Description
A command such as apk add py3-pip can install different versions as the Alpine repository changes. The same Dockerfile can therefore produce different images over time.
Reproducible production images make troubleshooting and rollback easier. Use the apk add package=version form to reduce unexpected changes.
Potential impact
- Repository changes can select different package versions.
- Dependency changes can alter application behavior.
- Rebuilt deployment images can differ from the tested image.
Remediation
- Specify versions with the
apk add package=versionform. - Pin each package when installing several at once.
- Test changes and check vulnerabilities before updating versions.
Examples
These installation excerpts assume the same supported Alpine environment. Supply a reviewed version and its -r release from that repository through PIP_APK_VERSION. Installation can fail if the pinned package disappears from the repository, so plan how required packages will remain available.
Before
dockerfile
RUN apk add --update py3-pip
After
dockerfile
ARG PIP_APK_VERSION
RUN test -n "$PIP_APK_VERSION" && apk add --update "py3-pip=${PIP_APK_VERSION}"
Explanation:
- Before: The package version is unspecified and build results can change.
- After: An explicit version controls the package selected for the image.