Dockerfile Validator
Lint a Dockerfile for syntax problems and common best-practice issues.
Dockerfiles run fine long after they should have been reviewed: an unpinned base image, a missing USER, an apt cache left in a layer. The Dockerfile Validator in HackUtilities parses your file and lists findings with line numbers, ranked as errors, warnings or info. The file is analyzed locally, so build scripts that reference private registries or internal paths stay private.
Parsed with dockerfile-ast
The file is parsed into instructions first, so a malformed file is reported as a parse error instead of being skipped.
Structure checks
Flags a missing FROM, a first instruction that is not FROM, a missing CMD or ENTRYPOINT, and CMD or ENTRYPOINT written in shell form instead of exec form.
Image and user checks
Warns on base images that use the latest tag or no tag, on USER root or 0, and on files with no USER instruction. Suggests adding a HEALTHCHECK when there is none.
Package and copy checks
Catches sudo in RUN, apk add without --no-cache, apt-get update without install, a missing apt cache cleanup, COPY of the whole context, ADD for local files, and relative WORKDIR paths.
Sorted findings and examples
Results are sorted by line, then severity. Load a Node.js, Python or multi-stage example to see a clean file.
Is this the same as Hadolint?
No. HackUtilities uses its own set of checks on top of a Dockerfile parser. It covers common issues but not every Hadolint rule, so it complements rather than replaces a CI linter.
Does it build or run my image?
No. It only reads the Dockerfile text. Nothing is built, pulled or executed, and it does not need Docker installed.
Build GitHub Actions workflow YAML from triggers, jobs and starter templates.
Open →Generate a .gitlab-ci.yml with stages, jobs and scripts from templates.
Open →Check YAML syntax and see the parsed structure as JSON.
Open →No card, no account. Every tool included, bought once.