Update Valleysoft.DockerfileModel to 2.0.0 for heredoc support - #1887
Open
Dan Cristoloveanu (dcristoloveanu) wants to merge 2 commits into
Open
Dan Cristoloveanu (dcristoloveanu) wants to merge 2 commits into
Dan Cristoloveanu (dcristoloveanu) wants to merge 2 commits into
Conversation
Valleysoft.DockerfileModel 1.2.0 predates BuildKit heredoc support, so any Dockerfile using RUN/COPY <<EOF fails to parse and the detector skips it. 2.0.0 adds heredoc parsing; the detector code compiles and behaves unchanged against it. Adds regression tests for RUN heredocs, a syntax directive with an interpreter heredoc, a multi-stage file with COPY heredoc and COPY --from, and a heredoc body containing a FROM line that must not be reported. Fixes microsoft#1878 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Dan Cristoloveanu (dcristoloveanu)
requested a review
from a team
as a code owner
October 1, 2026 02:52
Dan Cristoloveanu (dcristoloveanu)
requested a review
from Joe Schmitt (schmittjoseph)
October 1, 2026 02:52
Copilot started reviewing on behalf of
Dan Cristoloveanu (dcristoloveanu)
October 1, 2026 02:53
View session
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The output-changing parser upgrade requires incrementing the Dockerfile detector version.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Updates Dockerfile parsing to support BuildKit heredocs.
Changes:
- Upgrades
Valleysoft.DockerfileModelto 2.0.0. - Adds four heredoc regression tests.
- Documents heredoc behavior.
| File | Description |
|---|---|
Directory.Packages.props |
Upgrades the Dockerfile parser dependency. |
DockerfileComponentDetectorTests.cs |
Tests RUN/COPY heredocs and opaque bodies. |
docs/detectors/dockerfile.md |
Documents heredoc support. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Heredoc Dockerfiles that were previously skipped now produce components, which the detector version policy treats as an output change. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot started reviewing on behalf of
Dan Cristoloveanu (dcristoloveanu)
October 2, 2026 02:02
View session
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Fixes #1878.
Problem
Valleysoft.DockerfileModel1.2.0 predates BuildKit here-document support. Any Dockerfile that usesRUN <<EOF/COPY <<EOFfails to parse: the parser reads the heredoc body as instructions and throws aSprache.ParseException. The detector then skips the whole file, so none of that file's image references are reported. After #1883 this is logged as a warning rather than an error, but the file is still skipped.Heredoc support landed in DockerfileModel 2.0.0 (mthalman/DockerfileModel#253 / #256).
Change
Directory.Packages.props:Valleysoft.DockerfileModel1.2.0 → 2.0.0. No detector code changes were needed. 2.0.0 still depends on Sprache (2.3.1), so thecatch (ParseException)added in Add exception handling for non-Dockerfile formats #1883 still applies.DockerfileComponentDetectorTests:RUN <<EOF: one image detected, and nothing logged at Warning or above.# syntax=directive plusRUN <<END_OF_SCRIPT bash(interpreter after the delimiter).COPY <<EOFheredoc andCOPY --from=<stage>, which still yields exactly two images. This covers theCopyInstruction.FromStageNameTokenretyping in 2.0.0; the detector only readsFromStageName.FROM inner/image:1.0line, which must not be reported.docs/detectors/dockerfile.md: one sentence noting heredoc support.DockerfileComponentDetector.Version: 1 → 2. Heredoc Dockerfiles that were previously skipped now produce components, which the detector version policy counts as an output change. The verification corpus has no heredoc Dockerfiles, so its count check can't see this.Validation
Microsoft.ComponentDetection.Detectors.Tests: 983/983 pass (979 existing + 4 new). The whole solution builds with no errors.scripts/azure-pipelines/android/Dockerfile,scripts/azure-pipelines/linux-arm64/Dockerfile, pluslinux/Dockerfilefrom the same folder) with--DetectorArgs DockerReference=EnableIfDefaultOff:Ignoring file that doesn't appear to be a Dockerfile) and 1 image reported.test/Microsoft.ComponentDetection.VerificationTests/resources/dockerFilesgives the same 6 components with 1.2.0 and 2.0.0, so snapshot verification should be unaffected.I did not run the Integration test category locally. Those tests spawn external build tools and do not touch this parser.