Skip to main content

pindock

Pin and update Docker image digests in Dockerfiles and compose files

PyPI: Version AUR: version GitHub: Release Docker: ghcr CI: Main CI: Coverage

InstallationUsagePre-commit

Installation

# PyPI
uv tool install pindock

# AUR
yay -S pindock-bin

# Docker
docker pull ghcr.io/deadnews/pindock

Usage

Usage: pindock <command> [flags]

Pin and update Docker image digests.

Commands:
  run      Pin unpinned image digests.
  check    Verify all images are pinned.

run flags:
  -C, --dir=.      Directory to scan.
  -u, --update     Also update tags and pinned digests to latest.
  -v, --verbose    Show all images, including pinned.

check flags:
  -C, --dir=.      Directory to scan.
  -u, --update     Also check tags and pinned digests for updates.
  -v, --verbose    Show all images, including pinned.
  • When no files are given, pindock auto-discovers files recursively.
  • latest and untagged images are pinned to the version tag pointing at the same digest (2.0.1 preferred over 2.0 and 2).
  • --update never moves a version tag past the version latest points to; prerelease tags (-rc, -alpha, -beta) are not capped.

Supported files

  • Dockerfile, Containerfile (and variants like Dockerfile.dev, *.dockerfile)
  • compose*.yml, docker-compose*.yml (and .yaml)

Supported instructions

Dockerfile Compose
FROM [--platform=...] image:tag[@digest] [AS name] image: image:tag[@digest]
COPY --from=image:tag[@digest] ...
RUN --mount=from=image:tag[@digest],... ...

Authentication

Uses existing Docker credentials. If you can docker pull, pindock works too.

Pre-commit

repos:
  - repo: https://github.com/deadnews/pindock
    rev: v1.0.0
    hooks:
      - id: pindock
      - id: pindock-check

      # example with args
      - id: pindock-check
        args: [--update, --verbose]

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distributions

No source distribution files available for this release.See tutorial on generating distribution archives.

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

pindock-1.1.0-py3-none-win_arm64.whl (3.6 MB view details)

Uploaded Python 3Windows ARM64

pindock-1.1.0-py3-none-win_amd64.whl (4.0 MB view details)

Uploaded Python 3Windows x86-64

pindock-1.1.0-py3-none-musllinux_1_2_x86_64.whl (3.9 MB view details)

Uploaded Python 3musllinux: musl 1.2+ x86-64

pindock-1.1.0-py3-none-musllinux_1_2_aarch64.whl (3.5 MB view details)

Uploaded Python 3musllinux: musl 1.2+ ARM64

pindock-1.1.0-py3-none-manylinux_2_17_x86_64.whl (3.9 MB view details)

Uploaded Python 3manylinux: glibc 2.17+ x86-64

pindock-1.1.0-py3-none-manylinux_2_17_aarch64.whl (3.5 MB view details)

Uploaded Python 3manylinux: glibc 2.17+ ARM64

pindock-1.1.0-py3-none-macosx_11_0_arm64.whl (3.6 MB view details)

Uploaded Python 3macOS 11.0+ ARM64

pindock-1.1.0-py3-none-macosx_10_9_x86_64.whl (3.9 MB view details)

Uploaded Python 3macOS 10.9+ x86-64

File details

Details for the file pindock-1.1.0-py3-none-win_arm64.whl.

File metadata

  • Download URL: pindock-1.1.0-py3-none-win_arm64.whl
  • Upload date:
  • Size: 3.6 MB
  • Tags: Python 3, Windows ARM64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for pindock-1.1.0-py3-none-win_arm64.whl
Algorithm Hash digest
SHA256 3c98709775f3f7febc87193493189ada741991b515fd2f03046a60357233c15c
MD5 0f90912af8acc904a24748ff37e66f8c
BLAKE2b-256 a9e90851d90f0f693729282acc46dd914126aa5b3e2b5ec5a44bf1645580af2f

See more details on using hashes here.

Provenance

The following attestation bundles were made for pindock-1.1.0-py3-none-win_arm64.whl:

Publisher: main.yml on deadnews/pindock

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file pindock-1.1.0-py3-none-win_amd64.whl.

File metadata

  • Download URL: pindock-1.1.0-py3-none-win_amd64.whl
  • Upload date:
  • Size: 4.0 MB
  • Tags: Python 3, Windows x86-64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for pindock-1.1.0-py3-none-win_amd64.whl
Algorithm Hash digest
SHA256 9ea5b561b515fe0aca4723fa2e438eb7bc2936cb9503c58cc669e69eb6691366
MD5 8e4495fd565b9260b4c7750c4e13f192
BLAKE2b-256 eca10609a987ea2dfd5066a781090e4a97c51040866d7af60b4dbcc23e17cbe3

See more details on using hashes here.

Provenance

The following attestation bundles were made for pindock-1.1.0-py3-none-win_amd64.whl:

Publisher: main.yml on deadnews/pindock

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file pindock-1.1.0-py3-none-musllinux_1_2_x86_64.whl.

File metadata

File hashes

Hashes for pindock-1.1.0-py3-none-musllinux_1_2_x86_64.whl
Algorithm Hash digest
SHA256 9ea4937c6f60e60ba2706395b437d81cb236f3088d287bfcc528cd58d31a61e0
MD5 da5486b7514b0e024073fef2e59d6538
BLAKE2b-256 2d7019a48a936e1677e474ed60a75f5b51a5f337b60c8e237c7b629762aeefbe

See more details on using hashes here.

Provenance

The following attestation bundles were made for pindock-1.1.0-py3-none-musllinux_1_2_x86_64.whl:

Publisher: main.yml on deadnews/pindock

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file pindock-1.1.0-py3-none-musllinux_1_2_aarch64.whl.

File metadata

File hashes

Hashes for pindock-1.1.0-py3-none-musllinux_1_2_aarch64.whl
Algorithm Hash digest
SHA256 d2b4c053fa3d944c7ec4495968eaa8eeba458685df250bf4ff70c61409bf9503
MD5 8d6c4b6191fe765a3043c960c12f01ac
BLAKE2b-256 873406bca9247a60717e0c8d025d5269a04495616423d0c1d71230af620455ee

See more details on using hashes here.

Provenance

The following attestation bundles were made for pindock-1.1.0-py3-none-musllinux_1_2_aarch64.whl:

Publisher: main.yml on deadnews/pindock

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file pindock-1.1.0-py3-none-manylinux_2_17_x86_64.whl.

File metadata

File hashes

Hashes for pindock-1.1.0-py3-none-manylinux_2_17_x86_64.whl
Algorithm Hash digest
SHA256 e3b0a3073988456af11a060a4f14e550abad7ce2b98a0f0122fd114384bee30c
MD5 e1ae0c7ea1245c5fde93225cc28a1ee9
BLAKE2b-256 53a18bbda3fca772dbcd508d11e60fc74d4d0f6bd0064c3974f05b0d46bf35bc

See more details on using hashes here.

Provenance

The following attestation bundles were made for pindock-1.1.0-py3-none-manylinux_2_17_x86_64.whl:

Publisher: main.yml on deadnews/pindock

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file pindock-1.1.0-py3-none-manylinux_2_17_aarch64.whl.

File metadata

File hashes

Hashes for pindock-1.1.0-py3-none-manylinux_2_17_aarch64.whl
Algorithm Hash digest
SHA256 f845585b3a2d7f27c737d6f30cac04b9b13b6acaf3e6ff68b4bc190702040f1c
MD5 3074d54004d0ed4ade9ed5657e73843c
BLAKE2b-256 22f2e7d3e910267fc584edd307a7ef6170f6e86bd74a8f60ec132159eb7a89cd

See more details on using hashes here.

Provenance

The following attestation bundles were made for pindock-1.1.0-py3-none-manylinux_2_17_aarch64.whl:

Publisher: main.yml on deadnews/pindock

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file pindock-1.1.0-py3-none-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for pindock-1.1.0-py3-none-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 046cd9e890ed23167af506c9804873f5c22a7eca90665f08c78a3de2c04157cc
MD5 82a4a75123a94143c70c4a42e482f064
BLAKE2b-256 ceef6bdf867c0ce27171a94f19e89cfc121ca1568e5ea5f68a0bdd83a955fba4

See more details on using hashes here.

Provenance

The following attestation bundles were made for pindock-1.1.0-py3-none-macosx_11_0_arm64.whl:

Publisher: main.yml on deadnews/pindock

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file pindock-1.1.0-py3-none-macosx_10_9_x86_64.whl.

File metadata

File hashes

Hashes for pindock-1.1.0-py3-none-macosx_10_9_x86_64.whl
Algorithm Hash digest
SHA256 91764f4df1ccd93dadfe9d7a59777fb1a76440a03375d9e3cb9f40053708814e
MD5 f16567cb9ba4ea8d43394f41d1b208d8
BLAKE2b-256 b698a084aecf5c5cfd58099296e7121473e957cccbad8f829227de4e3ab5e9df

See more details on using hashes here.

Provenance

The following attestation bundles were made for pindock-1.1.0-py3-none-macosx_10_9_x86_64.whl:

Publisher: main.yml on deadnews/pindock

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page