Sign inSign up

pirlruc/ci-lint

By pirlruc

•Updated 14 days ago

Image with tools for linting workflow files and secrets / SAST

Image
Languages & frameworks
Developer tools
0

1.4K

pirlruc/ci-lint repository overview

⁠ci-lint

Short-lived CI toolchain image that run workflow lint and secrets/SAST: actionlint, hadolint, shellcheck, zizmor, yamllint, gitleaks, and semgrep.

⁠Image

ItemValue
Docker Hubpirlruc/ci-lint
Architectureslinux/amd64
Usernon-root 1000:1000
⁠Tags
TagMeaning
5.1.1 / 5.1.1-alpineImmutable Alpine sha256:35a82a43839e0969dc7c44d63c36b5c97cdefb20c6d3112255f52c09444042a1
5.1.1-debianImmutable Debian sha256:6834b69583a9f67ac21bd06167672e793ce2cba1c14e646a98108e0fc9512dcd
5.1.0 / 5.1.0-alpinePrevious Alpine sha256:fc7d91c3ad2ca946e50395227b86396ac92d90afa14e9ca8c301909a5424085c
5.1.0-debianPrevious Debian sha256:c46d04b224d6a7e3227c02aa693c6cce277614be9432f6a6bcc88e8dbbbe1a7d
latest / latest-alpineLatest non-prerelease Alpine publish
latest-debianLatest non-prerelease Debian publish
sha-<git> / sha-<git>-alpine / sha-<git>-debianExact git SHA of the published commit

Alpine owns the unsuffixed tags because it currently has the lower OS vulnerability posture on the DHI catalog. Prefer an explicit -alpine / -debian suffix when the libc matters; prefer a digest in production. latest equals latest-alpine (flavor: latest=false). A monthly rebuild may move latest off the SemVer tag — pin the digest, not latest.

docker pull pirlruc/ci-lint:5.1.1
# or
docker pull pirlruc/ci-lint:5.1.1-debian
docker pull pirlruc/ci-lint@sha256:35a82a43839e0969dc7c44d63c36b5c97cdefb20c6d3112255f52c09444042a1

⁠Quick start

docker run --rm -v "$PWD:/workspace:ro" -w /workspace \
  pirlruc/ci-lint:5.1.1 \
  actionlint .github/workflows/*.yml

Hardened local run (read-only workspace mount):

docker run --rm \
  --read-only \
  --cap-drop ALL \
  --security-opt no-new-privileges \
  --tmpfs /tmp:rw,noexec,nosuid,size=256m \
  -v "$PWD:/workspace:ro" -w /workspace \
  pirlruc/ci-lint:5.1.1 \
  semgrep scan --config auto --error .

⁠What is inside

ToolRole
actionlintGitHub Actions workflow lint
hadolintDockerfile lint
shellcheckShell script lint
zizmorActions security lint
yamllintYAML lint
gitleaksSecrets detection
semgrepSAST (--config auto)

Not included: syft, grype, trivy, grant, dive (see ci-supply-chain and ci-container).

⁠Vulnerabilities

Donor Go binaries (notably actionlint) embed stdlib CVEs that only clear when upstream publishes a newer digest. shellcheck and gitleaks on the Alpine variant are copied from the Debian DHI donors (no Alpine DHI build exists; both binaries are statically linked).

⁠License

MIT

Tag summary

Content type

Image

Digest

sha256:35a82a438…

Size

219 MB

Last updated

14 days ago

docker pull pirlruc/ci-lint