Dockerfile Lint

io.github.basitalisandhuv0.1.1Updated Oct 5, 2026

Lint Dockerfiles for root users, latest tags, secrets in ENV or ARG, missing HEALTHCHECK and more.

VerifiedSTDIODesktop onlyDeveloper ToolsSecurity & Monitoring

Overview

AI-generated overview

Lints Dockerfiles for production-image mistakes such as root users, latest tags, and secrets in ENV or ARG.

What it does
Parses Dockerfiles, including comments, escape directives, line continuations, heredocs, and multi-stage builds, then runs static lint rules over them. The lint_dockerfile tool reports findings with rule id, severity, line, and suggested fix; parse_dockerfile returns instructions, line ranges, stages, and base images; explain_rule describes one rule. Docker itself is never invoked.
When to use it
Useful when reviewing or hardening Dockerfiles before building images, or when an assistant should check a Dockerfile for common production pitfalls without running a build.
Requirements
Runs locally over stdio as an npm package (npx) or from a checkout with Node.js; no network access, accounts, or API keys. It reads the single Dockerfile path or content you provide, up to 1 MB.
Before you install
Read-only static analysis: it does not build images or modify files. Findings are text heuristics, so a clean result does not mean the built image is secure or free of vulnerable packages.

Installation

In SourceWeft

  1. Open Dockerfile Lint in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.

Other MCP clients

Follow the launch instructions in the repository.

README

dockerfile-lint MCP server

Parses Dockerfiles (comments, escape directive, line continuations, heredocs, multi-stage builds) and lints them for the mistakes that matter in production images. Static analysis only; Docker is never invoked.

Part of dev-mcp-servers. Stdio transport only; the server never opens a port.

Tools

ToolInputWhat it returns
lint_dockerfilepath or content, ignore?Findings with rule id, severity, line and fix: final stage running as root, latest or missing tags, no digest, credential-like ENV/ARG names and literals, missing HEALTHCHECK, apt-get without cleanup or --no-install-recommends, apt-get upgrade, apk add without --no-cache, pip without --no-cache-dir, ADD for plain files or URLs, `curl
parse_dockerfilepath or contentInstructions with line ranges and stage index, stages with AS names and base images, escape character.
explain_ruleruleSeverity, description and fix for one rule.

Install

Claude Code:

bash
claude mcp add dockerfile-lint -- npx -y @basitalisandhu/[email protected]

Add -s user to make it available in every project. Any client that reads .mcp.json (Claude Code, Claude Desktop, Cursor):

json
{  "mcpServers": {    "dockerfile-lint": {      "command": "npx",      "args": ["-y", "@basitalisandhu/[email protected]"]    }  }}

Pin the version as shown so that an update to the package cannot change what runs in your editor without you noticing. From a checkout, use "command": "node", "args": ["<path>/packages/dockerfile-lint/dist/index.js"] after npm install && npm run build at the repository root.

What it touches

  • Network: None.
  • Local files: Reads the one file you name, up to 1 MB.
  • Telemetry: none.

Notes

  • FROM $ARG bases are checked against the declared ARGs; scratch and stage references are exempt from tag checks.
  • Rules are heuristics on the text; a clean result does not scan the image's packages.

Build and test

bash
npm install        # at the repository rootnpm run build -w @basitalisandhu/mcp-dockerfile-lintnpm test -w @basitalisandhu/mcp-dockerfile-lint

Tests use node:test and the SDK's in-memory transport; they do not reach the network.

Licence

MIT. See LICENSE.

Source: packages/dockerfile-lint/README.md at commit 58c8c95

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.1.1LatestOct 5, 2026