About Dockerfile Roast
droast, short for Dockerfile Roast, is a linter for Dockerfiles that has strong opinions. It catches bad practices and reports them in a deliberately blunt tone, like feedback from a senior engineer who has seen too many production incidents. It is written in Rust.
Its parser is span-aware and understands heredocs, parser and escape directives, shell and JSON forms, BuildKit flags such as RUN --mount, Windows paths and PowerShell, and it reports malformed syntax under its own rule code. Findings can be tuned with presets, for example a production preset, and a comparison page explains how it differs from other linters.
You can use it through a VS Code extension with inline diagnostics, a Neovim plugin, a GitHub Action, a Docker image, a binary, Homebrew, Cargo, Wasmer or a browser-based linter built on WebAssembly. A Rust library is available for embedding it in other tools. The project is MIT licensed.
Key features
- Opinionated Dockerfile linting with blunt messages
- Span-aware parser for heredocs and BuildKit flags
- VS Code extension with inline diagnostics
- Neovim plugin with lint-on-save
- Web linter running in the browser via WASM
- Docker image, Homebrew, Cargo and Wasmer installs
- GitHub Action for CI
Good fit for
- →Linting Dockerfiles in CI pipelines
- →Catching container build mistakes while editing
- Tags
- dockerfile
- linter
- docker
- rust
- static-analysis
- ci
- security
- devops
- wasm
Dockerfile Roast: questions and answers
- What is Dockerfile Roast used for?
- Dockerfile Roast is an opinionated Dockerfile linter written in Rust that flags bad practices with blunt messages, with editor plugins, a web version and CI support. It is a good fit for linting Dockerfiles in CI pipelines and catching container build mistakes while editing.
- Is Dockerfile Roast open source?
- Yes. Dockerfile Roast is open source under the MIT licence. Its source code is on GitHub at immanuwell/dockerfile-roast and is written mainly in Rust.
- Is Dockerfile Roast free?
- Yes. Dockerfile Roast is open source, so the software itself is free to use.
- What are some alternatives to Dockerfile Roast?
- Similar open-source tools in the CI/CD & DevOps category include actionlint, kube-score and Act. SaaS products in the same category include Blacksmith, Depot and Sonatype Nexus Repository.
- Is Dockerfile Roast actively maintained?
- Yes. The most recent commit to Dockerfile Roast was on 1 September 2026, and the latest release is 1.7.0, published on 1 September 2026. The project has 1.1k stars on GitHub.
Open-source alternatives to Dockerfile Roast
See allactionlint
CI/CD & DevOps
:octocat: Static checker for GitHub Actions workflow files
MIT★ 4.3kkube-score
CI/CD & DevOps
Kubernetes object analysis with recommendations for improved reliability and security. kub
MIT★ 3.1k
Act
CI/CD & DevOps
Run your GitHub Actions locally 🚀
MIT★ 72k
reviewdog
CI/CD & DevOps
🐶 Automated code review tool integrated with any code analysis tools regardless of progra
MITvs Codacy★ 9.6k
Earthly
CI/CD & DevOps
Super simple build framework with fast, repeatable builds and an instantly familiar syntax
MPL-2.0vs Depot★ 12k
release-plz
CI/CD & DevOps
Publish Rust crates from CI with a Release PR.
Apache-2.0★ 1.5k
SaaS alternatives to Dockerfile Roast
See all
Blacksmith
CI/CD & DevOps
Faster GitHub Actions runners billed per minute, with build caching
SaaS
Depot
CI/CD & DevOps
Remote container build and CI runner service that speeds up Docker builds
SaaS
Sonatype Nexus Repository
CI/CD & DevOps
Artifact repository manager for storing and distributing software packages
SaaS
Travis CI
CI/CD & DevOps
Hosted continuous integration service that builds and tests code from Git repos
SaaS
Appcircle
CI/CD & DevOps
Mobile CI/CD platform for building, testing and publishing apps, cloud or self-hosted
SaaS
AWS CodePipeline
CI/CD & DevOps
Managed AWS service that automates build, test and deploy release pipelines
SaaS

