Review relative WORKDIR paths

Establish an explicit absolute working-directory path.

Description

A relative WORKDIR is resolved against the previous working directory, which may be inherited from the base image. This is valid syntax, but a change to that base location can change where commands run.

Potential impact

Files may be copied or commands run in an unintended location, causing build errors.

Remediation

Establish the working-directory base with an absolute path in each stage. If later paths are relative, check that their base and resolved location are intentional.

Examples

In these examples, WORKDIR app after /usr/src resolves to /usr/src/app, so both configurations use the same location. Combining them into an absolute path reduces dependence on the preceding declaration.

Before

dockerfile
FROM node:22-alpine

WORKDIR /usr/src
WORKDIR app
COPY . .

After

dockerfile
FROM node:22-alpine

WORKDIR /usr/src/app
COPY . .

References