Detect registry hosts in image names like Docker does - #1310
Open
Fabian Schurig (FabianSchurig) wants to merge 2 commits into
Open
Fabian Schurig (FabianSchurig) wants to merge 2 commits into
Fabian Schurig (FabianSchurig) wants to merge 2 commits into
Conversation
An image name with one slash was always treated as a Docker Hub name, so a private registry was looked up on docker.io first (devcontainers#811) and a registry host with a port failed to parse. The first segment is a registry host when it contains a dot or a colon, is localhost, or has uppercase letters, matching Docker's splitDockerDomain. Names without a host, including nested paths, are qualified as docker.io. A repository with no extra path segment now parses. The Podman base-image path uses the same check.
Fabian Schurig (FabianSchurig)
requested a review
from a team
as a code owner
September 23, 2026 16:31
Copilot started reviewing on behalf of
Fabian Schurig (FabianSchurig)
September 23, 2026 16:32
View session
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
OCI parsing can accept invalid identifiers and generate malformed endpoints.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
Open (1)
What changed in this PR
Updates Docker and Podman image qualification to recognize private registry hosts, ports, localhost, and nested paths.
Changes:
- Added Docker-compatible registry detection.
- Updated Podman base-image handling.
- Adjusted OCI path parsing.
- Added registry and qualification tests.
| File | Summary |
|---|---|
src/test/dockerUtils.test.ts |
Adds registry detection and qualification tests. |
src/spec-node/utils.ts |
Implements registry-aware image qualification. |
src/spec-node/containerFeatures.ts |
Reuses registry detection for Podman. |
src/spec-configuration/containerCollectionsOCI.ts |
Contains unresolved moderate issues involving invalid feature identifiers and registry-only inputs. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
A name with no slash, such as ghcr.io, was accepted once the empty namespace stopped producing a leading slash. Keep that case invalid, and still accept a host plus repository such as registry.example.com:5000/image.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Fixes #811.
qualifyImageNametreated every image name with a single/as a Docker Hub name. A private registry such asregistry.example.com/imagewas therefore looked up ondocker.iofirst, and a host with a port (registry.example.com:5000/image) failed to parse.inspectDockerImagethen fell back to a fulldocker pull.The first path segment is now a registry host when it contains
.or:, islocalhost, or contains uppercase letters. That is Docker'ssplitDockerDomainrule. Names without a host are qualified asdocker.io, including nested paths:foo/random/imagebecomesdocker.io/foo/random/image. Previously that name was left unchanged, which Docker itself does not do.docker.io/<name>still becomesdocker.io/library/<name>.A repository with no extra path segment (
registry.example.com:5000/image) now parses.getRefused to build the path as/image, which its own validation rejected.The Podman base-image path uses the same
hasRegistryHostcheck. It previously missedmyregistry:5000/imageandlocalhost:5000/imageand prefixed them withlocalhost/.