dnf package versions are not pinned

Leaving versions unspecified in dnf install can change Docker build results.

Description

Installing packages by name alone with dnf install can select different versions as the repository changes. Rebuilding the same Dockerfile can therefore produce a different image.

These differences can cause unexpected dependency changes, compatibility problems, or deployment failures. Specify package versions to control what is installed.

Potential impact

  • Repository updates can change image contents.
  • Package changes can affect application behavior or configuration.
  • A rebuilt deployment image can differ from the tested image.

Remediation

  • Specify an exact version and release available in the repository, using the form dnf install httpd-<version>-<release>.
  • Pin each package where multiple packages are installed.
  • Test updates and check vulnerabilities before changing versions.

Examples

Supply a reviewed version-release available in the selected Fedora repository through HTTPD_VERSION_RELEASE. The latest base and general update remain mutable, so pinning one package does not make the whole image reproducible.

Before

dockerfile
FROM fedora:latest
RUN dnf -y update && dnf -y install httpd && dnf clean all
RUN ["dnf", "install", "httpd"]

After

dockerfile
FROM fedora:latest
ARG HTTPD_VERSION_RELEASE
RUN test -n "$HTTPD_VERSION_RELEASE" && dnf -y update && dnf -y install "httpd-${HTTPD_VERSION_RELEASE}" && dnf clean all

Explanation:

  • Before: The package version is not pinned and can change between builds.
  • After: The reviewed version is provided explicitly to control the named package.

References