What this Dockerfile checker catches
The checker focuses on the Dockerfile issues teams commonly catch during review: mutable image tags, root runtime users, missing health checks, package manager cache bloat, broad COPY instructions, and accidental secrets in image layers.
It is intentionally fast and local. Pair it with hadolint, image vulnerability scanning, and CI policy checks when you need strict enforcement across production images.