Multi-stage Dockerfile: pin base image, add test/lint stages
Pin alpine:latest to the full patch-level tag alpine:3.22.1 so Renovate can classify patch/minor/major bumps on it. Add a `test` stage (bats) and a `lint` stage (shellcheck, severity=error) that build from `base` before ENTRYPOINT is set, so CI can run them without an --entrypoint override. A trailing `FROM base` keeps the lean prod image as the default `docker build .` target despite the extra stages.
This commit is contained in:
+17
-1
@@ -1,4 +1,4 @@
|
||||
FROM alpine:latest
|
||||
FROM alpine:3.22.1 AS base
|
||||
|
||||
RUN apk add --no-cache socat netcat-openbsd \
|
||||
&& rm -rf /var/cache/apk/* /tmp/*
|
||||
@@ -7,4 +7,20 @@ COPY entrypoint.sh VERSION /
|
||||
RUN mkdir -p /socket \
|
||||
&& chmod +x /entrypoint.sh
|
||||
|
||||
FROM base AS test
|
||||
|
||||
RUN apk add --no-cache bats bash procps
|
||||
|
||||
WORKDIR /app
|
||||
COPY entrypoint.sh VERSION /app/
|
||||
COPY tests/ /app/tests/
|
||||
|
||||
FROM base AS lint
|
||||
|
||||
RUN apk add --no-cache shellcheck
|
||||
RUN shellcheck --severity=error -s sh /entrypoint.sh
|
||||
|
||||
# Kept as the last stage so `docker build .` (no --target) still produces
|
||||
# the lean prod image, not the `test`/`lint` stages above.
|
||||
FROM base
|
||||
ENTRYPOINT ["/entrypoint.sh"]
|
||||
Reference in New Issue
Block a user