Rules
The rules godolint implements, with the code, severity and message each reports. All of them come from hadolint 2.15.1; hadolint's wiki documents each code in detail.
Two rules are off by default, as in hadolint: DL1001 objects to inline ignore pragmas, and DL3057 asks for a HEALTHCHECK. Enable them explicitly if needed. RuleSetRecommended keeps only the error and warning rows below. Messages shown as Label <label> name the offending label when reported.
- 14 error
- 43 warning
- 11 info
- 1 style
- 2 off by default
| Code | Severity | Message |
|---|---|---|
| DL1001 | off by default | Please refrain from using inline ignore pragmas # hadolint ignore=DLxxxx. |
| DL3000 | error | Use absolute WORKDIR |
| DL3001 | info | For some bash commands it makes no sense running them in a Docker container like ssh, vim, shutdown, service, ps, free, top, kill, mount, ifconfig |
| DL3002 | warning | Last USER should not be root |
| DL3003 | warning | Use WORKDIR to switch to a directory |
| DL3004 | error | Do not use sudo as it leads to unpredictable behavior. Use a tool like gosu to enforce root |
| DL3006 | warning | Always tag the version of an image explicitly |
| DL3007 | warning | Using latest is prone to errors if the image will ever update. Pin the version explicitly to a release tag |
| DL3008 | warning | Pin versions in apt get install. Instead of apt-get install <package> use apt-get install <package>=<version> |
| DL3009 | info | Delete the apt lists (/var/lib/apt/lists) after installing something |
| DL3010 | info | Use ADD for extracting archives into an image |
| DL3011 | error | Valid UNIX ports range from 0 to 65535 |
| DL3012 | error | Multiple HEALTHCHECK instructions |
| DL3013 | warning | Pin versions in pip. Instead of pip install <package> use pip install <package>==<version> or pip install --requirement <requirements file> |
| DL3014 | warning | Use the -y switch to avoid manual input apt-get -y install <package> |
| DL3015 | info | Avoid additional packages by specifying --no-install-recommends |
| DL3016 | warning | Pin versions in npm. Instead of npm install <package> use npm install <package>@<version> |
| DL3018 | warning | Pin versions in apk add. Instead of apk add <package> use apk add <package>=<version> |
| DL3019 | info | Use the --no-cache switch to avoid the need to use --update and remove /var/cache/apk/* when done installing packages |
| DL3020 | error | Use COPY instead of ADD for files and folders |
| DL3021 | error | COPY with more than 2 arguments requires the last argument to end with / |
| DL3022 | warning | COPY --from should reference a previously defined FROM alias |
| DL3023 | error | COPY --from cannot reference its own FROM alias |
| DL3024 | error | FROM aliases (stage names) must be unique |
| DL3025 | warning | Use arguments JSON notation for CMD and ENTRYPOINT arguments |
| DL3026 | error | Use only an allowed registry in the FROM image |
| DL3027 | warning | Do not use apt as it is meant to be an end-user tool, use apt-get or apt-cache instead |
| DL3028 | warning | Pin versions in gem install. Instead of gem install <gem> use gem install <gem>:<version> |
| DL3029 | warning | Do not use --platform flag with FROM |
| DL3030 | warning | Use the -y switch to avoid manual input yum install -y <package> |
| DL3032 | warning | yum clean all missing after yum command. |
| DL3033 | warning | Specify version with yum install -y <package>-<version>. |
| DL3034 | warning | Non-interactive switch missing from zypper command: zypper install -y |
| DL3035 | warning | Do not use zypper dist-upgrade. |
| DL3036 | warning | zypper clean missing after zypper use. |
| DL3037 | warning | Specify version with zypper install -y <package>=<version>. |
| DL3038 | warning | Use the -y switch to avoid manual input dnf install -y <package> |
| DL3040 | warning | dnf clean all missing after dnf command. |
| DL3041 | warning | Specify version with dnf install -y <package>-<version>. |
| DL3042 | warning | Avoid use of cache directory with pip. Use pip install --no-cache-dir <package> |
| DL3043 | error | ONBUILD, FROM or MAINTAINER triggered from within ONBUILD instruction. |
| DL3044 | error | Do not refer to an environment variable within the same ENV statement where it is defined. |
| DL3045 | warning | COPY to a relative destination without WORKDIR set. |
| DL3046 | warning | useradd without flag -l and high UID will result in excessively large Image. |
| DL3047 | info | Avoid use of wget without progress bar. Use wget --progress=dot:giga <url>. Or consider using -q or -nv (shorthands for --quiet or --no-verbose). |
| DL3048 | style | Invalid label key. |
| DL3049 | info | Label <label> is missing. |
| DL3050 | info | Superfluous label(s) present. |
| DL3051 | warning | label <label> is empty. |
| DL3052 | warning | Label <label> is not a valid URL. |
| DL3053 | warning | Label <label> is not a valid time format - must conform to RFC3339. |
| DL3054 | warning | Label <label> is not a valid SPDX identifier. |
| DL3055 | warning | Label <label> is not a valid git hash. |
| DL3056 | warning | Label <label> does not conform to semantic versioning. |
| DL3057 | off by default | HEALTHCHECK instruction missing. |
| DL3058 | warning | Label <label> is not a valid email format - must conform to RFC5322. |
| DL3059 | info | Multiple consecutive RUN instructions. Consider consolidation. |
| DL3060 | info | yarn cache clean missing after yarn install was run. |
| DL3061 | error | Invalid instruction order. Dockerfile must begin with FROM, ARG or comment. |
| DL3062 | warning | Pin versions in go. Instead of go install <package> use go install <package>@<version> |
| DL3063 | warning | stage name should not be a reserved word |
| DL3064 | warning | Potentially sensitive data should not be used in the ARG or ENV commands |
| DL3065 | warning | Setting FROM --platform to predefined $TARGETPLATFORM in is redundant as this is the default behavior |
| DL3066 | info | Non-numeric user-id may not be resolvable by host system |
| DL3067 | warning | Do not copy an entire filesystem from another stage |
| DL4000 | error | MAINTAINER is deprecated |
| DL4001 | warning | Either use Wget or Curl but not both |
| DL4003 | warning | Multiple CMD instructions found. If you list more than one CMD then only the last CMD will take effect |
| DL4004 | error | Multiple ENTRYPOINT instructions found. If you list more than one ENTRYPOINT then only the last ENTRYPOINT will take effect |
| DL4005 | warning | Use SHELL to change the default shell |
| DL4006 | warning | Set the SHELL option -o pipefail before RUN with a pipe in it. If you are using /bin/sh in an alpine image or if your shell is symlinked to busybox then consider explicitly setting your SHELL to /bin/ash, or disable this check |
Shellcheck findings, when the integration is on, are reported alongside these with their own SC codes.