Lint Dockerfile Online — Hadolint-Style DL Rules

Lint Dockerfiles with syntax checks plus ~26 Hadolint DL best-practice rules. ShellCheck in RUN is not included.

Loading…
Dockerfile linter — Hadolint-style DL checks
Catch latest tags, ADD vs COPY, missing USER and other high-value issues before CI runs the full Hadolint CLI.

Developer notes

• DL rules run on dockerfile-ast; syntax errors from dockerfile-utils are separate. • ShellCheck (SC*) rules are intentionally out of scope v1. • Info vs warning severities follow our DL mapping. • Pin base images after fixing DL3006/DL3007 warnings.

When teams pick this route

• Quick lint on a Dockerfile pasted in a review comment. • Educate juniors with official DL codes and wiki links. • Pre-flight check before pushing to a registry pipeline. • Compare against Hadolint CLI on small files.

Worked examples

Latest tag + ADD + apt without pins

Dockerfile input

FROM ubuntu:latest MAINTAINER [email protected] RUN apt-get update && apt-get install curl RUN echo "starting build" ADD app.tar.gz /app/ WORKDIR relative EXPOSE 80 CMD echo start

Lint highlights

Warnings: DL3007 (latest), DL4000 (MAINTAINER), DL3020 (ADD), DL3008/DL3014/DL3015 (apt), DL3000 (relative WORKDIR), DL4001 (no USER), DL3025 (shell CMD).

Improved production-style fragment

Dockerfile input

FROM ubuntu:22.04 RUN apt-get update \ && DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends curl=7.81.0-1 \ && rm -rf /var/lib/apt/lists/* COPY --chown=app:app src /app/ USER app WORKDIR /app CMD ["./server"]

Lint highlights

Fewer DL warnings — pinned apt, non-root USER, JSON CMD, COPY instead of ADD.

Navigate related DevOps tools

Format first with format Dockerfile. Compose stacks: validate Docker Compose.

Dockerfile linter FAQ

DL rules without ShellCheck

Is this full Hadolint?

No — ~26 DL rules plus syntax checks. ShellCheck inside RUN is not included in v1.

Why DL codes?

They match the official Hadolint wiki so you can compare with CI and learn remediation.

Errors vs warnings?

Syntax issues from dockerfile-utils are errors. DL rules are mostly warnings or info.

DevOps & Infra

Terraform HCL format/validate/minify, Dockerfile format & lint, Docker Compose and .env validation.

Explore other tool categories

Minify

Shrink code and assets for production — minify JavaScript, CSS, HTML, JSON and XML before gzip or CDN deploy.

Beautify

Make code readable with consistent indentation — beautify JavaScript, CSS, TypeScript, SCSS, LESS, Markdown, GraphQL, SQL, YAML and more in your browser.

Unminify

Expand minified or compressed code — unminify JavaScript, CSS, TypeScript, SCSS, LESS, SQL, YAML and other formats when debugging or reviewing.

Conversion

Transform data between JSON, YAML, XML and CSV locally — no server uploads.

CSS preprocessors

Compile SCSS or LESS to standard CSS in the browser — pair with beautify or minify for a full stylesheet workflow.

JSON Tools

Validate, format, diff and explore JSON payloads — complementary to minifiers and converters.

SVG Tools

Preview, optimize with SVGO, export Data URI, resize, beautify, convert to JSX and validate SVG — all in your browser.

CI/CD

GitHub Actions and GitLab CI — format YAML and check workflow/job structure in your browser.

Logs & observability

Line-oriented JSON/NDJSON and Nginx/Apache access logs — format, filter, validate, and CSV/TSV.

Kubernetes

Multi-doc manifests, structural validate, Ingress/Deployment starters, and Helm values formatting.

Networking / IP

CIDR, subnets, and IPv4/IPv6 helpers — in your browser.

Security & tokens

JWKS, X.509 certificates, and secrets scan — browser-local.

API & schemas

OpenAPI tools to format, validate, and lint your specs.

Encoding

Encode or decode Base64, URL components and HTML entities — client-side only.

Developer utilities

Timestamps, UUID, ULID, Nanoid, cron, passwords, regex, slugify, number bases, case, text diff, and chmod — all client-side.

Text & Markdown

Count words, build Markdown TOCs, and clean line lists — all in your browser.

AI & LLM

Token counting, pricing estimates, and context-window fit — 100% browser-local.

Serialization

Serialize and deserialize PHP data structures beside JSON workflows.