Dockerfile Lint

io.github.basitalisandhuv0.1.1更新於 Oct 5, 2026

Lint Dockerfiles for root users, latest tags, secrets in ENV or ARG, missing HEALTHCHECK and more.

概覽

AI 產生的概覽

檢查 Dockerfile 中常見的正式環境映像問題,例如以 root 執行、使用 latest 標籤、在 ENV 或 ARG 中寫入密鑰。

功能
解析 Dockerfile,包括註解、escape 指令、續行、heredoc 與多階段建置,然後對其執行靜態檢查規則。lint_dockerfile 工具會回傳包含規則編號、嚴重性、行號與修正建議的結果;parse_dockerfile 回傳指令、行範圍、階段與基礎映像;explain_rule 說明單一規則。不會呼叫 Docker 本身。
適用情境
適合在建置映像前審查或強化 Dockerfile,或讓助理在不執行建置的情況下檢查 Dockerfile 的常見正式環境隱患。
執行需求
以 npm 套件(npx)或從程式碼檢出搭配 Node.js 在本機透過 stdio 執行;不需要網路、帳號或 API 金鑰。它只讀取你指定的單一 Dockerfile 路徑或內容,最大 1 MB。
安裝前請注意
只做唯讀靜態分析:不會建置映像或修改檔案。檢查結果是文字啟發式規則,因此沒有問題並不代表建置出的映像安全或沒有含漏洞的套件。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Dockerfile Lint,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

dockerfile-lint MCP server

Parses Dockerfiles (comments, escape directive, line continuations, heredocs, multi-stage builds) and lints them for the mistakes that matter in production images. Static analysis only; Docker is never invoked.

Part of dev-mcp-servers. Stdio transport only; the server never opens a port.

Tools

ToolInputWhat it returns
lint_dockerfilepath or content, ignore?Findings with rule id, severity, line and fix: final stage running as root, latest or missing tags, no digest, credential-like ENV/ARG names and literals, missing HEALTHCHECK, apt-get without cleanup or --no-install-recommends, apt-get upgrade, apk add without --no-cache, pip without --no-cache-dir, ADD for plain files or URLs, `curl
parse_dockerfilepath or contentInstructions with line ranges and stage index, stages with AS names and base images, escape character.
explain_ruleruleSeverity, description and fix for one rule.

Install

Claude Code:

bash
claude mcp add dockerfile-lint -- npx -y @basitalisandhu/[email protected]

Add -s user to make it available in every project. Any client that reads .mcp.json (Claude Code, Claude Desktop, Cursor):

json
{  "mcpServers": {    "dockerfile-lint": {      "command": "npx",      "args": ["-y", "@basitalisandhu/[email protected]"]    }  }}

Pin the version as shown so that an update to the package cannot change what runs in your editor without you noticing. From a checkout, use "command": "node", "args": ["<path>/packages/dockerfile-lint/dist/index.js"] after npm install && npm run build at the repository root.

What it touches

  • Network: None.
  • Local files: Reads the one file you name, up to 1 MB.
  • Telemetry: none.

Notes

  • FROM $ARG bases are checked against the declared ARGs; scratch and stage references are exempt from tag checks.
  • Rules are heuristics on the text; a clean result does not scan the image's packages.

Build and test

bash
npm install        # at the repository rootnpm run build -w @basitalisandhu/mcp-dockerfile-lintnpm test -w @basitalisandhu/mcp-dockerfile-lint

Tests use node:test and the SDK's in-memory transport; they do not reach the network.

Licence

MIT. See LICENSE.

來源:packages/dockerfile-lint/README.md,提交 58c8c95

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.1.1最新Oct 5, 2026