3 ms·
Pinning the version tag for base images in Dockerfile is a good idea beyond the scope of security. It helps with onboarding as well. I've been in situations whe
by tomphoolery 6y ago
Pinning the version tag for base images in Dockerfile is a good idea beyond the scope of security. It helps with onboarding as well. I've been in situations where depending on the `:latest` tag of a base image caused different versions of that image to be used on different machines, resulting in developers having weird issues that no one else was having ("I thought Docker was supposed to solve this!"). Now, I only use non-specific tags like `:latest` or `:12-alpine` before I distribute the Docker image, by either collaborating with others or pushing it to Docker Hub. It just gives me peace of mind to know that others are building on the exact same stack as I was building on.
- 3pt14159 6y agoThis is a reasonable choice to make depending on the complexity of your project. For the projects I've been on, the latest version plus the test suite is enough to catch weirdness creeping in and, as a side benefit, it gets fixed faster than if it were pinned. Sometimes the issue really is caused by the base image and it is easier to get a fix merged if the issue was caused quite recently because the developers responsible see early reports of issues as more endemic than if they're reported days or weeks later.
- piaste 6y agoFor many popular images, you can use a major-version tag and fetch the latest patch but avoid breaking changes. Eg. postgres:12 instead of either postgres:latest or postgres:12.0.1