Description
In FROM alpine:latest, latest is a mutable tag chosen by the publisher; it does not guarantee the newest image. If the tag points elsewhere, rebuilding the same Dockerfile can produce different results.
This makes reproducibility harder and can introduce unexpected production changes. A version tag identifies a release series but can also change. A verified digest, as in image:latest@sha256:..., fixes the selected image contents.
Potential impact
- Repository changes can select a different base image.
- Unexpected version changes can cause compatibility problems.
- Troubleshooting and rollback become harder.
Remediation
- Use a specific version tag instead of relying on
latest. - Define clear tag policies for production, testing, and other environments.
- Add a digest for important images. Even with a
latesttag, a digest fixes the image contents selected.
Examples
Before
dockerfile
FROM alpine:latest
After
dockerfile
FROM alpine:3.22
Explanation:
- Before:
latestis not a fixed version, so build results can change. - After: The intended release series is explicit. Use a digest for exact content pinning and continue applying security updates to pinned images.