Dockerfile Validator

Lint a Dockerfile for syntax problems and common best-practice issues.

Works offline Native desktop macOS & Windows
Dockerfile Validator
What it does

Dockerfiles run fine long after they should have been reviewed: an unpinned base image, a missing USER, an apt cache left in a layer. The Dockerfile Validator in HackUtilities parses your file and lists findings with line numbers, ranked as errors, warnings or info. The file is analyzed locally, so build scripts that reference private registries or internal paths stay private.

Parsed with dockerfile-ast

The file is parsed into instructions first, so a malformed file is reported as a parse error instead of being skipped.

Structure checks

Flags a missing FROM, a first instruction that is not FROM, a missing CMD or ENTRYPOINT, and CMD or ENTRYPOINT written in shell form instead of exec form.

Image and user checks

Warns on base images that use the latest tag or no tag, on USER root or 0, and on files with no USER instruction. Suggests adding a HEALTHCHECK when there is none.

Package and copy checks

Catches sudo in RUN, apk add without --no-cache, apt-get update without install, a missing apt cache cleanup, COPY of the whole context, ADD for local files, and relative WORKDIR paths.

Sorted findings and examples

Results are sorted by line, then severity. Load a Node.js, Python or multi-stage example to see a clean file.

FAQ

Is this the same as Hadolint?

No. HackUtilities uses its own set of checks on top of a Dockerfile parser. It covers common issues but not every Hadolint rule, so it complements rather than replaces a CI linter.

Does it build or run my image?

No. It only reads the Dockerfile text. Nothing is built, pulled or executed, and it does not need Docker installed.

Pairs well with
All 46 tools →
Try Dockerfile Validator free for 14 days

No card, no account. Every tool included, bought once.

Download