Base image uses the latest tag

Using the latest tag can select a different base image in later Docker builds.

Description

In FROM alpine:latest, latest is a mutable tag chosen by the publisher; it does not guarantee the newest image. If the tag points elsewhere, rebuilding the same Dockerfile can produce different results.

This makes reproducibility harder and can introduce unexpected production changes. A version tag identifies a release series but can also change. A verified digest, as in image:latest@sha256:..., fixes the selected image contents.

Potential impact

  • Repository changes can select a different base image.
  • Unexpected version changes can cause compatibility problems.
  • Troubleshooting and rollback become harder.

Remediation

  • Use a specific version tag instead of relying on latest.
  • Define clear tag policies for production, testing, and other environments.
  • Add a digest for important images. Even with a latest tag, a digest fixes the image contents selected.

Examples

Before

dockerfile
FROM alpine:latest

After

dockerfile
FROM alpine:3.22

Explanation:

  • Before: latest is not a fixed version, so build results can change.
  • After: The intended release series is explicit. Use a digest for exact content pinning and continue applying security updates to pinned images.

References