291ae5345e
Repo/CI hygiene batch (none base-affecting; image contents unchanged): - LICENSE: actual MIT file (repo previously declared MIT only in prose). - THIRD_PARTY.md: notes bundled software + licenses (pi/pi-fork/pi-obsmem/ pi-studio MIT, gosu Apache-2.0, Debian packages under their own terms). - .dockerignore: trims build context to what the Dockerfiles COPY (rootfs/ + entrypoint*.sh); keeps .git/docs/scripts/compose out. Verified it excludes none of the required COPY sources. - lint.yml: new hadolint job (pinned v2.14.0) lints both Dockerfiles; .hadolint.yaml grandfathers deliberate choices (DL3008/DL3016/DL4006/DL3003/ SC2086, mirroring the shellcheck excludes), fails on anything new at warning+. Verified hadolint exit 0 and the repo shell-guard passes with the new job. - IDEAS.md: parks deferred follow-ups (SHA-pin actions, trivy, buildx SBOM/ provenance, Makefile, renovate). - README/DOCKER_HUB License sections now link LICENSE + THIRD_PARTY.md. No tag.
28 lines
1.4 KiB
YAML
28 lines
1.4 KiB
YAML
# hadolint configuration for pi-devbox.
|
|
#
|
|
# Both Dockerfiles are linted in CI (.gitea/workflows/lint.yml → `hadolint`
|
|
# job). hadolint reads this file automatically, so a local
|
|
# `hadolint Dockerfile.base` reproduces CI exactly.
|
|
#
|
|
# The ignores below are DELIBERATE project choices — they mirror the
|
|
# philosophy of the shellcheck excludes already applied to `run:` steps
|
|
# (SHELLCHECK_OPTS in lint.yml). Anything NOT listed here still fails the
|
|
# build at `warning` and above, so new Dockerfile smells are caught going
|
|
# forward.
|
|
ignored:
|
|
- DL3008 # "pin apt versions" — intentionally unpinned: the base tracks
|
|
# Debian stable and runs `apt-get upgrade`, so pinning point
|
|
# versions would rot and fight security updates.
|
|
- DL3016 # "pin npm versions" — pi's version IS pinned, but via the
|
|
# PI_VERSION build-arg (CI-resolved from npm), not the npm CLI.
|
|
- DL4006 # "set -o pipefail before a pipe" — the piped RUNs are
|
|
# download|extract steps with their own retries / `set -e`.
|
|
# Switching the global SHELL to bash is a larger, base-affecting
|
|
# change — tracked in IDEAS.md.
|
|
- DL3003 # "use WORKDIR, not cd" — cosmetic in the few `cd` RUNs here.
|
|
- SC2086 # "double-quote to prevent word-splitting" — the same code is
|
|
# excluded for shell `run:` steps in lint.yml; splitting is
|
|
# intentional in these contexts.
|
|
|
|
failure-threshold: warning
|