Description
A relative WORKDIR is resolved against the previous working directory, which may be inherited from the base image. This is valid syntax, but a change to that base location can change where commands run.
Potential impact
Files may be copied or commands run in an unintended location, causing build errors.
Remediation
Establish the working-directory base with an absolute path in each stage. If later paths are relative, check that their base and resolved location are intentional.
Examples
In these examples, WORKDIR app after /usr/src resolves to /usr/src/app, so both configurations use the same location. Combining them into an absolute path reduces dependence on the preceding declaration.
Before
dockerfile
FROM node:22-alpine
WORKDIR /usr/src
WORKDIR app
COPY . .
After
dockerfile
FROM node:22-alpine
WORKDIR /usr/src/app
COPY . .