Description
A command such as yum install httpd can select different versions as the repository changes. Rebuilding the same Dockerfile may therefore produce a different image.
Consistent deployment images make troubleshooting and rollback easier. Specifying package versions reduces unexpected changes.
Potential impact
- Different package versions can be installed between builds.
- Unexpected package changes can alter application behavior.
- Test and production images can have different contents.
Remediation
- Specify an exact version and release available in the repository, using the form
yum install -y httpd-<version>-<release>. - Keep resolved versions fixed even when they are managed through variables.
- Test changes and perform security checks before updating versions.
Examples
These are installation excerpts for a supported image that provides yum. Supply a reviewed version-release available in that image’s repository through HTTPD_VERSION_RELEASE. Manage pinning and security updates for other packages and the base image separately.
Before
dockerfile
RUN yum install -y httpd && yum clean all
RUN ["yum", "install", "httpd"]
After
dockerfile
ARG HTTPD_VERSION_RELEASE
RUN test -n "$HTTPD_VERSION_RELEASE" && yum install -y "httpd-${HTTPD_VERSION_RELEASE}" && yum clean all
Explanation:
- Before: Unspecified versions let repository changes affect the build.
- After: The required version is supplied explicitly to control the package installed.