forkcloser/godolint

Rules

The rules godolint implements, with the code, severity and message each reports. All of them come from hadolint 2.15.1; hadolint's wiki documents each code in detail.

Two rules are off by default, as in hadolint: DL1001 objects to inline ignore pragmas, and DL3057 asks for a HEALTHCHECK. Enable them explicitly if needed. RuleSetRecommended keeps only the error and warning rows below. Messages shown as Label <label> name the offending label when reported.

  • 14 error
  • 43 warning
  • 11 info
  • 1 style
  • 2 off by default
CodeSeverityMessage
DL1001off by defaultPlease refrain from using inline ignore pragmas # hadolint ignore=DLxxxx.
DL3000errorUse absolute WORKDIR
DL3001infoFor some bash commands it makes no sense running them in a Docker container like ssh, vim, shutdown, service, ps, free, top, kill, mount, ifconfig
DL3002warningLast USER should not be root
DL3003warningUse WORKDIR to switch to a directory
DL3004errorDo not use sudo as it leads to unpredictable behavior. Use a tool like gosu to enforce root
DL3006warningAlways tag the version of an image explicitly
DL3007warningUsing latest is prone to errors if the image will ever update. Pin the version explicitly to a release tag
DL3008warningPin versions in apt get install. Instead of apt-get install <package> use apt-get install <package>=<version>
DL3009infoDelete the apt lists (/var/lib/apt/lists) after installing something
DL3010infoUse ADD for extracting archives into an image
DL3011errorValid UNIX ports range from 0 to 65535
DL3012errorMultiple HEALTHCHECK instructions
DL3013warningPin versions in pip. Instead of pip install <package> use pip install <package>==<version> or pip install --requirement <requirements file>
DL3014warningUse the -y switch to avoid manual input apt-get -y install <package>
DL3015infoAvoid additional packages by specifying --no-install-recommends
DL3016warningPin versions in npm. Instead of npm install <package> use npm install <package>@<version>
DL3018warningPin versions in apk add. Instead of apk add <package> use apk add <package>=<version>
DL3019infoUse the --no-cache switch to avoid the need to use --update and remove /var/cache/apk/* when done installing packages
DL3020errorUse COPY instead of ADD for files and folders
DL3021errorCOPY with more than 2 arguments requires the last argument to end with /
DL3022warningCOPY --from should reference a previously defined FROM alias
DL3023errorCOPY --from cannot reference its own FROM alias
DL3024errorFROM aliases (stage names) must be unique
DL3025warningUse arguments JSON notation for CMD and ENTRYPOINT arguments
DL3026errorUse only an allowed registry in the FROM image
DL3027warningDo not use apt as it is meant to be an end-user tool, use apt-get or apt-cache instead
DL3028warningPin versions in gem install. Instead of gem install <gem> use gem install <gem>:<version>
DL3029warningDo not use --platform flag with FROM
DL3030warningUse the -y switch to avoid manual input yum install -y <package>
DL3032warningyum clean all missing after yum command.
DL3033warningSpecify version with yum install -y <package>-<version>.
DL3034warningNon-interactive switch missing from zypper command: zypper install -y
DL3035warningDo not use zypper dist-upgrade.
DL3036warningzypper clean missing after zypper use.
DL3037warningSpecify version with zypper install -y <package>=<version>.
DL3038warningUse the -y switch to avoid manual input dnf install -y <package>
DL3040warningdnf clean all missing after dnf command.
DL3041warningSpecify version with dnf install -y <package>-<version>.
DL3042warningAvoid use of cache directory with pip. Use pip install --no-cache-dir <package>
DL3043errorONBUILD, FROM or MAINTAINER triggered from within ONBUILD instruction.
DL3044errorDo not refer to an environment variable within the same ENV statement where it is defined.
DL3045warningCOPY to a relative destination without WORKDIR set.
DL3046warninguseradd without flag -l and high UID will result in excessively large Image.
DL3047infoAvoid use of wget without progress bar. Use wget --progress=dot:giga <url>. Or consider using -q or -nv (shorthands for --quiet or --no-verbose).
DL3048styleInvalid label key.
DL3049infoLabel <label> is missing.
DL3050infoSuperfluous label(s) present.
DL3051warninglabel <label> is empty.
DL3052warningLabel <label> is not a valid URL.
DL3053warningLabel <label> is not a valid time format - must conform to RFC3339.
DL3054warningLabel <label> is not a valid SPDX identifier.
DL3055warningLabel <label> is not a valid git hash.
DL3056warningLabel <label> does not conform to semantic versioning.
DL3057off by defaultHEALTHCHECK instruction missing.
DL3058warningLabel <label> is not a valid email format - must conform to RFC5322.
DL3059infoMultiple consecutive RUN instructions. Consider consolidation.
DL3060infoyarn cache clean missing after yarn install was run.
DL3061errorInvalid instruction order. Dockerfile must begin with FROM, ARG or comment.
DL3062warningPin versions in go. Instead of go install <package> use go install <package>@<version>
DL3063warningstage name should not be a reserved word
DL3064warningPotentially sensitive data should not be used in the ARG or ENV commands
DL3065warningSetting FROM --platform to predefined $TARGETPLATFORM in is redundant as this is the default behavior
DL3066infoNon-numeric user-id may not be resolvable by host system
DL3067warningDo not copy an entire filesystem from another stage
DL4000errorMAINTAINER is deprecated
DL4001warningEither use Wget or Curl but not both
DL4003warningMultiple CMD instructions found. If you list more than one CMD then only the last CMD will take effect
DL4004errorMultiple ENTRYPOINT instructions found. If you list more than one ENTRYPOINT then only the last ENTRYPOINT will take effect
DL4005warningUse SHELL to change the default shell
DL4006warningSet the SHELL option -o pipefail before RUN with a pipe in it. If you are using /bin/sh in an alpine image or if your shell is symlinked to busybox then consider explicitly setting your SHELL to /bin/ash, or disable this check

Shellcheck findings, when the integration is on, are reported alongside these with their own SC codes.