Base-image version is not specified

An unspecified base-image version can change the result of a Docker build.

Description

A reference such as FROM alpine uses the latest tag when no tag or digest is supplied. If that tag points to another image, rebuilding the same Dockerfile can produce different results.

The base image defines the application’s execution environment. Use an explicit tag and, where possible, a digest to support reproducible builds.

Potential impact

  • Builds can contain different operating-system or library versions.
  • Unexpected image changes can make test and production results differ.
  • Vulnerability assessment and deployment tracking become harder.

Remediation

  • Specify an explicit image tag, such as FROM alpine:3.22.
  • Tags can be reassigned; use a digest to select the same image contents. Review security updates and refresh pinned images.
  • Also specify versions or digests for external images used in multistage builds.

Examples

Before

dockerfile
FROM alpine

After

dockerfile
FROM alpine:3.22

Explanation:

  • Before: The untagged base-image reference can resolve differently as the repository changes.
  • After: A version tag identifies the intended release series. The tag remains mutable; add a verified digest when identical contents are required.

References