build rejects valid tag@digest image references during registry inspection
@v-Kaniska244 已经在做这个了。
开始于 2026年9月25日。
评估
- 难度
- 3/5
- 预计耗时
- 1-2 天
- 新手友好度
- 78/100
- Issue 类型
- 缺陷
- 描述清晰度
- 描述清楚
- 活跃度
- 活跃
- 技术栈
- docker, typescript
调研方向
Start in src/spec-configuration/containerCollectionsOCI.ts, especially getRef and inspectImageInRegistry, then run the provided devcontainer build reproduction for the direct image and Dockerfile FROM cases. Done means valid name:tag@sha256:digest references pass registry inspection while digest-only references continue to work.
由索引模型根据 Issue 内容生成。
描述
Summary
@devcontainers/cli 0.89.0 rejects valid OCI/Docker name:tag@sha256:digest references during registry inspection. This reproduces for both a direct devcontainer.json.image and a Dockerfile FROM. The equivalent digest-only reference works.
This is related to #825, but that report is limited to Feature identifiers and explicitly says ordinary image references accept tag plus digest.
Environment
@devcontainers/cli: 0.89.0- Node.js: 26.9.0
- OS: Linux 7.2.6-1-cachyos x64
- CLI 0.89.0 and current
main:5dc7533314b5ba7ec3875c30143dfe1aec644870
Minimal reproduction
.devcontainer/devcontainer.json:
{
"image": "mcr.microsoft.com/devcontainers/go:2.3.1-1.27-bookworm@sha256:adc326255c019241228f9da4a1cb5d6a89abaaa0eb8d926a355b00af7daafd00"
}
Run:
npx -y @devcontainers/[email protected] build --workspace-folder . --log-level info
The same failure occurs when a Dockerfile contains a FROM reference in name:tag@digest form.
Actual result
Path 'devcontainers/go:2.3.1-1.27-bookworm' for input 'mcr.microsoft.com/devcontainers/go:2.3.1-1.27-bookworm@sha256:adc326255c019241228f9da4a1cb5d6a89abaaa0eb8d926a355b00af7daafd00' failed validation. Expected path to match regex ...\nError fetching image details: Could not parse image name ...\n```\n\nChanging only the reference to the equivalent digest-only form succeeds:\n\n```text\nmcr.microsoft.com/devcontainers/go@sha256:adc326255c019241228f9da4a1cb5d6a89abaaa0eb8d926a355b00af7daafd00\n```\n\nDocker itself accepts the original tag-plus-digest reference.\n\nIn my two original runs, the CLI also remained alive after printing the parser diagnostic until interrupted with SIGINT. I have not isolated whether that is the fallback `docker pull` path or process cleanup, so the deterministic defect in this report is the parser rejection.\n\n## Expected result\n\n`build` should accept the distribution reference grammar `name [":" tag] ["@" digest]` for direct images and Dockerfile base images.\n\n## Source-level observation\n\n`getRef` removes the digest suffix but leaves `:tag` in `resource` before validating the repository path. The colon then fails the path regex. `inspectImageInRegistry` reports `Could not parse image name`, and both direct-image and Dockerfile inspection reach that path.\n\nReference grammar: https://github.com/distribution/reference/blob/0965666a6ade2e06035fe352e38344be1e68951a/reference.go#L5-L20\n\nRelevant 0.89.0 code: https://github.com/devcontainers/cli/blob/5dc7533314b5ba7ec3875c30143dfe1aec644870/src/spec-configuration/containerCollectionsOCI.ts#L152-L230
- 主要语言
- TypeScript
- 星标
- 3k
- 派生
- 461
- 平均合并
- 18 分钟
- 30 天内合并 PR
- 5
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
devcontainers/cli 的其他 Issue
-
难度 1/5 1 小时以内 新手友好度 92/100
devcontainers/cli#1203 ·
-
难度 1/5 1-3 小时 新手友好度 68/100
devcontainers/cli#1178 · 1 条评论 ·
-
难度 5/5 一周以上 新手友好度 25/100
devcontainers/cli#1308 ·
-
难度 4/5 3-5 天 新手友好度 55/100
devcontainers/cli#1305 ·
-
难度 3/5 1-2 天 新手友好度 68/100
devcontainers/cli#1301 ·
查看 devcontainers/cli 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 84/100
receptron/mulmoterminal#2264 ·
-
documentation
难度 2/5 1-3 小时 新手友好度 78/100
components-web-app/docs#96 ·
-
enhancement
难度 2/5 1-3 小时 新手友好度 78/100
-
难度 2/5 1-3 小时 新手友好度 68/100
simonsobs/tileviewer#114 ·
-
难度 2/5 1-3 小时 新手友好度 75/100