feat: add docker-hub-webhooks skill - #204
Merged
Merged
Conversation
…their sources Cite docker/docs#23955 for the callback_url 404 report, and ground the raw-PAT-as-bearer warning in the Hub API reference's auth guidance plus the observed 401 for an unrecognised bearer on a public repo. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds
docker-hub-webhooks, a skill for receiving Docker Hub repository webhooks, with Express, Next.js and FastAPI examples (19 tests each).The scheme: there isn't one
Docker Hub webhooks are unsigned. The webhooks docs describe no signature header, shared secret, HMAC, timestamp or auth option, and the create form takes only a name and a destination URL (255 characters max). The skill therefore ships no verifier. What it does instead:
/webhooks/docker-hub/<token>), compared in constant time. It fails closed with 500 whenDOCKER_HUB_WEBHOOK_TOKENis unset. The docs are explicit that this is a bearer secret in a URL and not a Docker signature.DOCKER_HUB_ALLOWED_REPOS, 403 for anything else), plus shape validation onpush_data.tagandrepository.repo_name(400 if missing).GetRepositoryTagbefore acting, with a recommendation to pull by digest.Other mechanics it covers:
event,typeoractionfield. Handlers route onrepo_name+tag.dhi_metadata: pushes to mirrored Docker Hardened Image repos include a map keyed by per-architecture manifest digest (DHI docs, added in dhi: new webhook data docker/docs#26116, Sep 2026).callback_urlis legacy. The docs say it "is no longer supported". The callback-validation / webhook-chain section (state: success|failure|error) was removed in hub: remove webhook callback_url docker/docs#20565 (Aug 2024), and Add documentation on how to handle the callback_url, and how to verify a callback request came from docker. docker/docs#23955 reports the URL returning 404. The examples ignore the field, and the tests check that no outbound request is made.Things a reviewer might flag (checked)
X-Docker-Signatureheader and no IP allowlist.POST /v2/auth/tokento get a JWT (valid 10 min). The examples exchange the credential and cache the JWT, and send noAuthorizationheader for public repos. I checked on 2026-09-28:GET .../library/repositories/alpine/tags/latestreturns 200 with no auth and 401 with an unrecognised bearer.pushed_atis in Unix seconds, inferred from the 10-digit example. Retry policy, timeout and request headers are not documented, and the skill says so rather than giving numbers. The documented example payload dates from 2014, so the skill only relies on a small set of fields.Cross-checked against hookdeck/core (merged in hookdeck/core#5669)
Core's
DOCKER_HUBsource type is "No verification (schema only)", uses managed POST, and hasexternal_docs_url=https://docs.docker.com/docker-hub/repos/manage/webhooks/. That matches the primary docs and this skill, with no disagreements. The skill says Hookdeck doesn't verify Docker Hub (there's nothing to verify). It also says Hookdeck's own outbound signature only secures the Hookdeck → destination hop. Docker Hub isn't in the hookdeck.com/docs/sources list yet (checked 2026-09-28).Testing
validate-provider.sh docker-hub-webhooks: passes🤖 Generated with Claude Code