Use COPY instead of ADD

Use COPY for local files and verify remote artifacts separately.

Description

ADD can download remote URLs or automatically extract archives in addition to copying files. Those extra behaviors are unnecessary for a local copy and can make a Dockerfile’s intent harder to understand.

Use COPY to place local files in an image. When downloading a remote artifact, verify its integrity separately or use a supported mechanism such as ADD --checksum. Keep local copying and remote downloading clearly distinguished.

Potential impact

  • It may be unclear whether an instruction copies, extracts or downloads files.
  • A local tar archive may be extracted unexpectedly.
  • Image builds can become harder to reproduce and maintain.

Remediation

  • Use COPY instead of ADD for local file copies.
  • When a remote download is needed, use a separate pattern that verifies its checksum.
  • Check whether ADD is actually needed for archive extraction or a remote artifact.

Examples

This existing example compares local JAR copying. Set JAR_FILE to an actual file in the build context and use a supported Java version for production images.

Before

dockerfile
FROM openjdk:10-jdk
VOLUME /tmp
ARG JAR_FILE
ADD ${JAR_FILE} app.jar
ENTRYPOINT ["java","-Djava.security.egd=file:/dev/./urandom","-jar","/app.jar"]

After

dockerfile
FROM openjdk:10-jdk
VOLUME /tmp
ARG JAR_FILE
COPY ${JAR_FILE} app.jar
ENTRYPOINT ["java","-Djava.security.egd=file:/dev/./urandom","-jar","/app.jar"]

Explanation:

  • Before: Using ADD for a local artifact introduces extra behavior that can make the build less predictable.
  • After: COPY makes the local-copy intent explicit. Verify the artifact’s trustworthiness and integrity separately.

References