Skip to content

Add a Docker base-image pinning check to the CI-health engineΒ #362

Description

@exploreriii

πŸ§‘β€πŸŽ“ Beginner Issue β€” a well-scoped task for contributors ready to learn this codebase and own a small implementation.
Time: ~8 hours Β· Prerequisites: ~1 completed Good First Issue recommended; comfortable forking, branching, and opening a PR without a tutorial.
If that feels unfamiliar, a Good First Issue is the more rewarding path right now β€” you can always come back.

The task

Blocked by #359 β€” the ci_health engine and findings contract must exist first.

Problem:

The org's CI/CD audit checklist requires pinned Docker base images: a FROM python:3.12 can silently change under a repo, while FROM python:3.12@sha256:… cannot. No check surfaces which repos pin and which don't.

What done looks like:

A docker_pinning check in the ci_health engine: find Dockerfiles anywhere in the repo tree (the engine's tree fetch already has the file list β€” Dockerfile, *.dockerfile, Dockerfile.*), check each FROM for an @sha256: digest, and emit findings with file:line and the unpinned reference as evidence. Repos with no Dockerfiles are na, never fail. Watch the honest edge cases: multi-stage builds where a later FROM references an earlier build stage by name (not an image β€” skip those), and scratch.

Where to look first: the ci_health engine and its seed checks from #359 β€” copy their shape exactly; the na semantics are defined by its contract.

How to work on this

  1. Claim it: comment /assign and wait to be assigned β€” unassigned PRs are closed automatically.
  2. Get a plan: once assigned, comment @coderabbitai plan for a draft implementation plan. Verify it against the code β€” spotting where it's wrong is the research.
  3. Research before coding: read the files above and their tests; most of the value of this level is building an accurate picture before changing anything. The workflow guide has the mechanics.

πŸ€– AI: tools are welcome; verified work is required. You ran it, you can explain every line, your tests verify behaviour β€” see the AI policy. Fully automated bot PRs are closed.

Before opening your PR:

  • I spent real time reading the relevant code before writing any
  • The implementation works and follows the surrounding patterns
  • I added basic unit tests for what I changed, in the mirrored path tests/<pkg>/test_<module>.py (testing guide)
  • uv run pytest and uv run ruff check src tests pass; scope is limited to this issue
  • The basics from your first issue still apply β€” signed commits, linked issue, clean history (quick refs)

Stuck? Comment here with what you've tried β€” see getting help.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    beginnerA very narrow issue requiring some research or self-directionpythonTouches Python code (src/, tests/)

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions