
Dockerfile Lint
io.github.basitalisandhuv0.1.1Updated Oct 5, 2026
Lint Dockerfiles for root users, latest tags, secrets in ENV or ARG, missing HEALTHCHECK and more.
Overview
Lints Dockerfiles for production-image mistakes such as root users, latest tags, and secrets in ENV or ARG.
- What it does
- Parses Dockerfiles, including comments, escape directives, line continuations, heredocs, and multi-stage builds, then runs static lint rules over them. The lint_dockerfile tool reports findings with rule id, severity, line, and suggested fix; parse_dockerfile returns instructions, line ranges, stages, and base images; explain_rule describes one rule. Docker itself is never invoked.
- When to use it
- Useful when reviewing or hardening Dockerfiles before building images, or when an assistant should check a Dockerfile for common production pitfalls without running a build.
- Requirements
- Runs locally over stdio as an npm package (npx) or from a checkout with Node.js; no network access, accounts, or API keys. It reads the single Dockerfile path or content you provide, up to 1 MB.
Installation
In SourceWeft
- Open Dockerfile Lint in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
dockerfile-lint MCP server
Parses Dockerfiles (comments, escape directive, line continuations, heredocs, multi-stage builds) and lints them for the mistakes that matter in production images. Static analysis only; Docker is never invoked.
Part of dev-mcp-servers. Stdio transport only; the server never opens a port.
Tools
Install
Claude Code:
Add -s user to make it available in every project. Any client that reads .mcp.json (Claude Code, Claude Desktop, Cursor):
Pin the version as shown so that an update to the package cannot change what runs in your editor without you noticing. From a checkout, use "command": "node", "args": ["<path>/packages/dockerfile-lint/dist/index.js"] after npm install && npm run build at the repository root.
What it touches
- Network: None.
- Local files: Reads the one file you name, up to 1 MB.
- Telemetry: none.
Notes
FROM $ARGbases are checked against the declaredARGs;scratchand stage references are exempt from tag checks.- Rules are heuristics on the text; a clean result does not scan the image's packages.
Build and test
Tests use node:test and the SDK's in-memory transport; they do not reach the network.
Licence
MIT. See LICENSE.
Source: packages/dockerfile-lint/README.md at commit 58c8c95
Tools
0Version history
1- v0.1.1LatestOct 5, 2026


