Missing package version pins in apt-get installs

Specify package versions for apt-get install to reduce unexpected changes to build results while continuing to manage security updates.

Description

Using apt-get install without specifying package versions can install different versions as the package repository changes. As a result, the same Dockerfile can produce different results when built at different times.

Pinning versions reduces unplanned changes, but does not guarantee that the pinned version is secure or that the entire image is reproducible. Available packages, base images, and repository state also need to be managed.

Potential impact

  • A rebuilt image can contain different package versions from an earlier build.
  • Untested updates can change application compatibility or behavior.
  • Conversely, leaving version pins unchanged indefinitely can prevent necessary security fixes from being applied.

Remediation

  • Specify versions using apt-get install package=version and review each package when installing several together.
  • Run apt-get update before installation in the same RUN step, and confirm that the target distribution's repository contains the selected versions.
  • Review security updates regularly, test them, and update version pins.

Version-specification examples

These snippets illustrate the difference in version syntax; they are not runnable build instructions. The standard busybox image does not include apt-get, and python=2.7 is not a recommended version for current use. For a real build, choose an apt-capable base image and a supported version available in its repository.

Without a version specification

dockerfile
FROM busybox
RUN apt-get install python
RUN ["apt-get", "install", "python"]

With a version specification

dockerfile
FROM busybox
RUN apt-get install python=2.7

Explanation:

  • Without a version: Only the package name is specified, leaving the version unrestricted.
  • With a version: The =2.7 suffix requests that version. For a real build, specify a reviewed, supported package version available in the selected distribution.

References