From 8c22140ebb010a253bad7c3aa4f3bcffb45c2e72 Mon Sep 17 00:00:00 2001 From: Akira Yamamoto <3007213+akirayamamoto@users.noreply.github.com> Date: Mon, 27 Apr 2026 14:27:46 +1000 Subject: [PATCH] Make ca-certificates dependency explicit ca-certificates-bundle (which provides /etc/ssl/certs/ca-certificates.crt) is already pulled in transitively by apache2 / php-apache2 on alpine:3.23, so live HTTPS calls from PHP work today (verified with file_get_contents against ipinfo.io). But the master image (FROM php:8-alpine) installs the full ca-certificates package explicitly, and operators with IPINFO_APIKEY configured rely on outbound HTTPS. Make the dependency explicit to: * Match master's package set rather than relying on a transitive pull that some future apk dep change could drop. * Document the runtime TLS requirement at the Dockerfile level instead of leaving it implicit. ~50 KB image-size cost; the umbrella ca-certificates package adds the update-ca-certificates CLI on top of the bundle. Per Qodo's review on PR #800. --- Dockerfile.alpine | 1 + 1 file changed, 1 insertion(+) diff --git a/Dockerfile.alpine b/Dockerfile.alpine index 472d5e3..e492a83 100755 --- a/Dockerfile.alpine +++ b/Dockerfile.alpine @@ -2,6 +2,7 @@ FROM alpine:3.23 RUN apk add --quiet --no-cache \ bash \ apache2 \ + ca-certificates \ php \ php-apache2 \ php-ctype \