Sign inSign up

pirlruc/ci-container

By pirlruc

•Updated 14 days ago

Image with tools to analyze container images

Image
Developer tools
0

2.1K

pirlruc/ci-container repository overview

⁠ci-container

Short-lived CI toolchain image for container jobs.

⁠Image

ItemValue
Docker Hubpirlruc/ci-container
Architectureslinux/amd64
Usernon-root 1000:1000
Basepirlruc/ci-lint (digest-pinned at publish)
⁠Tags
TagMeaning
5.0.3 / 5.0.3-alpineImmutable Alpine sha256:3aeed6541a875ff4b4c0954cb838a1414800c0f3231970acbb7e2bbef9783d00
5.0.3-debianImmutable Debian sha256:14f26db2831086123bf79caa3aac39e337edcc565d41ea894a376f463d850ef7
5.0.0 / 5.0.0-alpinePrevious Alpine sha256:0d4328a0b6051a87df5baa70b19edeaa521ee479462268fe7b2be619209a42d4
5.0.0-debianPrevious Debian sha256:a4d6a2dd0c9ea1d6e09c78962e7fc918e42607e3461489bf17c1118308582c86
latest / latest-alpineLatest non-prerelease Alpine publish
latest-debianLatest non-prerelease Debian publish
sha-<git> / sha-<git>-alpine / sha-<git>-debianExact git SHA of the published commit

Alpine owns the unsuffixed tags to match ci-lint (lower OS vulnerability posture). Prefer an explicit -alpine / -debian suffix when the libc matters; prefer a digest in production. latest equals latest-alpine (flavor: latest=false). A monthly rebuild may move latest off the SemVer tag — pin the digest, not latest.

docker pull pirlruc/ci-container:5.0.3
# or
docker pull pirlruc/ci-container:5.0.3-debian
docker pull pirlruc/ci-container@sha256:3aeed6541a875ff4b4c0954cb838a1414800c0f3231970acbb7e2bbef9783d00

⁠Quick start

docker run --rm -v "$PWD:/workspace:ro" -w /workspace \
  pirlruc/ci-container:5.0.3 \
  hadolint Dockerfile
docker run --rm -v /var/run/docker.sock:/var/run/docker.sock \
  pirlruc/ci-container:5.0.3 \
  dive --ci my-app:local

Hardened local run (read-only workspace mount):

docker run --rm \
  --read-only \
  --cap-drop ALL \
  --security-opt no-new-privileges \
  --tmpfs /tmp:rw,noexec,nosuid,size=256m \
  -v "$PWD:/workspace:ro" -w /workspace \
  pirlruc/ci-container:5.0.3 \
  hadolint Dockerfile

⁠What is inside

Everything in ci-lint, plus:

ToolRole
diveImage layer efficiency
container-structure-testImage structure / command tests

Not included: syft, grype, trivy, grant (use ci-supply-chain).

⁠Vulnerabilities

Donor Go binaries (dive, structure-test, actionlint) embed dependency CVEs that only clear when upstream publishes a newer digest.

⁠License

MIT

Tag summary

Content type

Image

Digest

sha256:3aeed6541…

Size

231.6 MB

Last updated

14 days ago

docker pull pirlruc/ci-container