From 3fc0696d099f1d4c18001f22d355133081db11a4 Mon Sep 17 00:00:00 2001 From: Gonzalo Diaz Date: Sun, 20 Sep 2026 19:36:22 -0300 Subject: [PATCH] Add Hadolint workflow for Dockerfile linting This workflow configures Hadolint to run on pushes and pull requests to the main branch, as well as on a schedule. It includes steps to check out the code, run Hadolint, and upload the results in SARIF format. --- .github/workflows/hadolint.yml | 52 ++++++++++++++++++++++++++++++++++ 1 file changed, 52 insertions(+) create mode 100644 .github/workflows/hadolint.yml diff --git a/.github/workflows/hadolint.yml b/.github/workflows/hadolint.yml new file mode 100644 index 0000000..e5ef074 --- /dev/null +++ b/.github/workflows/hadolint.yml @@ -0,0 +1,52 @@ +# This workflow uses actions that are not certified by GitHub. +# They are provided by a third-party and are governed by +# separate terms of service, privacy policy, and support +# documentation. +# hadoint is a Dockerfile linter written in Haskell +# that helps you build best practice Docker images. +# More details at https://github.com/hadolint/hadolint + +--- +name: Hadolint + +on: # yamllint disable-line rule:truthy + push: + branches: ["main"] + pull_request: + # The branches below must be a subset of the branches above + branches: ["main"] + schedule: + - cron: '33 15 * * 3' + +permissions: + contents: read + +jobs: + hadolint: + name: Run hadolint scanning + runs-on: ubuntu-26.04 + permissions: + # for actions/checkout to fetch code + contents: read + # for github/codeql-action/upload-sarif to upload SARIF results + security-events: write + # only required for a private repository by + # github/codeql-action/upload-sarif to get the Action run status + actions: read + steps: + - name: Checkout code + uses: actions/checkout@v7.0.1 + + - name: Run hadolint + uses: hadolint/hadolint-action@v3.5.0 + with: + dockerfile: ./Dockerfile + format: sarif + output-file: hadolint-results.sarif + no-fail: true + + - name: Upload analysis results to GitHub + uses: github/codeql-action/upload-sarif@v4.38.1 + with: + sarif_file: hadolint-results.sarif + wait-for-processing: true