Matchboxmatchbox
← Back to match

dockerfile-pin

CLI that adds SHA-256 digest pins to Docker and CI image references to prevent supply-chain attacks.

Desktopfree

dockerfile-pin is a command-line tool that automatically adds SHA-256 digest pins to Docker image references in Dockerfiles, docker-compose files, GitHub Actions, and GitLab CI configuration, helping prevent supply-chain attacks from mutable tags. It also includes a check mode for CI that validates pins exist and are correct. It is aimed at DevOps and platform engineers who want to harden build pipelines against image tampering.

Categories
Security toolsDevOps

Full match profile

Behind the summary, Matchbox keeps a richer profile of dockerfile-pin - the signals our matcher actually reads to decide when to surface it. It stays private; claim the listing to see and control it.

  • Problem & pain-point mapping
  • Who we surface it to (audience fit)
  • What it's a strong alternative to
  • Trust & credibility signals

Try Matchbox with your own problem

Describe what is not working - we’ll show you whether dockerfile-pin (or something else) actually fits.