Description
Specifying only a package name in zypper install can select different versions as repositories change. The same Dockerfile can therefore produce different results over time, making failures harder to reproduce or roll back.
Version pinning controls changes; it does not establish that a version is secure. Base images, dependencies and repository state also affect build results.
Potential impact
- Unexpected dependency changes can alter application behavior.
- Keeping an old version pinned can prevent needed security fixes from being incorporated.
Remediation
- Check the package name and version available in your repositories and specify a reviewed version using package=version.
- Review security fixes and support periods when updating pins. Manage dependencies and repository snapshots when reproducibility matters.
Examples
The existing httpd=2.4.58 illustrates version syntax. Replace it with the Apache package name and version/release actually available in your openSUSE environment. Do not treat this base tag or package version as a current deployment recommendation.
Before
dockerfile
FROM opensuse/leap:15.6
RUN zypper install -y httpd \
&& zypper clean
After
dockerfile
FROM opensuse/leap:15.6
RUN zypper install -y httpd=2.4.58 \
&& zypper clean
Explanation:
- Before: Without a version constraint, the repository-selected version can change.
- After: A specific version is requested. The package and version must exist in the repository, and security updates still require separate management.