What
The repo has 56 tracked Dockerfiles across the sensor stacks. image-security-scan.yml covers base-image CVEs, but nothing lints the Dockerfiles themselves: missing --no-install-recommends, ADD of remote URLs, unpinned apk/apt versions, USER missing, shell-form CMD. #3303's investigation showed how opaque Dockerfile-level failures get on the runner.
Proposal
A hadolint job (pinned, checksummed) over changed **/Dockerfile*, with a repo .hadolint.yaml that ignores rules we violate deliberately (each with a reason). Start advisory, then make it blocking for new violations only (hadolint's --failure-threshold plus a baseline).
Sources
Found by the #3194 OmniRoute ops/CI deep-check (pinned 18bbb101, APIARY main 3dca4457).
What
The repo has 56 tracked Dockerfiles across the sensor stacks.
image-security-scan.ymlcovers base-image CVEs, but nothing lints the Dockerfiles themselves: missing--no-install-recommends,ADDof remote URLs, unpinnedapk/aptversions,USERmissing, shell-formCMD. #3303's investigation showed how opaque Dockerfile-level failures get on the runner.Proposal
A hadolint job (pinned, checksummed) over changed
**/Dockerfile*, with a repo.hadolint.yamlthat ignores rules we violate deliberately (each with a reason). Start advisory, then make it blocking for new violations only (hadolint's--failure-thresholdplus a baseline).Sources
.github/workflows/ci.ymlFound by the #3194 OmniRoute ops/CI deep-check (pinned
18bbb101, APIARYmain3dca4457).