Description
With pipefail disabled, a shell generally takes a pipeline’s exit status from its last command. A RUN step can therefore succeed when an earlier command fails but the last command succeeds.
Potential impact
An unnoticed download or preprocessing failure can leave incomplete artifacts in the image.
Remediation
Enable pipefail in a shell installed in the image that supports it. Otherwise, explicitly choose a supporting shell or check each command’s failure separately.
Examples
The examples configure Bash to propagate pipeline failures. pipefail does not verify the downloaded script’s trustworthiness; check its source and integrity before execution.
Before
dockerfile
FROM node:22
RUN curl -fsSL https://example.com/install.sh | bash
After
dockerfile
FROM node:22
SHELL ["/bin/bash", "-o", "pipefail", "-c"]
RUN curl -fsSL https://example.com/install.sh | bash