d73ff9b0fb
Deploy Site / deploy-vercel (push) Has been cancelled
Deploy Site / deploy-docs (push) Has been cancelled
Docker / shell lint / Lint Dockerfile (hadolint) (push) Has been cancelled
Docker / shell lint / Lint docker/ shell scripts (shellcheck) (push) Has been cancelled
Docker Build and Publish / build-amd64 (push) Has been cancelled
Docker Build and Publish / build-arm64 (push) Has been cancelled
Lint (ruff + ty) / ruff + ty diff (push) Has been cancelled
Lint (ruff + ty) / ruff enforcement (blocking) (push) Has been cancelled
Lint (ruff + ty) / Windows footguns (blocking) (push) Has been cancelled
Nix Lockfile Fix / auto-fix-main (push) Has been cancelled
Nix Lockfile Fix / fix (push) Has been cancelled
Nix / nix (macos-latest) (push) Has been cancelled
Nix / nix (ubuntu-latest) (push) Has been cancelled
OSV-Scanner / Scan lockfiles (push) Has been cancelled
Build Skills Index / build-index (push) Has been cancelled
Tests / test (1) (push) Has been cancelled
Tests / test (2) (push) Has been cancelled
Tests / test (3) (push) Has been cancelled
Tests / test (4) (push) Has been cancelled
Tests / test (5) (push) Has been cancelled
Tests / test (6) (push) Has been cancelled
Tests / e2e (push) Has been cancelled
uv.lock check / uv lock --check (push) Has been cancelled
Docker Build and Publish / merge (push) Has been cancelled
Build Skills Index / trigger-deploy (push) Has been cancelled
Tests / save-durations (push) Has been cancelled
37 lines
1.6 KiB
YAML
37 lines
1.6 KiB
YAML
# hadolint configuration for the Hermes Agent Dockerfile.
|
|
# See https://github.com/hadolint/hadolint#configure for rules.
|
|
#
|
|
# We want hadolint to surface NEW Dockerfile lint regressions, but we
|
|
# don't want to rewrite the existing image to silence rules that are
|
|
# either intentional or pragmatic tradeoffs for this project. Each
|
|
# ignore below has a one-line justification.
|
|
failure-threshold: warning
|
|
|
|
ignored:
|
|
# Pin versions in apt get install. We intentionally don't pin common
|
|
# tools (curl, git, openssh-client, etc.) — security updates flow in
|
|
# via the periodic base-image rebuild, and pinning would lock us to
|
|
# superseded patch releases. Same rationale as nearly every distro-
|
|
# base official image (python, node, debian).
|
|
- DL3008
|
|
# Use WORKDIR to switch to a directory. The image uses `(cd web && …)`
|
|
# / `(cd ../ui-tui && …)` inline subshells for one-off build steps
|
|
# because they don't affect later RUN commands; promoting them to
|
|
# full WORKDIR switches with restores would obscure intent.
|
|
- DL3003
|
|
# Multiple consecutive RUN instructions. The `touch README.md` + `uv
|
|
# sync` split is intentional — `touch` is cheap, `uv sync` is the
|
|
# expensive layer-cached step we want isolated, and merging them
|
|
# would invalidate the cache for trivial changes.
|
|
- DL3059
|
|
# Last USER should not be root. /init (s6-overlay) runs as root so the
|
|
# stage2 hook can usermod/groupmod and chown the data volume per
|
|
# HERMES_UID at runtime; each supervised service then drops to the
|
|
# hermes user via `s6-setuidgid`.
|
|
- DL3002
|
|
|
|
# Require explicit base-image pins (SHA256) — we already do this.
|
|
trustedRegistries:
|
|
- docker.io
|
|
- ghcr.io
|