I always advocate having custom-built docker images for CI, periodically refreshed for security fixes. CI should not run more than few seconds over the standard time to run the same thing from a dev machine.
However, other people around me are fine with apt installs and pip installs from global mirrors in every CI run. So I may be just autistic.
I do this occasionally. But it's because my company's security org has a ridiculous policy enforcing 0 CVE images for anything running on our infra (including internal CI images).
In some cases baking a dependency into an image is signing myself up for perpetual toil to keep the image CVE free.
wannabe44 · · focus · HN ↗
However, other people around me are fine with apt installs and pip installs from global mirrors in every CI run. So I may be just autistic.
bumblehean · · focus · HN ↗
In some cases baking a dependency into an image is signing myself up for perpetual toil to keep the image CVE free.