Summary
@devcontainers/cli 0.89.0 rejects valid OCI/Docker name:tag@sha256:digest references during registry inspection. This reproduces for both a direct devcontainer.json.image and a Dockerfile FROM. The equivalent digest-only reference works.
This is related to #825, but that report is limited to Feature identifiers and explicitly says ordinary image references accept tag plus digest.
Environment
@devcontainers/cli: 0.89.0
- Node.js: 26.9.0
- OS: Linux 7.2.6-1-cachyos x64
- CLI 0.89.0 and current
main: 5dc7533314b5ba7ec3875c30143dfe1aec644870
Minimal reproduction
.devcontainer/devcontainer.json:
{
"image": "mcr.microsoft.com/devcontainers/go:2.3.1-1.27-bookworm@sha256:adc326255c019241228f9da4a1cb5d6a89abaaa0eb8d926a355b00af7daafd00"
}
Run:
npx -y @devcontainers/cli@0.89.0 build --workspace-folder . --log-level info
The same failure occurs when a Dockerfile contains a FROM reference in name:tag@digest form.
Actual result
Path 'devcontainers/go:2.3.1-1.27-bookworm' for input 'mcr.microsoft.com/devcontainers/go:2.3.1-1.27-bookworm@sha256:adc326255c019241228f9da4a1cb5d6a89abaaa0eb8d926a355b00af7daafd00' failed validation. Expected path to match regex ...\nError fetching image details: Could not parse image name ...\n```\n\nChanging only the reference to the equivalent digest-only form succeeds:\n\n```text\nmcr.microsoft.com/devcontainers/go@sha256:adc326255c019241228f9da4a1cb5d6a89abaaa0eb8d926a355b00af7daafd00\n```\n\nDocker itself accepts the original tag-plus-digest reference.\n\nIn my two original runs, the CLI also remained alive after printing the parser diagnostic until interrupted with SIGINT. I have not isolated whether that is the fallback `docker pull` path or process cleanup, so the deterministic defect in this report is the parser rejection.\n\n## Expected result\n\n`build` should accept the distribution reference grammar `name [":" tag] ["@" digest]` for direct images and Dockerfile base images.\n\n## Source-level observation\n\n`getRef` removes the digest suffix but leaves `:tag` in `resource` before validating the repository path. The colon then fails the path regex. `inspectImageInRegistry` reports `Could not parse image name`, and both direct-image and Dockerfile inspection reach that path.\n\nReference grammar: https://github.com/distribution/reference/blob/0965666a6ade2e06035fe352e38344be1e68951a/reference.go#L5-L20\n\nRelevant 0.89.0 code: https://github.com/devcontainers/cli/blob/5dc7533314b5ba7ec3875c30143dfe1aec644870/src/spec-configuration/containerCollectionsOCI.ts#L152-L230
Summary
@devcontainers/cli0.89.0 rejects valid OCI/Dockername:tag@sha256:digestreferences during registry inspection. This reproduces for both a directdevcontainer.json.imageand a DockerfileFROM. The equivalent digest-only reference works.This is related to #825, but that report is limited to Feature identifiers and explicitly says ordinary image references accept tag plus digest.
Environment
@devcontainers/cli: 0.89.0main:5dc7533314b5ba7ec3875c30143dfe1aec644870Minimal reproduction
.devcontainer/devcontainer.json:{ "image": "mcr.microsoft.com/devcontainers/go:2.3.1-1.27-bookworm@sha256:adc326255c019241228f9da4a1cb5d6a89abaaa0eb8d926a355b00af7daafd00" }Run:
npx -y @devcontainers/cli@0.89.0 build --workspace-folder . --log-level infoThe same failure occurs when a Dockerfile contains a
FROMreference inname:tag@digestform.Actual result