All checks were successful
check / check (push) Successful in 1m9s
The `(Debian-based)` parenthetical broke the required `# image:vX.Y.Z, YYYY-MM-DD` form and asserted a base change that never happened (v2.12.1 was Debian too); the tag before the digest left three FROM lines in one file using two conventions. Digest unchanged, in both Dockerfile and Dockerfile.lint. The golang and alpine pin comments already matched the required form. script/verify-lint-image-pin parses these two FROM lines to keep them identical and still matches the tagless form; its advice line drops the now-meaningless "tag and digest". With no tag in either reference a tag-only disagreement cannot arise; a tag reintroduced on one side is caught as a plain mismatch.