Skip to main content

tesserakit-dockerfile

Lint Dockerfiles for image hygiene and security.

tessera-dockerfile parses Dockerfiles (handling line continuations and multi-stage builds), inventories their instructions, and flags common hygiene and security problems. No image is built and nothing is executed.

Lint

tessera dockerfile lint --input . --output ./out/dockerfile_pack
tessera dockerfile lint --input Dockerfile --output ./out/dockerfile_pack

Recognizes Dockerfile, Dockerfile.*, and *.dockerfile.

Artifacts written:

instructions.jsonl       one Instruction per parsed line (with build stage)
index.md                 instruction inventory + stage list
validation_report.md     hygiene + security findings
coverage_report.md       instruction frequency

Lint rules

  • unpinned_base_image — FROM image with no tag (implicitly :latest)
  • latest_tag — FROM image:latest
  • runs_as_root — no USER instruction; the container runs as root
  • secret_in_image — ENV/ARG bakes a secret-named value into an image layer
  • add_instead_of_copy — ADD used for local files (prefer COPY)
  • missing_healthcheck — no HEALTHCHECK instruction (info)

Multi-stage builds are understood: a FROM <stage> that references an earlier AS <stage> is not flagged as an unpinned base image.

Metadata

Release files for tesserakit-dockerfile 0.4.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for tesserakit-dockerfile 0.4.0
File Size Uploaded
tesserakit_dockerfile-0.4.0.tar.gz 6.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for tesserakit-dockerfile 0.4.0
File Interpreter ABI Platform
tesserakit_dockerfile-0.4.0-py3-none-any.whl Python 3 none any Details

Total release size: 15.2 kB

Release files / tesserakit_dockerfile-0.4.0.tar.gz

Download URL tesserakit_dockerfile-0.4.0.tar.gz
Size 6.5 kB
Tags Source
SHA-256 checksum
How to use checksums
9a980ca61be5ca01b43b6fbcc2996c0ee838f29a889cb55d0617898665146db5
BLAKE2b-256 checksum
How to use checksums
3b81eae28bc0fc512808ab04399a3eb2e1d9e4015df062b4fae4e1cc683f2b17
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.11

Release files / tesserakit_dockerfile-0.4.0-py3-none-any.whl

Download URL tesserakit_dockerfile-0.4.0-py3-none-any.whl
Size 8.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
66ed368497ff95b711424b4ef9969421121bf4ef0fb7e523c872e1da62d9cbb3
BLAKE2b-256 checksum
How to use checksums
f21284747aa0767cb75d4d115b35db91087cf3568cb785b75c69079530b15fe5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.11

Release history Release notifications | RSS feed

This release

0.4.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page