
Dockerfile Lint
io.github.basitalisandhuv0.1.1更新于 Oct 5, 2026
Lint Dockerfiles for root users, latest tags, secrets in ENV or ARG, missing HEALTHCHECK and more.
概览
检查 Dockerfile 中的生产镜像常见问题,例如以 root 运行、使用 latest 标签、在 ENV 或 ARG 中写入密钥。
- 功能
- 解析 Dockerfile,包括注释、escape 指令、续行、heredoc 和多阶段构建,然后对其运行静态检查规则。lint_dockerfile 工具返回包含规则编号、严重级别、行号和修复建议的结果;parse_dockerfile 返回指令、行范围、阶段和基础镜像;explain_rule 说明单条规则。不会调用 Docker 本身。
- 适用场景
- 适合在构建镜像前审查或加固 Dockerfile,或让助手在不执行构建的情况下检查 Dockerfile 的常见生产隐患。
- 运行要求
- 以 npm 包(npx)或从代码检出配合 Node.js 在本地通过 stdio 运行;无需网络、账号或 API 密钥。它只读取你指定的单个 Dockerfile 路径或内容,最大 1 MB。
安装
在 SourceWeft 中
- 打开 控制台中的 Dockerfile Lint,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
dockerfile-lint MCP server
Parses Dockerfiles (comments, escape directive, line continuations, heredocs, multi-stage builds) and lints them for the mistakes that matter in production images. Static analysis only; Docker is never invoked.
Part of dev-mcp-servers. Stdio transport only; the server never opens a port.
Tools
Install
Claude Code:
Add -s user to make it available in every project. Any client that reads .mcp.json (Claude Code, Claude Desktop, Cursor):
Pin the version as shown so that an update to the package cannot change what runs in your editor without you noticing. From a checkout, use "command": "node", "args": ["<path>/packages/dockerfile-lint/dist/index.js"] after npm install && npm run build at the repository root.
What it touches
- Network: None.
- Local files: Reads the one file you name, up to 1 MB.
- Telemetry: none.
Notes
FROM $ARGbases are checked against the declaredARGs;scratchand stage references are exempt from tag checks.- Rules are heuristics on the text; a clean result does not scan the image's packages.
Build and test
Tests use node:test and the SDK's in-memory transport; they do not reach the network.
Licence
MIT. See LICENSE.
来源:packages/dockerfile-lint/README.md,提交 58c8c95
工具
0版本历史
1- v0.1.1最新Oct 5, 2026


