Skip to content

Commit 1d2870b

Browse files
committed
shellcheck_run_steps: Pin upstream shellcheck container by SHA
We're using an upstream container until we have a guarded one. Let's pin it by SHA while we're doing that. Signed-off-by: dann frazier <dann.frazier@chainguard.dev>
1 parent e499481 commit 1d2870b

1 file changed

Lines changed: 4 additions & 1 deletion

File tree

pre_commit_hooks/shellcheck_run_steps.py

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,6 +13,9 @@
1313

1414
yaml = ruamel.yaml.YAML(typ="safe")
1515

16+
# Reference by SHA for safety
17+
DefaultShellCheckImage = "koalaman/shellcheck@sha256:652a5a714dc2f5f97e36f565d4f7d2322fea376734f3ec1b04ed54ce2a0b124f"
18+
1619

1720
def do_shellcheck(
1821
melange_cfg: Mapping[str, Any],
@@ -79,7 +82,7 @@ def main(argv: Sequence[str] | None = None) -> int:
7982
f"--volume={os.getcwd()}:/mnt",
8083
"--rm",
8184
"-it",
82-
"koalaman/shellcheck:latest",
85+
DefaultShellCheckImage,
8386
],
8487
nargs="*",
8588
help="shellcheck command",

0 commit comments

Comments
 (0)