Description
Using apt-get install without specifying package versions can install different versions as the package repository changes. As a result, the same Dockerfile can produce different results when built at different times.
Pinning versions reduces unplanned changes, but does not guarantee that the pinned version is secure or that the entire image is reproducible. Available packages, base images, and repository state also need to be managed.
Potential impact
- A rebuilt image can contain different package versions from an earlier build.
- Untested updates can change application compatibility or behavior.
- Conversely, leaving version pins unchanged indefinitely can prevent necessary security fixes from being applied.
Remediation
- Specify versions using
apt-get install package=versionand review each package when installing several together. - Run
apt-get updatebefore installation in the sameRUNstep, and confirm that the target distribution's repository contains the selected versions. - Review security updates regularly, test them, and update version pins.
Version-specification examples
These snippets illustrate the difference in version syntax; they are not runnable build instructions. The standard busybox image does not include apt-get, and python=2.7 is not a recommended version for current use. For a real build, choose an apt-capable base image and a supported version available in its repository.
Without a version specification
FROM busybox
RUN apt-get install python
RUN ["apt-get", "install", "python"]
With a version specification
FROM busybox
RUN apt-get install python=2.7
Explanation:
- Without a version: Only the package name is specified, leaving the version unrestricted.
- With a version: The
=2.7suffix requests that version. For a real build, specify a reviewed, supported package version available in the selected distribution.