Dockerfile Lint

io.github.basitalisandhuv0.1.1更新于 Oct 5, 2026

Lint Dockerfiles for root users, latest tags, secrets in ENV or ARG, missing HEALTHCHECK and more.

概览

AI 生成的概览

检查 Dockerfile 中的生产镜像常见问题,例如以 root 运行、使用 latest 标签、在 ENV 或 ARG 中写入密钥。

功能
解析 Dockerfile,包括注释、escape 指令、续行、heredoc 和多阶段构建,然后对其运行静态检查规则。lint_dockerfile 工具返回包含规则编号、严重级别、行号和修复建议的结果;parse_dockerfile 返回指令、行范围、阶段和基础镜像;explain_rule 说明单条规则。不会调用 Docker 本身。
适用场景
适合在构建镜像前审查或加固 Dockerfile,或让助手在不执行构建的情况下检查 Dockerfile 的常见生产隐患。
运行要求
以 npm 包(npx)或从代码检出配合 Node.js 在本地通过 stdio 运行;无需网络、账号或 API 密钥。它只读取你指定的单个 Dockerfile 路径或内容,最大 1 MB。
安装前请注意
只做只读静态分析:不会构建镜像或修改文件。检查结果基于文本启发式规则,因此无问题并不代表构建出的镜像安全或没有存在漏洞的软件包。

安装

在 SourceWeft 中

  1. 打开 控制台中的 Dockerfile Lint,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。

其他 MCP 客户端

参照 仓库 中的启动说明。

README

dockerfile-lint MCP server

Parses Dockerfiles (comments, escape directive, line continuations, heredocs, multi-stage builds) and lints them for the mistakes that matter in production images. Static analysis only; Docker is never invoked.

Part of dev-mcp-servers. Stdio transport only; the server never opens a port.

Tools

ToolInputWhat it returns
lint_dockerfilepath or content, ignore?Findings with rule id, severity, line and fix: final stage running as root, latest or missing tags, no digest, credential-like ENV/ARG names and literals, missing HEALTHCHECK, apt-get without cleanup or --no-install-recommends, apt-get upgrade, apk add without --no-cache, pip without --no-cache-dir, ADD for plain files or URLs, `curl
parse_dockerfilepath or contentInstructions with line ranges and stage index, stages with AS names and base images, escape character.
explain_ruleruleSeverity, description and fix for one rule.

Install

Claude Code:

bash
claude mcp add dockerfile-lint -- npx -y @basitalisandhu/[email protected]

Add -s user to make it available in every project. Any client that reads .mcp.json (Claude Code, Claude Desktop, Cursor):

json
{  "mcpServers": {    "dockerfile-lint": {      "command": "npx",      "args": ["-y", "@basitalisandhu/[email protected]"]    }  }}

Pin the version as shown so that an update to the package cannot change what runs in your editor without you noticing. From a checkout, use "command": "node", "args": ["<path>/packages/dockerfile-lint/dist/index.js"] after npm install && npm run build at the repository root.

What it touches

  • Network: None.
  • Local files: Reads the one file you name, up to 1 MB.
  • Telemetry: none.

Notes

  • FROM $ARG bases are checked against the declared ARGs; scratch and stage references are exempt from tag checks.
  • Rules are heuristics on the text; a clean result does not scan the image's packages.

Build and test

bash
npm install        # at the repository rootnpm run build -w @basitalisandhu/mcp-dockerfile-lintnpm test -w @basitalisandhu/mcp-dockerfile-lint

Tests use node:test and the SDK's in-memory transport; they do not reach the network.

Licence

MIT. See LICENSE.

来源:packages/dockerfile-lint/README.md,提交 58c8c95

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v0.1.1最新Oct 5, 2026