🐋

Dockerfile Linter — Optimize & Secure Your Container Builds

Lint Dockerfile instructions for best practices, security issues, and layer optimization. Flags unpinned base images, root user, ADD vs COPY, apt-get mistakes, shell-form CMD, and more — with fix guidance for each issue.

Devops ToolsDevOps & Infrastructure
Loading tool...

How to Use Dockerfile Linter — Optimize & Secure Your Container Builds

How to Use the Dockerfile Linter

Step 1: Paste Your Dockerfile

Copy your entire Dockerfile and paste it into the input area. The linter parses all instructions including multi-line RUN commands joined with backslash continuations.

Step 2: Review the Summary

The summary bar shows the total issue count broken down by severity — errors (critical, must fix), warnings (important best practices), and info (recommendations). The instruction count confirms how many Dockerfile statements were successfully parsed.

Step 3: Expand Issues for Details

Click any issue card to expand it and see a full explanation of why the practice is problematic, plus a concrete fix suggestion you can copy directly into your Dockerfile.

Step 4: Try the Example Dockerfiles

Use the example buttons to see the linter in action on a naive Dockerfile (many issues), a typical Node.js app Dockerfile (some issues), and a production-ready multi-stage Dockerfile (minimal issues). These examples illustrate how each rule applies in practice.

Checks Performed

SeverityCheckWhat It Catches
ErrorMissing FROMDockerfile with no base image
WarningUnpinned base imageFROM node (no tag) or FROM node:latest
WarningRoot userNo USER instruction or explicit USER root
WarningADD vs COPYADD used for local files instead of COPY
Warningapt-get without -yInteractive prompt would hang the build
Warningapt cache not clearedrm -rf /var/lib/apt/lists/* missing
Warningapt-get update aloneStandalone update creates stale cache layer
WarningShell-form CMD/ENTRYPOINTPoor signal handling, PID 1 is shell
WarningSecrets in ENVPASSWORD, SECRET, TOKEN, API_KEY in ENV
WarningSource before manifestsLayer cache busted on every code change
InfoNo WORKDIRFiles land in root directory
InfoMany RUN layers5+ separate RUN commands bloat image
InfoNo EXPOSEPort not documented
InfoNo HEALTHCHECKOrchestrators cannot detect unhealthy containers

Frequently Asked Questions

Most Viewed Tools

📺

Screen Size Converter — Diagonal Dimension Tool

7,407 views

Calculate screen width and height from diagonal size and aspect ratio. Convert between inches and centimeters for displays, TVs, and monitors with instant dimension calculations.

Use Tool →
🖨️

DPI Calculator — Print Resolution Tool

5,691 views

Calculate DPI (dots per inch), image dimensions, and print sizes. Convert between pixels and physical dimensions for printing and displays.

Use Tool →
🔐

TOTP Code Generator — 2FA Testing Tool

3,909 views

Generate time-based one-time passwords from a TOTP secret key. Enter your base32 secret, choose a period and digit length, and get the current and next codes with a live countdown timer. Useful for testing and debugging 2FA integrations.

Use Tool →
🔑

Password Entropy Calculator — Crack Time Estimator

3,836 views

Calculate the information-theoretic bit entropy of any password or API key. Detects character set pools automatically, shows the total number of possible combinations, and estimates crack time across five attack scenarios from rate-limited web logins to GPU cracking clusters.

Use Tool →
{}

JSONL Formatter — Line-by-Line Validator

3,786 views

Format, validate, and inspect JSON Lines (JSONL) and NDJSON files. Validates each line individually, reports parse errors by line number, outputs compact JSONL or a pretty-print preview, and lets you download the cleaned file.

Use Tool →
⏱️

Seconds to Time Converter — HH:MM:SS Formatter

3,743 views

Convert seconds to HH:MM:SS time format instantly with precise calculations and easy-to-read formatting.

Use Tool →
{ }

JSON to Zod — Schema Generator

3,644 views

Generate Zod validation schema code from a JSON sample object. Infers z.string(), z.number(), z.boolean(), z.array(), z.object(), and z.null() types automatically. Handles nested objects, arrays of objects with optional field detection, and outputs copy-ready TypeScript with import and z.infer type alias.

Use Tool →
🔐

TLS Cipher Suite Checker — Strength Analyzer

3,550 views

Check TLS protocol version compatibility and cipher suite strength ratings against current best practices. Supports IANA and OpenSSL cipher names — rates each suite as Strong, Weak, or Deprecated and explains why.

Use Tool →

Related DevOps & Infrastructure Tools

⚙️

GitHub Actions Validator — Workflow Syntax & CI/CD Security Audit

Validate GitHub Actions workflow YAML for syntax errors, missing required fields, deprecated commands, mutable action refs, outdated action versions, and broken job dependencies. Get per-job results with fix hints in real time.

Use Tool →
🔭

OpenTelemetry Span Builder — Construct, Validate, and Export OTel Spans

Configure span name and attributes and events and generate OpenTelemetry span setup code for popular SDKs

Use Tool →
🪣

AWS S3 CORS Generator — Build, Audit, and Export S3 CORS Policies

Configure allowed origins/methods/headers and generate the S3 bucket CORS JSON policy

Use Tool →
📈

Prometheus Query Builder — Visual PromQL Generator & Alert Modeler

Build Prometheus PromQL queries with metric name/labels/aggregation and generate the query string

Use Tool →
🔍

User Agent Parser — Browser & Device Decoder

Parse user agent strings to extract browser, operating system, device, and engine information. Essential for web analytics, device detection, and browser compatibility testing.

Use Tool →
🔀

GitHub Actions Matrix Generator — Build, Validate & Optimize CI/CD Matrices

Define OS and runtime version combinations and generate the strategy.matrix configuration block

Use Tool →
🔐

SSL Certificate Decoder — Expiry & SAN Inspector

Decode X.509 SSL/TLS certificates and RSA private keys in your browser. View subject, issuer, SANs, validity dates, key type, serial number, and SHA-256/SHA-1 fingerprints. Optionally check if a certificate and private key match.

Use Tool →
🌐

Random User Agent Generator — Browser String Tool

Generate random browser user agent strings for testing and development.

Use Tool →

Share Your Feedback

Help us improve this tool by sharing your experience

We will only use this to follow up on your feedback