yum package versions are not pinned

Installing yum packages without versions can change the contents of a Docker build.

Description

A command such as yum install httpd can select different versions as the repository changes. Rebuilding the same Dockerfile may therefore produce a different image.

Consistent deployment images make troubleshooting and rollback easier. Specifying package versions reduces unexpected changes.

Potential impact

  • Different package versions can be installed between builds.
  • Unexpected package changes can alter application behavior.
  • Test and production images can have different contents.

Remediation

  • Specify an exact version and release available in the repository, using the form yum install -y httpd-<version>-<release>.
  • Keep resolved versions fixed even when they are managed through variables.
  • Test changes and perform security checks before updating versions.

Examples

These are installation excerpts for a supported image that provides yum. Supply a reviewed version-release available in that image’s repository through HTTPD_VERSION_RELEASE. Manage pinning and security updates for other packages and the base image separately.

Before

dockerfile
RUN yum install -y httpd && yum clean all
RUN ["yum", "install", "httpd"]

After

dockerfile
ARG HTTPD_VERSION_RELEASE
RUN test -n "$HTTPD_VERSION_RELEASE" && yum install -y "httpd-${HTTPD_VERSION_RELEASE}" && yum clean all

Explanation:

  • Before: Unspecified versions let repository changes affect the build.
  • After: The required version is supplied explicitly to control the package installed.

References