Review integrity checks for remote artifacts

Verify remote files with a trusted checksum or signature before using them.

Description

Downloading remote files in a Dockerfile without verifying their origin and integrity can introduce tampered files into the image. HTTPS protects transport but does not establish that the file is the expected artifact.

ADD is not inherently the wrong choice. Supported Dockerfile versions can use ADD --checksum to verify the SHA-256 digest of a remote HTTP file. Downloads made with curl or wget also need verification.

Potential impact

  • Tampered executables or configuration can be included in the image and used at runtime.
  • Content at a mutable URL can change the build result for the same Dockerfile.

Remediation

  • Use a trusted distribution source, independently establish the expected checksum or signature, and verify the download against it.
  • Use ADD --checksum or explicit download and verification commands, failing the build on verification errors. Explicitly extract archives and remove temporary files when needed.

Examples

Supply a supported Linux Java base image with tar through the JAVA_BUILD_IMAGE build argument. This replaces the deprecated openjdk image. The example.com URL and checksum are placeholders and must be replaced with the real source and verified value.

Before

dockerfile
ARG JAVA_BUILD_IMAGE
FROM ${JAVA_BUILD_IMAGE}

ADD https://example.com/app.tar.gz /opt/app/

After

dockerfile
ARG JAVA_BUILD_IMAGE
FROM ${JAVA_BUILD_IMAGE}

ADD --checksum=sha256:0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef \
    https://example.com/app.tar.gz /tmp/app.tar.gz
RUN mkdir -p /opt/app \
    && tar -xzf /tmp/app.tar.gz -C /opt/app \
    && rm /tmp/app.tar.gz

Explanation:

  • Before: The remote file is downloaded without checksum verification. This ADD does not automatically extract the remote archive.
  • After: ADD --checksum verifies the content before explicit extraction and temporary-file cleanup. Do not use the placeholder checksum unchanged.

References