Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

build rejects valid tag@digest image references during registry inspection

Open
#1,307 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
3/5
Estimated time
1-2 days
Newbie friendliness
78/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
docker, typescript
Domain
cli, devops

Research direction

Start in src/spec-configuration/containerCollectionsOCI.ts, especially getRef and inspectImageInRegistry, then run the provided devcontainer build reproduction for the direct image and Dockerfile FROM cases. Done means valid name:tag@sha256:digest references pass registry inspection while digest-only references continue to work.

Written by the indexing model from the issue text.

Description

Summary

@devcontainers/cli 0.89.0 rejects valid OCI/Docker name:tag@sha256:digest references during registry inspection. This reproduces for both a direct devcontainer.json.image and a Dockerfile FROM. The equivalent digest-only reference works.

This is related to #825, but that report is limited to Feature identifiers and explicitly says ordinary image references accept tag plus digest.

Environment

  • @devcontainers/cli: 0.89.0
  • Node.js: 26.9.0
  • OS: Linux 7.2.6-1-cachyos x64
  • CLI 0.89.0 and current main: 5dc7533314b5ba7ec3875c30143dfe1aec644870

Minimal reproduction

.devcontainer/devcontainer.json:

{
  "image": "mcr.microsoft.com/devcontainers/go:2.3.1-1.27-bookworm@sha256:adc326255c019241228f9da4a1cb5d6a89abaaa0eb8d926a355b00af7daafd00"
}

Run:

npx -y @devcontainers/cli@0.89.0 build --workspace-folder . --log-level info

The same failure occurs when a Dockerfile contains a FROM reference in name:tag@digest form.

Actual result

Path 'devcontainers/go:2.3.1-1.27-bookworm' for input 'mcr.microsoft.com/devcontainers/go:2.3.1-1.27-bookworm@sha256:adc326255c019241228f9da4a1cb5d6a89abaaa0eb8d926a355b00af7daafd00' failed validation. Expected path to match regex ...\nError fetching image details: Could not parse image name ...\n```\n\nChanging only the reference to the equivalent digest-only form succeeds:\n\n```text\nmcr.microsoft.com/devcontainers/go@sha256:adc326255c019241228f9da4a1cb5d6a89abaaa0eb8d926a355b00af7daafd00\n```\n\nDocker itself accepts the original tag-plus-digest reference.\n\nIn my two original runs, the CLI also remained alive after printing the parser diagnostic until interrupted with SIGINT. I have not isolated whether that is the fallback `docker pull` path or process cleanup, so the deterministic defect in this report is the parser rejection.\n\n## Expected result\n\n`build` should accept the distribution reference grammar `name [":" tag] ["@" digest]` for direct images and Dockerfile base images.\n\n## Source-level observation\n\n`getRef` removes the digest suffix but leaves `:tag` in `resource` before validating the repository path. The colon then fails the path regex. `inspectImageInRegistry` reports `Could not parse image name`, and both direct-image and Dockerfile inspection reach that path.\n\nReference grammar: https://github.com/distribution/reference/blob/0965666a6ade2e06035fe352e38344be1e68951a/reference.go#L5-L20\n\nRelevant 0.89.0 code: https://github.com/devcontainers/cli/blob/5dc7533314b5ba7ec3875c30143dfe1aec644870/src/spec-configuration/containerCollectionsOCI.ts#L152-L230
Dominant language
TypeScript
Stars
3k
Forks
461
Avg merge
18m
Merged PRs (30d)
5

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from devcontainers/cli

All issues in devcontainers/cli

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.