Description
apt is intended for interactive use, and its behavior and output can change between versions. An automation-oriented interface is more suitable for Buildah scripts.
Potential impact
Builds relying on command behavior or output can fail after package-tool updates.
Remediation
Use apt-get for installation and apt-cache for package queries. This change alone does not pin package versions or make build results reproducible.
Examples
These excerpts change only the installation command in an Ubuntu container with package lists prepared. Manage image and package versions and the remaining build steps separately.
Before
bash
c=$(buildah from ubuntu)
buildah run "${c}" apt install python3-setuptools -y
After
bash
c=$(buildah from ubuntu)
buildah run "${c}" apt-get install python3-setuptools -y