Description
With its default configuration, apt-get install also installs recommended packages (Recommends). Including recommendations that the workload does not need increases image size and the amount of software to maintain.
--no-install-recommends limits automatic installation of recommended packages. It does not omit required dependencies or guarantee that installed packages are secure.
Potential impact
- Unused binaries and libraries can increase image size and update-management work.
- Omitting a recommended package that the application actually needs can break functionality.
Remediation
- Use --no-install-recommends with apt-get install where appropriate, and explicitly install any additional packages that are actually required.
- Verify the installed package set and application behavior, and remove unnecessary caches and package lists in the same RUN.
Examples
The examples compare only the recommended-package option. Cache cleanup and version pinning are omitted.
Before
dockerfile
FROM ubuntu:24.04
RUN apt-get update \
&& apt-get install -y curl
After
dockerfile
FROM ubuntu:24.04
RUN apt-get update \
&& apt-get install -y --no-install-recommends curl
Explanation:
- Before: Depending on APT configuration, curl’s recommended packages can also be installed.
- After: Recommended packages are not added automatically, but curl’s required dependencies are still installed. Test the functionality you need.