azu / dockerfile-pin
PublicA CLI tool that adds @sha256:<digest> to FROM lines in Dockerfiles and image fields in docker-compose.yml to prevent supply chain attacks.
A tool that automatically adds cryptographic digests to image references in Dockerfiles and docker-compose files to prevent supply chain attacks by pinning to specific image versions.
How It Works
You learn about a helpful tool that locks your software recipes to exact, trusted versions to stop bad updates from sneaking in.
You easily download and place the tool on your computer with a simple grab-and-go step.
You look at a safe preview of how it adds unique security codes to your build instructions without changing anything yet.
You give the okay to update your files, adding those secure codes to make everything pinned and safe.
You run a quick check to confirm all your build images have the right security locks and point to real versions.
You set it up to automatically check and protect your builds every time you or your team makes changes.
Now your software builds always use the exact trusted versions you chose, keeping everything safe from surprise changes.
Star Growth
Repurpose is a Pro feature
Generate ready-to-use prompts for X threads, LinkedIn posts, blog posts, YouTube scripts, and more -- with full repo context baked in.
Unlock RepurposeSimilar repos coming soon.