Review apt-get recommended package installation

Identify required packages and dependencies, and reduce unnecessary recommended packages.

Description

With its default configuration, apt-get install also installs recommended packages (Recommends). Including recommendations that the workload does not need increases image size and the amount of software to maintain.

--no-install-recommends limits automatic installation of recommended packages. It does not omit required dependencies or guarantee that installed packages are secure.

Potential impact

  • Unused binaries and libraries can increase image size and update-management work.
  • Omitting a recommended package that the application actually needs can break functionality.

Remediation

  • Use --no-install-recommends with apt-get install where appropriate, and explicitly install any additional packages that are actually required.
  • Verify the installed package set and application behavior, and remove unnecessary caches and package lists in the same RUN.

Examples

The examples compare only the recommended-package option. Cache cleanup and version pinning are omitted.

Before

dockerfile
FROM ubuntu:24.04

RUN apt-get update \
    && apt-get install -y curl

After

dockerfile
FROM ubuntu:24.04

RUN apt-get update \
    && apt-get install -y --no-install-recommends curl

Explanation:

  • Before: Depending on APT configuration, curl’s recommended packages can also be installed.
  • After: Recommended packages are not added automatically, but curl’s required dependencies are still installed. Test the functionality you need.

References