no-image-latest

disallow container images without an explicit tag or with the “latest” tag

Category
reproducibility
Applies to
devcontainer
Platforms
all

Why

A reference with no tag resolves to “latest”, and “latest” is just the tag a publisher moves as they release. Either way the configuration says “whatever is current”, so the same devcontainer.json builds a different environment next month, and a build that broke cannot be reproduced from the file alone. Name the version the project was tested against.

Bad

{
  "image": "mcr.microsoft.com/devcontainers/base:latest"
}

Good

{
  "image": "mcr.microsoft.com/devcontainers/base:ubuntu-24.04"
}

References