Repository navigation
ci: update lint tooling and image security - #25
Merged
Merged
Conversation
- Upgrade Dockerfile linting to the latest Hadolint action release
Contributor
There was a problem hiding this comment.
🟢 Approval recommended
No unresolved issues were identified.
Pull request overview
Updates the Dockerfile linting GitHub Action to Hadolint v3.5.0 while preserving existing CI and Trivy scanning.
Changes:
- Upgraded Hadolint from v3.3.0 to v3.5.0.
- Retained the existing Dockerfile lint configuration.
File summaries
| File | Summary |
|---|---|
.github/workflows/testing.yml |
Uses Hadolint action v3.5.0 for Dockerfile linting. |
Review details
- Files reviewed: 1/1 changed files
- Comments generated: 0
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
- Use a lint binary compatible with the stable Go toolchain
- Ignore repeated test fixture strings in goconst - Mark documented file and URL loaders as reviewed gosec exceptions - Migrate gofumpt to its current extra-rules setting
- Upgrade Alpine packages before installing runtime certificates - Run the image with the existing numeric user and group IDs - Document why the certificate package intentionally tracks security updates
- Follow the latest patch release in the shared v2.13 line
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Update Dockerfile linting from
hadolint/[email protected]tov3.5.0and update golangci-lint fromv2.6to the sharedv2.13release line, which resolves to the latest 2.13.x patch. The lint configuration now ignores repeated test fixture strings, uses the current gofumpt setting, and records narrow gosec exceptions for the documented caller-selected file and URL loading features. The runtime image upgrades Alpine packages during build and uses numeric UID/GID1000:1000, clearing the vulnerabilities and lint rule surfaced by the new checks. The existing Trivy action remains on the latestv0.36.0release.Related issues
AI authorship
.github/workflows/testing.yml,.golangci.yml,prompt_loader.go,DockerfileChange classification
The workflow gates repository changes; a broken action reference can block CI.
Plan reference
Goal and scope: update stale GitHub Actions references while preserving the existing Trivy security policy. No runtime code or action metadata is changed.
Verification
Setup
ci/update-actions-security-scan, repository rootactionlintgit checkout ci/update-actions-security-scanAutomated checks
GOPATH=/tmp/codex-go GOMODCACHE=/tmp/codex-go/pkg/mod GOCACHE=/tmp/codex-go/cache go run github.com/rhysd/actionlint/cmd/actionlint@latest .github/workflows/testing.ymlactionlint v1.7.12exited 0 with no diagnosticsgolangci-lint config verify && golangci-lint runusing the current v2.13.2 binary resolved by the v2.13 line0 issuesGOPATH=/tmp/codex-test-go GOMODCACHE=/tmp/codex-test-go/pkg/mod GOCACHE=/tmp/codex-test-go/cache go test ./...docker run --rm -i ghcr.io/hadolint/hadolint:v2.15.1-debian < Dockerfiledocker build -t llm-action:codex-scan .docker run --rm -v /var/run/docker.sock:/var/run/docker.sock aquasec/trivy:0.70.0 image --severity HIGH,CRITICAL --exit-code 1 llm-action:codex-scangit diff --check main...HEADrg 'hadolint/[email protected]' .github/workflows/testing.ymlrg 'version: v2.13' .github/workflows/testing.ymlrg 'aquasecurity/[email protected]' .github/workflows/trivy.ymlBehavioral scenario: Repository linting
hadolint/[email protected]and installs the latest golangci-lint v2.13.x patchfile requires newer Go versionpanic, then Hadolint checks the existingDockerfileinputLint and Testingrun 34692070911 passed both jobs;Docker Imagerun 34692070962 passed its build and Trivy image scan.Security check
Risk and rollback
Reviewer guide
.github/workflows/trivy.ymlis unchanged and remains enabled.