From ring-dev-team
Hardens Dockerfiles to Docker Hub Health Score grade A: non-root user, minimal base images, zero fixable CVEs, no AGPL-3.0 deps, SBOM+provenance. Use when creating or auditing Dockerfiles for publication.
How this skill is triggered — by the user, by Claude, or both
Slash command
/ring-dev-team:hardening-dockerfilesThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
- Creating a new Dockerfile
Complementary: ring:implementing-tasks, ring:creating-helm-charts
General Dockerfile patterns: dev-team/docs/standards/devops.md#containers.
This skill focuses on Docker Hub Health Score compliance.
| # | Policy | Weight | Compliance |
|---|---|---|---|
| 1 | Default non-root user | Required | USER directive with non-root user |
| 2 | No fixable critical/high CVEs | Required | Distroless or Alpine, multi-stage |
| 3 | No high-profile vulnerabilities (CISA KEV) | Required | Up-to-date base images |
| 4 | No AGPL v3 licenses | Required | Audit dependencies |
| 5 | Supply chain attestations (SBOM + provenance) | Required | Pipeline config |
| 6 | No outdated base images | Optional | Only for Docker Hub hosted images |
| 7 | No unapproved base images | Optional | Only for Docker Hub hosted images |
Policies 6-7 are not evaluated when using non-Docker Hub base images (gcr.io/distroless, etc.).
# Alpine
RUN addgroup -S appgroup && adduser -S appuser -G appgroup
USER appuser
# Debian/Ubuntu
RUN groupadd -r appgroup && useradd -r -g appgroup appuser
USER appuser
# Distroless (pre-existing user)
USER nonroot:nonroot
USER root does NOT satisfy this policy.
# Go (statically compiled) — ~0 CVEs
FROM gcr.io/distroless/static-debian12
# Go (CGO) or general
FROM gcr.io/distroless/base-debian12
# Node.js
FROM node:22-alpine
# Multi-stage mandatory
FROM golang:1.23-alpine AS builder
# ... build ...
FROM gcr.io/distroless/static-debian12
COPY --from=builder /app/binary /app/binary
trivy fs --scanners license --severity CRITICAL .
Replace any AGPL-3.0 dependency.
# build-push-action config
sbom: generator=docker/scout-sbom-indexer:latest
provenance: mode=max
Not a Dockerfile concern — verify CI/CD includes both parameters.
FROM golang:1.23-alpine AS builder
WORKDIR /app
COPY go.mod go.sum ./
RUN go mod download
COPY . .
RUN CGO_ENABLED=0 GOOS=linux go build -a -installsuffix cgo -o app ./cmd/...
FROM gcr.io/distroless/static-debian12
COPY --from=builder /app/app /app/app
EXPOSE 3000
USER nonroot:nonroot
ENTRYPOINT ["/app/app"]
FROM node:22-alpine AS builder
WORKDIR /app
COPY package*.json ./
RUN npm ci --only=production
COPY . .
RUN npm run build
FROM node:22-alpine
WORKDIR /app
RUN addgroup -S appgroup && adduser -S appuser -G appgroup
COPY --from=builder /app/dist ./dist
COPY --from=builder /app/node_modules ./node_modules
EXPOSE 3000
USER appuser
CMD ["node", "dist/index.js"]
CRITICAL (blocks grade A):
[ ] USER directive with non-root user
[ ] Multi-stage build (no build tools in final)
[ ] Minimal base image (distroless/alpine)
[ ] No secrets in image layers
HIGH (CVE risk):
[ ] Base image is up to date
[ ] Package versions pinned
[ ] No dev dependencies in final stage
MEDIUM:
[ ] .dockerignore excludes .git, node_modules, test files
[ ] COPY used (not ADD)
[ ] Cache layers ordered: deps before source
SUPPLY CHAIN (pipeline):
[ ] sbom: parameter in build-push-action
[ ] provenance: mode=max
## Health Score Compliance
| Policy | Status | Details |
|--------|--------|---------|
| Default non-root user | PASS/FAIL | USER {user} at line {N} |
| No fixable CVEs | PASS/RISK | Base: {image} |
| No KEV vulnerabilities | PASS/RISK | Base image {status} |
| No AGPL v3 licenses | PASS/RISK | {N} deps audited |
| Supply chain attestations | PASS/MISSING | sbom: {yes/no}, provenance: {yes/no} |
**Grade A: {ACHIEVED / NOT ACHIEVED}**
## Actions Taken
| File | Action | Changes |
npx claudepluginhub p/lerianstudio-ring-dev-team-dev-teamHardens container images (Dockerfile/Containerfile) against supply-chain attacks: pins base images, enforces non-root user, verifies artifact fetches, lints with hadolint/shellcheck, and scans with grype/syft for SBOM.
Hardens Docker/container images and Kubernetes deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and pod security controls.
Dockerfile standards: Alpine/slim base, non-root user, multi-stage builds. Use when creating a Dockerfile, hardening security, or auditing image size.