pip install Without --no-cache-dir
LOWpip install without --no-cache-dir. Pip cache remains in image, adding 50-200 MB depending on dependencies.
pip install without --no-cache-dir. Pip cache remains in image, adding 50-200 MB depending on dependencies.
Experiment with the vulnerable code and security rule below. Edit the code to see how the rule detects different vulnerability patterns.
pathfinder ci --ruleset docker/DOCKER-BP-008 --project .Explore related security rules for Docker
apt-get install without --no-install-recommends. This installs unnecessary packages, increasing image size and attack surface.
Avoid 'apk upgrade' in Dockerfiles. Use specific base image versions instead for reproducible builds.
Avoid apt-get upgrade in Dockerfiles. Use specific base image versions instead.
Common questions about pip install Without --no-cache-dir
Use Code Pathfinder to scan your Docker codebase and automatically detect instances of this vulnerability pattern. Install Code Pathfinder and run the following command in your project directory:
pathfinder ci --ruleset docker/DOCKER-BP-008 --project .This rule is aligned with industry-standard security frameworks and classifications: