Description
When automatic confirmation is not configured, dnf install in a Dockerfile may request confirmation. An automated build has no user to answer, so the command can stop or fail.
Potential impact
- CI/CD image builds can fail during package installation.
- Builds needed for deployment or recovery can take longer.
Remediation
- Use -y or --assumeyes with dnf install while retaining package selection and signature verification.
- Keep installation and dnf clean all in the same RUN, and check for additional questions or errors in the actual build. Automatic confirmation does not resolve dependency or network failures.
Examples
The existing Fedora 40 examples are preserved. Use a supported base image and package repositories for current builds.
Before
dockerfile
FROM fedora:40
RUN dnf install nginx
After
dockerfile
FROM fedora:40
RUN dnf install -y nginx \
&& dnf clean all
Explanation:
- Before: Installation can request confirmation.
- After: The -y option answers installation confirmation, followed by cache cleanup on success. Verify successful builds in the actual environment.