Skip to content

fix(docker): install only the main dependency group in the image - #469

Open
joszz wants to merge 1 commit into
SAIC-iSmart-API:developfrom
joszz:fix/docker-only-main-deps
Open

joszz wants to merge 1 commit into
SAIC-iSmart-API:developfrom
joszz:fix/docker-only-main-deps

Conversation

@joszz

@joszz joszz commented Oct 5, 2026 •

Copy link
Copy Markdown

The Dockerfile runs poetry install --no-root, which also installs the dev group. Every published image ships pytest, mypy, pylint, ruff, pre-commit and their dependencies in /usr/src/app/.venv, 31 packages that never run in the container. This adds --only main.

Why

  • Image scanners flag the dev tools all the same. Trivy reports virtualenv 21.3.1 (pulled in by pre-commit) in saicismartapi/saic-python-mqtt-gateway:0.12.0 for CVE-2026-102925, CVE-2026-102930 and CVE-2026-102937 (high) and CVE-2026-102938 (medium). Anything built on the image inherits those alerts.
  • The image doesn't need them. CI runs mypy, ruff and pytest on the runner (build_and_test_python.yml), not inside the image.
  • Smaller image. In a local Python 3.14 venv, site-packages drops from 73 MB to 17 MB.

Runtime versions don't change: --only main installs from the same poetry.lock.

Testing

On develop with Poetry 2.3.2 and Python 3.14:

  • poetry install --no-root --only main installs the 17 packages of the main group and nothing else.
  • python -c "import main" from src/ succeeds against that venv. main.py pulls in every module except log_config, which only uses the standard library.

I haven't built the Docker image itself, and PR CI only runs the Python tests, so the image build is still untested.

🤖 Generated with Claude Code

poetry install without --only main also installs the dev group, so the
runtime venv shipped pytest, mypy, pylint, ruff, pre-commit and their
dependencies, virtualenv among them, which image scanners flag. None of
it runs in the container: CI runs the checks on the runner.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant