Skip to content

Update Valleysoft.DockerfileModel to 2.0.0 for heredoc support - #1887

Open
Dan Cristoloveanu (dcristoloveanu) wants to merge 2 commits into
microsoft:mainfrom
dcristoloveanu:dcristoloveanu/valleysoft-dockerfilemodel-2.0.0
Open

Dan Cristoloveanu (dcristoloveanu) wants to merge 2 commits into
microsoft:mainfrom
dcristoloveanu:dcristoloveanu/valleysoft-dockerfilemodel-2.0.0

Conversation

@dcristoloveanu

@dcristoloveanu Dan Cristoloveanu (dcristoloveanu) commented Oct 1, 2026 •

Copy link
Copy Markdown

Fixes #1878.

Problem

Valleysoft.DockerfileModel 1.2.0 predates BuildKit here-document support. Any Dockerfile that uses RUN <<EOF / COPY <<EOF fails to parse: the parser reads the heredoc body as instructions and throws a Sprache.ParseException. The detector then skips the whole file, so none of that file's image references are reported. After #1883 this is logged as a warning rather than an error, but the file is still skipped.

Heredoc support landed in DockerfileModel 2.0.0 (mthalman/DockerfileModel#253 / #256).

Change

  • Directory.Packages.props: Valleysoft.DockerfileModel 1.2.0 → 2.0.0. No detector code changes were needed. 2.0.0 still depends on Sprache (2.3.1), so the catch (ParseException) added in Add exception handling for non-Dockerfile formats #1883 still applies.
  • Four regression tests in DockerfileComponentDetectorTests:
    • RUN <<EOF: one image detected, and nothing logged at Warning or above.
    • A # syntax= directive plus RUN <<END_OF_SCRIPT bash (interpreter after the delimiter).
    • A multi-stage file with a COPY <<EOF heredoc and COPY --from=<stage>, which still yields exactly two images. This covers the CopyInstruction.FromStageNameToken retyping in 2.0.0; the detector only reads FromStageName.
    • A heredoc body that contains a FROM inner/image:1.0 line, which must not be reported.
  • docs/detectors/dockerfile.md: one sentence noting heredoc support.
  • DockerfileComponentDetector.Version: 1 → 2. Heredoc Dockerfiles that were previously skipped now produce components, which the detector version policy counts as an output change. The verification corpus has no heredoc Dockerfiles, so its count check can't see this.

Validation

  • Microsoft.ComponentDetection.Detectors.Tests: 983/983 pass (979 existing + 4 new). The whole solution builds with no errors.
  • With only the package version reverted to 1.2.0, exactly the 4 new tests fail and every existing Dockerfile test still passes.
  • I scanned two real-world heredoc Dockerfiles from microsoft/vcpkg (scripts/azure-pipelines/android/Dockerfile, scripts/azure-pipelines/linux-arm64/Dockerfile, plus linux/Dockerfile from the same folder) with --DetectorArgs DockerReference=EnableIfDefaultOff:
    • 1.2.0: 2 parse failures (Ignoring file that doesn't appear to be a Dockerfile) and 1 image reported.
    • 2.0.0: 0 parse failures, and both base images reported, with all three files attributed.
  • test/Microsoft.ComponentDetection.VerificationTests/resources/dockerFiles gives the same 6 components with 1.2.0 and 2.0.0, so snapshot verification should be unaffected.

I did not run the Integration test category locally. Those tests spawn external build tools and do not touch this parser.

Valleysoft.DockerfileModel 1.2.0 predates BuildKit heredoc support, so any Dockerfile using RUN/COPY <<EOF fails to parse and the detector skips it. 2.0.0 adds heredoc parsing; the detector code compiles and behaves unchanged against it.

Adds regression tests for RUN heredocs, a syntax directive with an interpreter heredoc, a multi-stage file with COPY heredoc and COPY --from, and a heredoc body containing a FROM line that must not be reported.

Fixes microsoft#1878

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The output-changing parser upgrade requires incrementing the Dockerfile detector version.

Review effort: Balanced
Findings: 1 High severity

Open (1)
What changed in this PR

Updates Dockerfile parsing to support BuildKit heredocs.

Changes:

  • Upgrades Valleysoft.DockerfileModel to 2.0.0.
  • Adds four heredoc regression tests.
  • Documents heredoc behavior.
File Description
Directory.Packages.props Upgrades the Dockerfile parser dependency.
DockerfileComponentDetectorTests.cs Tests RUN/COPY heredocs and opaque bodies.
docs/​detectors/​dockerfile.md Documents heredoc support.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread Directory.Packages.props
Heredoc Dockerfiles that were previously skipped now produce components, which the detector version policy treats as an output change.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 2, 2026 02:01

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The dependency upgrade, detector version bump, documentation, and focused regression coverage are consistent and complete.

Review effort: Balanced
Findings: None

Resolved since last review (1)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Dockerfile detector logs an error on BuildKit heredoc Dockerfiles (Valleysoft.DockerfileModel pinned to 1.2.0, predates heredoc support)

2 participants