Description
MAINTAINER was used to record the image author in older Dockerfiles, but it is now deprecated. LABEL provides a more flexible way to manage metadata such as the author, team, repository and version.
This is primarily a maintenance issue rather than a direct security vulnerability. Inconsistent metadata conventions can make image maintenance and integration with automation tools harder.
Potential impact
- Older Dockerfile conventions can make maintenance standards inconsistent.
- Tools that read image metadata can require additional handling.
Remediation
- Use LABEL instead of MAINTAINER to declare author or management information.
- Define the needed metadata keys and values and verify compatibility with consuming tools. Do not put secrets in published image metadata.
Examples
The examples compare author metadata only. The app directory must contain a server file that can run in the target image.
Before
dockerfile
FROM alpine:3.20
MAINTAINER devops@example.com
COPY app /app
CMD ["/app/server"]
After
dockerfile
FROM alpine:3.20
LABEL maintainer="devops@example.com"
COPY app /app
CMD ["/app/server"]
Explanation:
- Before: The deprecated MAINTAINER instruction is used.
- After: LABEL stores the same author information. This does not change application permissions or security.