This product is not supported for your selected Datadog site. ().
이 페이지는 아직 영어로 제공되지 않습니다. 번역 작업 중입니다. 현재 번역 프로젝트에 대한 질문이나 피드백이 있으신 경우 언제든지 연락주시기 바랍니다.
Metadata
ID:docker-best-practices/copy-reference-from
Language: Docker
Severity: Warning
Category: Best Practices
Description
This rule enforces that the COPY instruction must reference a valid build stage alias defined by a preceding FROM statement using the as keyword. Specifically, the --from flag in COPY should only point to an existing build stage alias, ensuring that the source files are correctly retrieved from the intended build context.
To avoid violations, always declare build stages with FROM <image> as <alias> before using COPY --from=<alias>. Verify that the alias used in COPY matches exactly with the alias declared in the earlier FROM statement. For example, using FROM debian:jesse as build followed by COPY --from=build ... ensures compliance and reliable builds.
Non-Compliant Code Examples
FROMdebian:jesseasbuildCOPY --from=build some stuff ./
Compliant Code Examples
FROMdebian:jesseasbuildRUN stuffFROMdebian:jesseCOPY --from=build some stuff ./
원활한 통합. Datadog Code Security를 경험해 보세요
Datadog Code Security
이 규칙을 사용해 Datadog Code Security로 코드를 분석하세요
규칙 사용 방법
1
2
rulesets:- docker-best-practices # Rules to enforce Docker best practices.
리포지토리 루트에 위의 내용을 포함하는 static-analysis.datadog.yml을 만듭니다
무료 IDE 플러그인을 사용하거나 CI 파이프라인에 Code Security 검사를 추가합니다