apt used in Buildah automation

Use the stable apt-get and apt-cache interfaces for automation.

Description

apt is intended for interactive use, and its behavior and output can change between versions. An automation-oriented interface is more suitable for Buildah scripts.

Potential impact

Builds relying on command behavior or output can fail after package-tool updates.

Remediation

Use apt-get for installation and apt-cache for package queries. This change alone does not pin package versions or make build results reproducible.

Examples

These excerpts change only the installation command in an Ubuntu container with package lists prepared. Manage image and package versions and the remaining build steps separately.

Before

bash
c=$(buildah from ubuntu)
buildah run "${c}" apt install python3-setuptools -y

After

bash
c=$(buildah from ubuntu)
buildah run "${c}" apt-get install python3-setuptools -y

References