Description
Depending on its configuration, apk add in an Alpine image can leave package indexes and cache files in the image. Files that are unnecessary at runtime increase image size and storage or transfer costs.
This concerns image management and operational efficiency rather than a direct security vulnerability. Retaining caches can be appropriate when they are managed outside the final image.
Potential impact
- Unnecessary caches can increase image storage requirements and deployment time.
- Removing every cache can increase download costs for repeated builds.
Remediation
- Use --no-cache for ordinary apk add commands whose cache would remain in the image, or manage needed build caches outside the image.
- Inspect the final image’s contents. --no-cache avoids local-cache use for that command; it does not delete caches stored in earlier layers.
Examples
The existing Alpine 3.20 examples compare cache use only. Use a supported base and package repositories for actual builds.
Before
dockerfile
FROM alpine:3.20
RUN apk add --update-cache python3
After
dockerfile
FROM alpine:3.20
RUN apk add --no-cache python3
Explanation:
- Before: --update-cache refreshes indexes, and cache files can remain in the image.
- After: --no-cache installs without using a local cache. It does not remove caches that already exist.