Description
apt is designed for interactive terminal use and does not guarantee interface compatibility across versions. Tools such as apt-get and apt-cache provide more stable interfaces for automation in Dockerfiles.
This does not mean apt always fails. Switching commands alone also does not pin package versions or build results.
Potential impact
- APT version changes can alter output or behavior expected by scripts.
- Unexpected differences can make image builds and maintenance harder.
Remediation
- Use apt-get for installation and apt-cache for package information. Adapt subcommands and options according to each tool’s documentation.
- Keep apt-get update and installation in the same RUN, configure automatic confirmation and cache cleanup, and verify actual builds and version management.
Examples
The examples compare interfaces for automation. The after example also refreshes package indexes; cache cleanup and version pinning are omitted.
Before
dockerfile
FROM ubuntu:24.04
RUN apt install -y curl
After
dockerfile
FROM ubuntu:24.04
RUN apt-get update \
&& apt-get install -y curl
Explanation:
- Before: The command uses the interactively oriented apt interface and omits index refresh.
- After: apt-get refreshes indexes and installs packages. This does not prevent every package or network error.