Description
Installing packages by name alone with dnf install can select different versions as the repository changes. Rebuilding the same Dockerfile can therefore produce a different image.
These differences can cause unexpected dependency changes, compatibility problems, or deployment failures. Specify package versions to control what is installed.
Potential impact
- Repository updates can change image contents.
- Package changes can affect application behavior or configuration.
- A rebuilt deployment image can differ from the tested image.
Remediation
- Specify an exact version and release available in the repository, using the form
dnf install httpd-<version>-<release>. - Pin each package where multiple packages are installed.
- Test updates and check vulnerabilities before changing versions.
Examples
Supply a reviewed version-release available in the selected Fedora repository through HTTPD_VERSION_RELEASE. The latest base and general update remain mutable, so pinning one package does not make the whole image reproducible.
Before
dockerfile
FROM fedora:latest
RUN dnf -y update && dnf -y install httpd && dnf clean all
RUN ["dnf", "install", "httpd"]
After
dockerfile
FROM fedora:latest
ARG HTTPD_VERSION_RELEASE
RUN test -n "$HTTPD_VERSION_RELEASE" && dnf -y update && dnf -y install "httpd-${HTTPD_VERSION_RELEASE}" && dnf clean all
Explanation:
- Before: The package version is not pinned and can change between builds.
- After: The reviewed version is provided explicitly to control the named package.