An up-to-date multi-arch image to easily lint git repository
10K+
A Python Docker image with pre-commit:
multiarch with support of amd64 and arm64,pre-commit and dependency versions),SBOM) attestation added using Syft,docker run -t --rm -v "$(pwd)":/workdir jfxs/pre-commit /bin/bash -c "pre-commit run --all-files"
The first time pre-commit runs, it will automatically download and install the hooks and save them in the .cache/pre-commit directory.
Don't forget to add the .cache directory to the .gitignore file.
The image runs as root by default. On a Linux host, run the container with your own user to avoid files owned by root (such as .cache) in your repository:
docker run -t --rm -u "$(id -u):$(id -g)" -v "$(pwd)":/workdir jfxs/pre-commit /bin/bash -c "pre-commit run --all-files"
docker run -t --rm -v "$(pwd)":/workdir jfxs/pre-commit /bin/bash -c "task --taskfile /lint.yml pre-commit DIR=/workdir"
or with task installed locally and the lint task template:
task lint:pre-commit
If the .pre-commit-config.yaml file doesn't exist, a default one is created, see the pre-commit task of the
lint task template.
Example of usage with Gitlab-CI:
...
pre-commit:
image: jfxs/pre-commit
stage: lint
script:
- task --taskfile /lint.yml pre-commit DIR=$(pwd)
Docker latest tag is 4.6.2-004, 4.6, 4.
The complete software bill of materials (SBOM) of each published image, with its known vulnerabilities,
is collected in the sbom-docker repository, under the
component pre-commit.
Dockerhub Overview page has the details of the last published image.
Docker tag definition:
<pre-commit_version>-<increment>
Example: 4.6.2-001
The floating tags <major>.<minor> (example: 4.6), <major> (example: 4) and latest point to the last published image.
Cosign public key:
-----BEGIN PUBLIC KEY-----
MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEa3yV6+yd/l4zh/tfT6Tx+zn0dhy3
BhFqSad1norLeKSCN2MILv4fZ9GA6ODOlJOw+7vzUvzZVr9IXnxEdjoWJw==
-----END PUBLIC KEY-----
The public key is also available online: https://gitlab.com/op_so/docker/cosign-public-key/-/raw/main/cosign.pub.
To verify an image:
cosign verify --key cosign.pub $IMAGE_URI
To verify and get the software bill of materials (SBOM) attestation:
cosign verify-attestation --key cosign.pub --type spdxjson $IMAGE_URI | jq '.payload | @base64d | fromjson | .predicate'
The versions of the base image, pre-commit, go-task, the Python dependencies (requirements.txt) and the lint task
template are updated by Renovate in a scheduled pipeline. Required GitLab CI/CD settings:
RENOVATE=true and DISABLE_JOBS=true (otherwise each run rebuilds and republishes the image),RENOVATE_TOKEN, and GITHUB_COM_TOKEN to look up the GitHub-hosted dependencies (go-task, hooks of .pre-commit-config.yaml),DOCKERHUB_*, QUAY_*, COSIGN_* and BOMPAGE_TOKEN / BOMPAGE_SIGN_KEY, see the docker component.To run the tests locally: task 00:10-build-local then task 00:20-test.
This program is free software: you can redistribute it and/or modify it under the terms of the MIT License (MIT). See the LICENSE for details.
Content type
Image
Digest
sha256:d8e793d76…
Size
105.8 MB
Last updated
about 14 hours ago
docker pull jfxs/pre-commit