Documentation
| Article | Path |
|---|---|
| Use COPY instead of ADD | dockerfile/add_instead_of_copy |
| CMD and ENTRYPOINT without JSON form | dockerfile/not_using_json_in_cmd_and_entrypoint_arguments |
| Review COPY file ownership and write permissions | dockerfile/chown_flag_exists |
| COPY --from references its own build stage | dockerfile/copy_from_references_current_from_alias |
| Review the intent of FROM platform selection | dockerfile/using_platform_with_from |
| Review container health-check configuration | dockerfile/healthcheck_instruction_missing |
| Use of the MAINTAINER instruction | dockerfile/maintainer_instruction_being_used |
| Working directory set with RUN cd | dockerfile/run_command_cd_instead_of_workdir |
| Review apt use in Dockerfile automation | dockerfile/run_using_apt |
| Using sudo in RUN | dockerfile/run_using_sudo |
| Changing the default shell with RUN | dockerfile/changing_default_shell_using_run_command |
| Review the container SSH port declaration | dockerfile/exposing_port_22 |
| Dockerfile has no USER instruction | dockerfile/missing_user_instruction |
| Review apk installation cache management | dockerfile/apk_add_using_local_cache_path |
| apk package versions are not pinned | dockerfile/unpinned_package_version_in_apk_add |
| Missing package version pins in apt-get installs | dockerfile/apt_get_install_pin_version_not_defined |
| Review apt-get installation prompts | dockerfile/apt_get_missing_flags_to_avoid_manual_input |
| Review apt-get recommended package installation | dockerfile/apt_get_not_avoiding_additional_packages |
| Review apt-get package-list cleanup | dockerfile/apt_get_install_lists_were_not_deleted |
| Review dnf installation cache cleanup | dockerfile/missing_dnf_clean_all |
| Review dnf installation prompts | dockerfile/missing_flag_from_dnf_install |
| dnf package versions are not pinned | dockerfile/missing_version_specification_in_dnf_install |
| Gem package versions are not pinned | dockerfile/gem_install_without_version |
| Base image uses the latest tag | dockerfile/image_version_using_latest |
| npm package versions are not pinned | dockerfile/npm_install_without_pinned_version |
| Review pip caches included in container images | dockerfile/pip_install_keeping_cached_packages |
| pip package versions are not pinned | dockerfile/unpinned_package_version_in_pip_install |
| Review separate package-index refresh and installation | dockerfile/update_instruction_alone |
| Review overlapping use of wget and curl | dockerfile/run_using_wget_and_curl |
| Review yum installation cache cleanup | dockerfile/yum_clean_all_missing |
| Review yum installation prompts | dockerfile/yum_install_allows_manual_input |
| yum package versions are not pinned | dockerfile/yum_install_without_version |
| Missing zypper non-interactive option | dockerfile/missing_zypper_non_interactive_switch |
| Review zypper cache cleanup | dockerfile/missing_zypper_clean |
| zypper package versions are not pinned | dockerfile/zypper_install_without_version |
| Review Dockerfile layers and temporary files | dockerfile/multiple_run_add_copy_instructions_listed |
| Dockerfile ends with root as the selected user | dockerfile/last_user_is_root |
| Base-image version is not specified | dockerfile/image_version_not_explicit |
| Review diagnostic commands in RUN | dockerfile/run_utilities_and_posix_commands |
| Duplicate build-stage names | dockerfile/same_alias_in_different_froms |
| Multiple CMD instructions in one build stage | dockerfile/multiple_cmd_instructions_listed |
| Multiple ENTRYPOINT instructions in one build stage | dockerfile/multiple_entrypoint_instructions_listed |
| Invalid COPY destination for multiple sources | dockerfile/copy_with_more_than_two_arguments_not_ending_with_slash |
| Review integrity checks for remote artifacts | dockerfile/curl_or_wget_instead_of_add |
| Review the range of EXPOSE port numbers | dockerfile/unix_ports_out_of_range |
| Build stage referenced by number | dockerfile/using_unnamed_build_stages |
| Review relative WORKDIR paths | dockerfile/workdir_path_not_absolute |
| Pipeline without pipefail | dockerfile/shell_running_a_pipe_without_pipefail_flag |