π§βπ Beginner Issue β a well-scoped task for contributors ready to learn this codebase and own a small implementation.
Time: ~8 hours Β· Prerequisites: ~1 completed Good First Issue recommended; comfortable forking, branching, and opening a PR without a tutorial.
If that feels unfamiliar, a Good First Issue is the more rewarding path right now β you can always come back.
The task
Blocked by #359 β the ci_health engine and findings contract must exist first.
Problem:
The org's CI/CD audit checklist requires pinned Docker base images: a FROM python:3.12 can silently change under a repo, while FROM python:3.12@sha256:β¦ cannot. No check surfaces which repos pin and which don't.
What done looks like:
A docker_pinning check in the ci_health engine: find Dockerfiles anywhere in the repo tree (the engine's tree fetch already has the file list β Dockerfile, *.dockerfile, Dockerfile.*), check each FROM for an @sha256: digest, and emit findings with file:line and the unpinned reference as evidence. Repos with no Dockerfiles are na, never fail. Watch the honest edge cases: multi-stage builds where a later FROM references an earlier build stage by name (not an image β skip those), and scratch.
Where to look first: the ci_health engine and its seed checks from #359 β copy their shape exactly; the na semantics are defined by its contract.
How to work on this
- Claim it: comment
/assign and wait to be assigned β unassigned PRs are closed automatically.
- Get a plan: once assigned, comment
@coderabbitai plan for a draft implementation plan. Verify it against the code β spotting where it's wrong is the research.
- Research before coding: read the files above and their tests; most of the value of this level is building an accurate picture before changing anything. The workflow guide has the mechanics.
π€ AI: tools are welcome; verified work is required. You ran it, you can explain every line, your tests verify behaviour β see the AI policy. Fully automated bot PRs are closed.
Before opening your PR:
Stuck? Comment here with what you've tried β see getting help.
The task
Blocked by #359 β the ci_health engine and findings contract must exist first.
Problem:
The org's CI/CD audit checklist requires pinned Docker base images: a
FROM python:3.12can silently change under a repo, whileFROM python:3.12@sha256:β¦cannot. No check surfaces which repos pin and which don't.What done looks like:
A
docker_pinningcheck in the ci_health engine: find Dockerfiles anywhere in the repo tree (the engine's tree fetch already has the file list βDockerfile,*.dockerfile,Dockerfile.*), check eachFROMfor an@sha256:digest, and emit findings withfile:lineand the unpinned reference as evidence. Repos with no Dockerfiles arena, neverfail. Watch the honest edge cases: multi-stage builds where a laterFROMreferences an earlier build stage by name (not an image β skip those), andscratch.Where to look first: the ci_health engine and its seed checks from #359 β copy their shape exactly; the
nasemantics are defined by its contract.How to work on this
/assignand wait to be assigned β unassigned PRs are closed automatically.@coderabbitai planfor a draft implementation plan. Verify it against the code β spotting where it's wrong is the research.π€ AI: tools are welcome; verified work is required. You ran it, you can explain every line, your tests verify behaviour β see the AI policy. Fully automated bot PRs are closed.
Before opening your PR:
tests/<pkg>/test_<module>.py(testing guide)uv run pytestanduv run ruff check src testspass; scope is limited to this issueStuck? Comment here with what you've tried β see getting help.