# hadolint configuration for pi-devbox. # # Both Dockerfiles are linted in CI (.gitea/workflows/lint.yml → `hadolint` # job). hadolint reads this file automatically, so a local # `hadolint Dockerfile.base` reproduces CI exactly. # # The ignores below are DELIBERATE project choices — they mirror the # philosophy of the shellcheck excludes already applied to `run:` steps # (SHELLCHECK_OPTS in lint.yml). Anything NOT listed here still fails the # build at `warning` and above, so new Dockerfile smells are caught going # forward. ignored: - DL3008 # "pin apt versions" — intentionally unpinned: the base tracks # Debian stable and runs `apt-get upgrade`, so pinning point # versions would rot and fight security updates. - DL3016 # "pin npm versions" — pi's version IS pinned, but via the # PI_VERSION build-arg (CI-resolved from npm), not the npm CLI. - DL4006 # "set -o pipefail before a pipe" — the piped RUNs are # download|extract steps with their own retries / `set -e`. # Switching the global SHELL to bash is a larger, base-affecting # change — tracked in IDEAS.md. - DL3003 # "use WORKDIR, not cd" — cosmetic in the few `cd` RUNs here. - SC2086 # "double-quote to prevent word-splitting" — the same code is # excluded for shell `run:` steps in lint.yml; splitting is # intentional in these contexts. failure-threshold: warning