Repository navigation
chore: pin Node 24 (24.21.0) across CI, Docker images, and Volta - #257
Conversation
Node was 20.19.0 in CI and Volta, 18.20.8 in the react Dockerfile, and floating `node:alpine` (currently Node 26) in the three backend Dockerfiles, so backend images changed Node major on rebuild with no code change. - ci.yml: setup-node 24.21.0 - react-ystemandchess/Dockerfile: both stages node:24.21.0-alpine - chessServer, stockfishServer, middlewareNode Dockerfiles: node:24.21.0-alpine - volta.node 24.21.0 and engines.node ">=24 <25" in the root and each service package.json (Volta resolves the nearest package.json, so pinning only the root would leave service dirs on 20.19.0) - lockfiles: only the matching engines entry - README: Node 24.21.0 setup instructions Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Heads-up for the stockfishServer "extra look": the Stockfish engine can't start in the Docker image (pre-existing, not caused by this PR)
Alpine images use musl and don't ship
So it's broken on Possible fix (not included here, to keep this PR a pure version pin): switch |
|
Update: booted the middlewareNode and stockfishServer images too (details in the Testing section). All four images now boot on Node 24.21.0. One non-Node finding while doing that: middleware can exit on a cold start if Mongo isn't accepting connections yet (1s dev timeout → falls back to |
Deepesh-Katudia
left a comment
There was a problem hiding this comment.
Approving. This is a clean, well-scoped pin. 24.21.0 is the current latest Node 24 release, CI is green on it, and replacing the floating node:alpine tag (which currently resolves to Node 26) in the three backend images is the important fix here. Thanks for booting all four images and for writing up the Stockfish finding.
Non-blocking comments:
Medium
- Exact-patch Docker pins won't pick up security updates.
node:24.21.0-alpineis frozen, so every Node 24 security release now means a manual bump in about 12 places (5FROMlines, CI, Volta, README). Suggest a follow-up adding a Dependabotdocker+npmconfig (or Renovate) so these come in as PRs. The other option isnode:24-alpineif we'd rather take patches automatically than have exact reproducibility. - The Stockfish engine can't run in the stockfishServer image. This is pre-existing and not caused by this PR, as your comment explains. Since
/api/analyzesilently falls back to the material-count heuristic, production analysis is degraded without anyone noticing. Please open the-slimfollow-up PR you offered (or an issue) so it's tracked.
Low
3. ci.yml could use node-version-file: package.json. setup-node@v4 reads volta.node, which would make the root package.json the single source of truth instead of repeating the version.
4. engines only produces warnings unless engine-strict=true is set in .npmrc. That's probably what we want for contributors; just noting that it isn't enforced.
5. chessclient/Dockerfile is still on node:18-alpine (Node 18 is EOL). It's out of scope here, but worth an issue so it isn't forgotten.
Merge note: chore/frontend-cra-to-vite touches the same files: ci.yml, react-ystemandchess/Dockerfile, and the frontend package.json and lockfile. Expect small conflicts in whichever lands second. Node 24 is compatible with Vite, which needs at least 20.19.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Summary
Pins Node.js to 24.21.0 everywhere. Before this, Node was 20.19.0 in CI and Volta, 18.20.8 in the react Dockerfile, and floating
node:alpinein the three backend Dockerfiles, which currently resolves to Node 26, so backend images could change Node major on any rebuild with no code change.Type of Change
Key Changes
.github/workflows/ci.yml:setup-node→24.21.0react-ystemandchess/Dockerfile: both stages →node:24.21.0-alpinechessServer,stockfishServer,middlewareNodeDockerfiles:node:alpine→node:24.21.0-alpinevolta.node→24.21.0and"engines": { "node": ">=24 <25" }in the root and each servicepackage.json. Volta resolves the nearestpackage.json, so pinning only the root would leave anyone runningnpm startinside a service directory on 20.19.0.enginesentry (npm's unrelateddev-flag/name churn was dropped to keep the diff reviewable).README.md: setup instructions updated from 18.20.8 to 24.21.0.Testing
All on Node 24.21.0 after a clean
npm ci:react-ystemandchessproduction build compiles (existing lint/source-map warnings only, unrelated to Node)node:24.21.0-alpineand were booted:mongo:6container): connects, seeds,GET /returns 200, andPOST /auth/loginas thestudenttest user returns 200/healthreturns{"status":"ok"}and the Socket.IO endpoint returns 200. The engine binary itself does not run in this image (pre-existing onmain, see the comment below)Not tested
npx playwright test): needs the full stack running; CI doesn't run it either.node:18-alpineas the build stage and is slated to become plain nginx).Merge notes
sahana/208-azure-cicd: the only conflict is the expected duplicateTest middlewareNodestep inci.yml(keep Sahana's). No other files conflict.mainand deliberately not changed here.🤖 Generated with Claude Code