Add automatic user confirmation (policy 18) #3845
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Hadolint | |
| permissions: {} | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} | |
| cancel-in-progress: true | |
| on: [ push, pull_request ] | |
| defaults: | |
| run: | |
| shell: bash | |
| jobs: | |
| hadolint: | |
| name: Validate Dockerfile syntax | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 30 | |
| steps: | |
| # Start Docker Buildx | |
| - name: Setup Docker Buildx | |
| uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0 | |
| # https://github.com/moby/buildkit/issues/3969 | |
| # Also set max parallelism to 2, the default of 4 breaks GitHub Actions and causes OOMKills | |
| with: | |
| buildkitd-config-inline: | | |
| [worker.oci] | |
| max-parallelism = 2 | |
| driver-opts: | | |
| network=host | |
| # Checkout the repo | |
| - name: Checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| # End Checkout the repo | |
| # Test Dockerfiles with hadolint | |
| # Uses the Docker-based action (hadolint pre-bundled in ghcr.io/hadolint/hadolint:v2.14.0-debian) | |
| # so no binary is downloaded at runtime. Pinned by commit SHA for supply-chain safety. | |
| - name: Run hadolint on Dockerfile.debian | |
| uses: hadolint/hadolint-action@2332a7b74a6de0dda2e2221d575162eba76ba5e5 # v3.3.0 | |
| with: | |
| dockerfile: docker/Dockerfile.debian | |
| - name: Run hadolint on Dockerfile.alpine | |
| uses: hadolint/hadolint-action@2332a7b74a6de0dda2e2221d575162eba76ba5e5 # v3.3.0 | |
| with: | |
| dockerfile: docker/Dockerfile.alpine | |
| # End Test Dockerfiles with hadolint | |
| # Test Dockerfiles with docker build checks | |
| - name: Run docker build check | |
| run: | | |
| echo "Checking docker/Dockerfile.debian" | |
| docker build --check . -f docker/Dockerfile.debian | |
| echo "Checking docker/Dockerfile.alpine" | |
| docker build --check . -f docker/Dockerfile.alpine | |
| # End Test Dockerfiles with docker build checks |