Review apt-get installation prompts

Automate apt-get confirmation and check for additional package-specific input.

Description

When automatic confirmation is not configured, apt-get install in a Dockerfile may request user input. An automated build such as a CI/CD job can stop or fail when it cannot provide that input.

The -y, --yes and --assume-yes options answer apt-get confirmation prompts. They do not handle every package configuration-script question or guarantee successful installation.

Potential impact

  • Automated builds can stop or fail at a confirmation prompt.
  • Image rebuilds needed for urgent deployment or recovery can be delayed.

Remediation

  • Use -y, --yes or --assume-yes with apt-get install and verify that the automated build completes.
  • Preconfigure required values for packages with additional questions, and scope noninteractive settings to the installation command. Do not bypass confirmation failures by disabling package signature verification.

Examples

The examples compare installation confirmation only. Index refresh and installation share a RUN instruction; cache cleanup and package version management need separate review.

Before

dockerfile
FROM ubuntu:24.04

RUN apt-get update && apt-get install curl

After

dockerfile
FROM ubuntu:24.04

RUN apt-get update && apt-get install -y curl

Explanation:

  • Before: apt-get may require installation confirmation.
  • After: The -y option answers apt-get confirmation. Additional package questions and dependency errors still need separate handling.

References