Description
ADD can download remote URLs or automatically extract archives in addition to copying files. Those extra behaviors are unnecessary for a local copy and can make a Dockerfile’s intent harder to understand.
Use COPY to place local files in an image. When downloading a remote artifact, verify its integrity separately or use a supported mechanism such as ADD --checksum. Keep local copying and remote downloading clearly distinguished.
Potential impact
- It may be unclear whether an instruction copies, extracts or downloads files.
- A local tar archive may be extracted unexpectedly.
- Image builds can become harder to reproduce and maintain.
Remediation
- Use
COPYinstead ofADDfor local file copies. - When a remote download is needed, use a separate pattern that verifies its checksum.
- Check whether
ADDis actually needed for archive extraction or a remote artifact.
Examples
This existing example compares local JAR copying. Set JAR_FILE to an actual file in the build context and use a supported Java version for production images.
Before
dockerfile
FROM openjdk:10-jdk
VOLUME /tmp
ARG JAR_FILE
ADD ${JAR_FILE} app.jar
ENTRYPOINT ["java","-Djava.security.egd=file:/dev/./urandom","-jar","/app.jar"]
After
dockerfile
FROM openjdk:10-jdk
VOLUME /tmp
ARG JAR_FILE
COPY ${JAR_FILE} app.jar
ENTRYPOINT ["java","-Djava.security.egd=file:/dev/./urandom","-jar","/app.jar"]
Explanation:
- Before: Using
ADDfor a local artifact introduces extra behavior that can make the build less predictable. - After:
COPYmakes the local-copy intent explicit. Verify the artifact’s trustworthiness and integrity separately.