot.yml | 17 +++++++++++++++++ .github/workflows/ci.yml | 2 +- CHANGELOG.md | 3 +++ justfile | 6 +++++- 4 files changed, 26 insertions(+), 2 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 6b82d5d..587d57b 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -9,6 +9,23 @@ updates: labels: - "dependencies" - "github-actions" + # actions/*, docker/* and github/codeql-action are pinned at the major tag + # on purpose, so minor/patch PRs against them only narrow the pin. Actions + # pinned exactly (hadolint, shellcheck, trivy, sbom-action) still get the + # full range of updates. + ignore: + - dependency-name: "actions/*" + update-types: + - "version-update:semver-minor" + - "version-update:semver-patch" + - dependency-name: "docker/*" + update-types: + - "version-update:semver-minor" + - "version-update:semver-patch" + - dependency-name: "github/codeql-action" + update-types: + - "version-update:semver-minor" + - "version-update:semver-patch" - package-ecosystem: "docker" directory: "/" diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index b244d55..c1d7ef5 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -19,7 +19,7 @@ jobs: - uses: actions/checkout@v7 - name: Lint Containerfile with hadolint - uses: hadolint/hadolint-action@v3.3.0 + uses: hadolint/hadolint-action@v3.4.0 with: dockerfile: Containerfile diff --git a/CHANGELOG.md b/CHANGELOG.md index a2e6ca8..f05daf0 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,6 +5,9 @@ ### Changed - `hlds` user is now created with a fixed uid/gid (10001) and `USER` references it numerically, making bind-mount ownership deterministic under rootless Podman and resolving hadolint `DL3066` - `HEALTHCHECK` `CMD` converted to JSON/exec notation (`/bin/sh -c ...`), resolving hadolint `DL3025` +- Bumped `hadolint/hadolint-action` in `ci.yml` from v3.3.0 to v3.4.0 (hadolint 2.14.0 → 2.15.0) +- `just lint` pins `ghcr.io/hadolint/hadolint:v2.15.0-debian` instead of tracking `:latest`, so local linting and CI run the same ruleset +- Dependabot no longer opens minor/patch PRs for `actions/*`, `docker/*` and `github/codeql-action`, which are pinned at the major tag on purpose - Bumped AMX Mod X pin from build 5478 to 5479 - Bumped shellcheck pin in `ci.yml` from v0.10.0 to v0.11.0 - README stack list resynced to the versions actually pinned in the Containerfile (ReHLDS 3.15.0.896, ReGameDLL_CS 5.30.0.814, ReAPI 5.29.0.358, AMX Mod X build 5479) diff --git a/justfile b/justfile index 435a6bc..4ae4f18 100644 --- a/justfile +++ b/justfile @@ -1,3 +1,7 @@ +# Keep in sync with the hadolint version bundled by hadolint/hadolint-action +# in .github/workflows/ci.yml, so `just lint` and CI agree on the ruleset. +HADOLINT_IMAGE := "ghcr.io/hadolint/hadolint:v2.15.0-debian" + default: @just --list @@ -38,7 +42,7 @@ install: # Lint Containerfile with hadolint lint: - podman run --rm -i hadolint/hadolint < Containerfile + podman run --rm -i {{HADOLINT_IMAGE}} < Containerfile # Lint shell scripts with shellcheck shellcheck: