Official agent skill

Update Container Images

by microsoft in microsoft/aspire

Updates Docker container image tags used by Aspire hosting integrations.

OfficialMITAuto-check passedDevOps & Cloud

Install Update Container Images

skills CLI
$ npx skills add microsoft/aspire --skill update-container-images -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/aspire update-container-images --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/aspire.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/update-container-images .claude/skills/update-container-images && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
update-container-images
GitHub stars
6.3k
Token cost
~2.4k tokens
SKILL.md length
917 words
Files
4
Skills in repo
22
Repo updated
First seen
Licence
MIT

At a glance

Updates Docker container image tags used by Aspire hosting integrations.

  • Works in 7 steps: Run the Tag Fetcher Script → Analyze the JSON Report → Determine Version Updates → …
  • Tasks that involve Containers
  • SKILL.md covers Background, Understanding User Requests, Task Execution Steps and Important Constraints, plus 1 more section
  • Runs C# scripts from its folder; calls dotnet; reaches container-registry.oracle.com

What it does

Update Container Images is an agent skill from microsoft/aspire, published by the product's own GitHub organization. Updates Docker container image tags used by Aspire hosting integrations. Queries registries for newer tags, uses LLM to determine version-compatible updates, and applies changes. Use this when asked to update container image versions.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files.

It sits in DevOps & Cloud, covering Containers. It works with Docker. The repository describes itself as: Aspire is the tool for code-first, extensible, observable dev and deploy. The licence is MIT.

When your agent uses it

  • Tasks that involve Containers

Example prompts

  • “Use the update-container-images skill to update Docker container image tags used by Aspire hosting integrations”
  • “/update-container-images”

Requirements

  • Docker

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Run the Tag Fetcher Script
  2. Analyze the JSON Report
  3. Determine Version Updates
  4. Present Update Summary
  5. Apply Changes
  6. Validate Build
  7. Summarize Results

What it can do on your machine

Read from SKILL.md and the folder at commit a3f44d2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (C#), which the agent can run.

    Shell commands in SKILL.md call:

    • dotnet

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • container-registry.oracle.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Update Container Images loads about 2.4k tokens when it runs. Until then it costs about 65 tokens; SKILL.md has 917 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/aspire at commit a3f44d2, republished under its MIT licence (© microsoft). 917 words, ~2,387 tokens.

Download SKILL.mdSave it as .claude/skills/update-container-images/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
update-container-images
description
Updates Docker container image tags used by Aspire hosting integrations. Queries registries for newer tags, uses LLM to determine version-compatible updates, and applies changes. Use this when asked to update container image versions.

You are a specialized container image update agent for the microsoft/aspire repository. Your primary function is to update the Docker container image tags used by Aspire hosting integrations to their latest compatible versions.

Background

Aspire hosting integrations pin specific Docker image tags in *ImageTags.cs files (e.g., SeqContainerImageTags.cs, RedisContainerImageTags.cs). These tags ensure the Aspire orchestrator uses known-compatible container images at runtime. Tags are intentionally pinned (never latest) and require periodic manual updates — roughly monthly.

Image Tag File Structure

Each *ImageTags.cs file follows this pattern:

csharp
internal static class RedisContainerImageTags
{
    /// <remarks>docker.io</remarks>
    public const string Registry = "docker.io";

    /// <remarks>library/redis</remarks>
    public const string Image = "library/redis";

    /// <remarks>8.6</remarks>
    public const string Tag = "8.6";
}

Some files contain multiple image definitions (primary + companion tools) using field name prefixes:

csharp
// Primary image: Registry, Image, Tag
// Companion:     PgAdminRegistry, PgAdminImage, PgAdminTag
Registries

The repository uses 5 container registries:

RegistryDomainAuth
Docker Hubdocker.ioAnonymous (Hub REST API)
Microsoft Container Registrymcr.microsoft.comAnonymous (OCI v2)
GitHub Container Registryghcr.ioAnonymous token
Oracle Container Registrycontainer-registry.oracle.comAnonymous token
Quay.io (Red Hat)quay.ioAnonymous (OCI v2)
Companion Script

A single-file C# script is bundled at .agents/skills/update-container-images/UpdateImageTags.cs. It discovers all *ImageTags.cs files, parses them, queries each registry for available tags, and outputs a structured JSON report. This script handles the deterministic work; the LLM handles version analysis.

Understanding User Requests

This skill is typically invoked with one of:

  • "Update container images" — full sweep of all images
  • "Update Docker image tags" — same as above
  • "Check for container image updates" — report only, don't apply

Task Execution Steps

Step 1: Run the Tag Fetcher Script

Run the companion script from the repository root to generate a JSON report of all images and their available tags:

bash
cd <repo-root>
dotnet run .agents/skills/update-container-images/UpdateImageTags.cs 2>update-tags-stderr.txt 1>update-tags-report.json

Check stderr for any failures:

bash
cat update-tags-stderr.txt

All registries should report a tag count. If any show FAILED, investigate the error (usually auth or network issues) before proceeding.

Step 2: Analyze the JSON Report

Read the generated update-tags-report.json. The report structure is:

json
{
  "images": [
    {
      "file": "src\\Aspire.Hosting.Redis\\RedisContainerImageTags.cs",
      "entries": [
        {
          "registry": "docker.io",
          "image": "library/redis",
          "currentTag": "8.6",
          "availableTags": ["8.6", "8.4", "8.2", "9.0", ...]
        }
      ]
    }
  ]
}

Entries marked with "skipped": true should be ignored (they are latest tags or derived/computed tags).

The script handles comprehensive tag discovery automatically — for Docker Hub images it queries both recent tags and version-prefix-based queries to ensure newer major/minor versions are included in the results.

Step 3: Determine Version Updates

For each image, apply these version analysis rules:

Rule 1: Match the Version Format (Precision)

The new tag must use the same version format as the current tag:

Current Tag FormatExampleMatch PatternDo NOT pick
M.m (2-part)8.28.6, 9.08.6.1, v8.6
M.m.p (3-part)9.9.09.12.0, 10.0.09.12, v9.12.0
vM.m.p (v-prefix 3-part)v1.15.5v1.16.3, v2.0.01.16.3, v1.16
vM.m (v-prefix 2-part)v2.5v2.6, v3.0v2.5.1, 2.5
YYYY.N (year.seq)2025.22025.3, 2026.12025.2.15571
M.m.p.b (4-part)23.26.0.023.26.1.023.26.1
YYYY-suffix2022-latest2025-latest2022-CU23
M.m.p-pre.N2.3.0-preview.42.3.0-preview.52.3.0, 2.3-preview
Rule 2: Cross Major Versions

Do cross major version boundaries. If Postgres is at 17.8 and 18.2 exists as an M.m tag, update to 18.2. The goal is to pick the newest tag that matches the same format.

Rule 3: Filter Out Platform Suffixes

Ignore tags with platform suffixes like -alpine, -bookworm, -amd64, -arm64, -fpm, -management-alpine, etc. Only consider "bare" tags matching the version format.

Exception: Tags like 4.2-management in RabbitMQ are derived/computed from the base Tag field and will be flagged as "isDerived": true in the report. Skip these — they auto-update when the base tag is updated.

Rule 4: Respect Known Issues

Check the source file for comments about known issues. For example, Milvus has:

csharp
// Note that when trying to update to v2.6.0 we hit https://github.com/microsoft/aspire/issues/11184

If such a comment exists, stay within the noted version range (e.g., v2.5.x for Milvus) unless you can verify the issue is resolved.

Show full SKILL.md (358 more words)Show less
Rule 5: Skip Non-Updatable Tags
  • Tags set to "latest" — cannot be version-bumped
  • Tags set to "vnext-latest" — not a version scheme
  • Derived/computed tags (e.g., $"{Tag}-management") — updated automatically
Step 4: Present Update Summary

Before applying changes, present a summary table to the user:

| Image | Current | New | Notes |
|-------|---------|-----|-------|
| library/postgres | 17.8 | 18.2 | Major version bump |
| qdrant/qdrant | v1.15.5 | v1.16.3 | Minor + patch bump |
| library/redis | 8.6 | 8.6 | Already latest |

Wait for user confirmation before proceeding. If the user wants to skip specific updates, honor that.

Step 5: Apply Changes

Edit each *ImageTags.cs file to update both the tag value and its <remarks> XML comment:

csharp
// Before:
/// <remarks>17.6</remarks>
public const string Tag = "17.6";

// After:
/// <remarks>18.2</remarks>
public const string Tag = "18.2";

Always update both the <remarks> and the string literal — they must stay in sync.

Step 6: Validate Build

Build all affected projects to ensure the changes compile:

bash
# Restore first if needed
./restore.cmd   # Windows
./restore.sh    # Linux/macOS

# Build each affected project
dotnet build src/Aspire.Hosting.Redis/Aspire.Hosting.Redis.csproj --no-restore -v q /p:SkipNativeBuild=true
dotnet build src/Aspire.Hosting.PostgreSQL/Aspire.Hosting.PostgreSQL.csproj --no-restore -v q /p:SkipNativeBuild=true
# ... repeat for each modified project

All projects must build successfully. If any fail, investigate whether it's related to the tag change (it shouldn't be — these are just string constants).

Step 7: Summarize Results

Present a final summary:

## Container Image Tag Updates

Updated 15 tags across 12 files:

| File | Field | Old Tag | New Tag |
|------|-------|---------|---------|
| PostgresContainerImageTags.cs | Tag | 17.6 | 18.2 |
| PostgresContainerImageTags.cs | PgAdminTag | 9.9.0 | 9.12.0 |
| ... | ... | ... | ... |

Unchanged (already latest): 14 entries
Skipped (latest/derived): 6 entries
Build: ✅ All affected projects compile

Important Constraints

  1. Always run the companion script first — don't try to manually query registries or guess versions
  2. Always confirm with the user before applying changes
  3. Always update both <remarks> and string literal in sync
  4. Always build after applying to verify changes compile
  5. Never update latest tags — they are intentionally unpinned
  6. Never add more precision to a tag (e.g., don't change 8.6 to 8.6.1)
  7. Never remove precision from a tag (e.g., don't change v1.16.3 to v1.16)
  8. Check for comments about known issues before updating an image
  9. Clean up temporary files (update-tags-report.json, update-tags-stderr.txt) after completing

Troubleshooting

Registry Query Failures
  • Oracle 401 Unauthorized: The script needs to acquire a token from https://container-registry.oracle.com/auth. If this fails, Oracle may be experiencing issues — skip and flag for manual review.
  • Docker Hub rate limits: Unauthenticated Docker Hub requests are limited to 100/6hr. The ~15-20 queries should be well within limits.
  • GHCR token failures: GHCR anonymous tokens occasionally fail. Retry once before flagging.
Version Confusion

Some images use non-standard versioning:

  • Seq: Uses YYYY.N format (e.g., 2025.2), but also has build-number tags like 2025.2.15571 — ignore the build-number variants
  • Oracle: Uses 4-part versioning (23.26.1.0) — all 4 parts are significant
  • SQL Server: Uses YYYY-latest rolling tags — look for newer year-based rolling tags
  • Milvus: Has a known blocking issue preventing update to v2.6.x — stay on v2.5.x

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files in .agents/skills/update-container-images of microsoft/aspire.

  • SKILL.md
  • .editorconfig
  • Directory.Packages.props
  • UpdateImageTags.cs

Open the folder on GitHubat commit a3f44d2

Compare with similar skills

Update Container Images next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Update Container Images compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Update Container Images this skillmicrosoft/aspire6.3k—~2.4kAutomated safety check: PassMIT
Iron Proxy Gateway for NanoClawnanocoai/nanoclaw31k—~4.6kAutomated safety check: NotesMIT
GreptimeDB Dev Docker ImageGreptimeTeam/greptimedb6.7k—~4kAutomated safety check: NotesApache-2.0
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence
LangBot Deployment Guidelangbot-app/LangBot18k—~1.2kAutomated safety check: NotesApache-2.0
Build Openshell Mxc WindowsNVIDIA/OpenShell15k—~4.9kAutomated safety check: PassApache-2.0

Similar skills

  • Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.

    31k GitHub stars~4.6k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • GreptimeDB Dev Docker Image

    GreptimeTeam/greptimedb

    Packages a locally built GreptimeDB debug binary into a development-only Docker image for local-cluster testing, with an optional push to a dev registry.

    6.7k GitHub stars~4k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • LangBot Deployment Guide

    langbot-app/LangBot

    Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.

    18k GitHub stars~1.2k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Official

    Maintain and validate OpenShell's build-only Windows MSVC lane for x64 and ARM64.

    15k GitHub stars~4.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Omnigent Docker Compose Deploy

    omnigent-ai/omnigent

    Brings up the Omnigent server and Postgres as a Docker compose stack on any Docker host, and covers the Dockerfile's runtime and host build targets for extending it to a new platform.

    11k GitHub stars~1.3k tokensUpdated today
    DevOps & CloudAuto-check: notes

More from microsoft/aspire

All 22 skills in this repo
  • Azdo Internal

    microsoft/aspire

    Official

    A skill your agent uses when asked to trigger or inspect Aspire internal Azure DevOps builds, source-index runs, or release validation on dnceng/internal; push to the internal mirror; download build…

    6.3k GitHub stars~4.5k tokensUpdated today
    Auto-check passed
  • Backport PR

    microsoft/aspire

    Official

    Backports a merged PR to a release branch by triggering the /backport bot, waiting for the bot-created PR, and filling in the shiproom template (Customer Impact, Testing, Risk, Regression?).

    6.3k GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Bump Aspire Version

    microsoft/aspire

    Official

    Bumps the Aspire repository product version in eng/Versions.props using previous version-bump commits as guidance.

    6.3k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • CI Test Failures

    microsoft/aspire

    Official

    Guide for diagnosing GitHub Actions test failures, extracting failed tests from runs, and creating or updating failing-test issues.

    6.3k GitHub stars~4.7k tokensUpdated today
    Auto-check passed
  • Create PR

    microsoft/aspire

    Official

    Create a pull request using the repository PR template. An agent skill from microsoft/aspire.

    6.3k GitHub stars~4k tokensUpdated today
    Auto-check passed
  • Dashboard Testing

    microsoft/aspire

    Official

    Guide for writing tests for the Aspire Dashboard. An agent skill from microsoft/aspire.

    6.3k GitHub stars~4.7k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Update Container Images

What does Update Container Images do?

Updates Docker container image tags used by Aspire hosting integrations. Update Container Images is an agent skill from microsoft/aspire, published by the product's own GitHub organization. Updates Docker container image tags used by Aspire hosting integrations.

When should I use Update Container Images?

Update Container Images fits situations like: tasks that involve Containers.

How do I install Update Container Images in Claude Code?

Run `npx skills add microsoft/aspire --skill update-container-images -a claude-code`. Or copy the skill folder (.agents/skills/update-container-images in microsoft/aspire) into .claude/skills/update-container-images in your project. Claude Code loads it when a task matches its description.

How do I install Update Container Images in Codex?

Run `npx skills add microsoft/aspire --skill update-container-images -a codex`. Or copy the skill folder (.agents/skills/update-container-images in microsoft/aspire) into .agents/skills/update-container-images in your project. Codex loads it when a task matches its description.

Can I use Update Container Images in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/aspire --skill update-container-images -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/update-container-images, .gemini/skills/update-container-images, .github/skills/update-container-images and .opencode/skills/update-container-images in your project.

What does Update Container Images need to run?

Going by SKILL.md and its folder, Update Container Images needs C# for the scripts in its folder and the command-line tools its instructions call (dotnet). Our summary lists: Docker.

Does Update Container Images access the network?

SKILL.md names 1 domain. In commands or code: container-registry.oracle.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Update Container Images safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Update Container Images use?

Update Container Images is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Update Container Images use?

About 2.4k tokens (SKILL.md is roughly 9.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Update Container Images?

Skills that share tags, products or a category with Update Container Images: Iron Proxy Gateway for NanoClaw (nanocoai/nanoclaw, 31k stars), GreptimeDB Dev Docker Image (GreptimeTeam/greptimedb, 6.7k stars), Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars) and LangBot Deployment Guide (langbot-app/LangBot, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Update Container Images?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/aspire, which has 6,348 GitHub stars. The repository holds 22 skills in this directory. The repository was last updated on October 8, 2026.

Source: microsoft/aspire on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.