Gem package versions are not pinned

Installing gems without versions can change the packages included in a Docker build.

Description

When gem install does not specify a Ruby package version, the selected version can change with the repository. Rebuilding the same Dockerfile can therefore produce different results.

Dependency changes in a deployment image can alter application behavior or cause compatibility failures. Explicit gem versions help control these changes.

Potential impact

  • Repository updates can change the contents of the image.
  • Unexpected upgrades can cause runtime errors.
  • Test and production environments can end up with different packages.

Remediation

  • Specify a gem version, as in gem install bundler:2.0.2.
  • Specify each version when installing multiple gems.
  • Test updates before changing pinned values.

Examples

These installation excerpts assume an image with Ruby and RubyGems available. The versions are historical syntax examples, not production recommendations. Choose reviewed, supported versions and manage transitive dependencies with a lock file.

Before

dockerfile
RUN gem install bundler
RUN ["gem", "install", "blunder"]

After

dockerfile
RUN gem install bundler:2.0.2
ENV GRPC_VERSION 1.0.0
RUN gem install grpc:${GRPC_VERSION} grpc-tools:${GRPC_VERSION}

Explanation:

  • Before: Package names alone allow the selected versions to change between builds.
  • After: Explicit versions control changes to the named dependencies.

References