Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
20 commits
Select commit Hold shift + click to select a range
bad77ef
chore(deps): bump @babel/core, protobufjs, yaml, webpack, tmp, tar, u…
cozminu Aug 4, 2026
f5ccf88
chore(deps): bump handlebars, shell-quote, websocket-driver
cozminu Aug 4, 2026
a22fb7f
chore(deps): bump babel systemjs transform, devalue, fast-uri, flatte…
cozminu Aug 4, 2026
2bed119
chore(deps): range-scoped bumps for brace-expansion, immutable, js-ya…
cozminu Aug 4, 2026
9a45958
chore(deps): astro 6.4.6, axios 1.18.0
cozminu Aug 4, 2026
25cf619
chore(deps): sharp 0.35.0, otel jaeger propagator 2.9.0
cozminu Aug 4, 2026
3f30814
chore(deps): suppress propagator-jaeger advisory instead of an otel v…
cozminu Aug 4, 2026
aeccbfa
chore(deps): relay-compiler 13 to drop immutable 3
cozminu Aug 4, 2026
ada1ae5
chore(deps): vanilla-extract integration 8 to drop vite 4
cozminu Aug 4, 2026
1dc9895
chore(deps): unscope the tmp override to catch 0.0.33
cozminu Aug 4, 2026
75a5d9c
chore(deps): drop npm from the prod runner images
cozminu Aug 6, 2026
930c772
chore(deps): collapse propagator-jaeger onto v2
cozminu Aug 6, 2026
3f7a507
chore(deps): record why bumping the base image doesn't help
cozminu Aug 6, 2026
d44848a
chore(deps): drop the scanner suppressions that are now dead
cozminu Aug 6, 2026
23e7805
chore: fail docker if npm rm fail, rm npm doc references
BlairCurrey Sep 16, 2026
5ff6d2c
Merge branch 'main' into cozmin/fix-all-deps
BlairCurrey Sep 16, 2026
92a467b
fix: openssl, next, faker, vulns
BlairCurrey Sep 16, 2026
219fcbd
fix: remove next
BlairCurrey Sep 17, 2026
935cb75
fix: posgtres startup error on authed frontend
BlairCurrey Sep 17, 2026
95d17f4
fix: drop rollup and vite overrides that match nothing
BlairCurrey Sep 17, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/node-build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -546,7 +546,7 @@ jobs:
- name: Scan docker image
run: |
docker images
/tmp/trivy image --db-repository ghcr.io/aquasecurity/trivy-db,public.ecr.aws/aquasecurity/trivy-db --java-db-repository ghcr.io/aquasecurity/trivy-java-db,public.ecr.aws/aquasecurity/trivy-java-db --ignore-unfixed --format table --vuln-type os,library --exit-code 1 --severity HIGH --input /tmp/${{ github.sha }}-${{ matrix.package }}-${{ matrix.platform.name }}-${{ needs.version-generator.outputs.version }}.tar
/tmp/trivy image --db-repository ghcr.io/aquasecurity/trivy-db,public.ecr.aws/aquasecurity/trivy-db --java-db-repository ghcr.io/aquasecurity/trivy-java-db,public.ecr.aws/aquasecurity/trivy-java-db --ignore-unfixed --format table --vuln-type os,library --exit-code 1 --severity HIGH,CRITICAL --input /tmp/${{ github.sha }}-${{ matrix.package }}-${{ matrix.platform.name }}-${{ needs.version-generator.outputs.version }}.tar

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

--severity is a list, not a floor. we werent scanning for critical vulnerabilities with Trivy


push:
name: Push to registry
Expand Down
3 changes: 0 additions & 3 deletions .grype.yaml

This file was deleted.

1 change: 0 additions & 1 deletion .trivyignore

This file was deleted.

2 changes: 1 addition & 1 deletion localenv/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -202,7 +202,7 @@ cloud-nine-mock-ase-1 | http://localhost:3010/?tenantId=438fa74a-fa7d-4317-9ced
Once authentication is enabled, create a user account by running the `invite-user` script from your terminal:

```sh
docker exec -it <admin-container-name> npm run invite-user -- example@mail.com
docker exec -it <admin-container-name> node --run invite-user -- example@mail.com
```

This generates a one-time invitation link. Open it in your browser to set a password and log in. See the [Rafiki Admin user guide](https://rafiki.dev/admin/admin-user-guide#invite-a-user) for more details.
Expand Down
8 changes: 8 additions & 0 deletions localenv/admin-auth/dbinit.sql
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,14 @@ CREATE USER happy_life_bank_auth WITH PASSWORD 'happy_life_bank_auth';
CREATE DATABASE happy_life_bank_auth;
ALTER DATABASE happy_life_bank_auth OWNER TO happy_life_bank_auth;

CREATE USER global_bank_backend WITH PASSWORD 'global_bank_backend';
CREATE DATABASE global_bank_backend;
ALTER DATABASE global_bank_backend OWNER TO global_bank_backend;

CREATE USER global_bank_auth WITH PASSWORD 'global_bank_auth';
CREATE DATABASE global_bank_auth;
ALTER DATABASE global_bank_auth OWNER TO global_bank_auth;

CREATE USER happy_life_kratos WITH PASSWORD 'kratos_password';
CREATE DATABASE happy_life_kratos;
ALTER DATABASE happy_life_kratos OWNER TO happy_life_kratos;
Expand Down
66 changes: 46 additions & 20 deletions package.json
Original file line number Diff line number Diff line change
Expand Up @@ -65,33 +65,59 @@
},
"pnpm": {
"overrides": {
"axios": "1.16.0",
"@ardatan/relay-compiler": "^13.0.2",
"@babel/core": "^7.29.6",
"@babel/plugin-transform-modules-systemjs": "^7.29.4",
"@apollo/server": "^5.5.0",
"@vanilla-extract/integration": "^8.0.10",
"@grpc/grpc-js@>=1.0.0": "^1.10.12",
"@opentelemetry/propagator-jaeger": "^2.10.0",
"@remix-run/router": ">=1.23.2",
"axios": "1.18.0",
"brace-expansion@>=1.0.0 <2.0.0": "^1.1.18",
"brace-expansion@>=2.0.0 <3.0.0": "^2.1.4",
"brace-expansion@>=5.0.0 <6.0.0": "^5.0.9",
"braces@<3.0.3": ">=3.0.3",
"devalue": "^5.8.1",
"dset@<3.1.4": ">=3.1.4",
"fast-uri": "^3.1.5",
"flatted": "^3.4.2",
"form-data": "^4.0.6",
"handlebars": "^4.7.9",
"immutable@>=5.0.0": "^5.1.8",
"jose": ">=4.15.5",
"js-yaml@>=3.0.0 <4.0.0": "^3.15.0",
"js-yaml@>=4.0.0 <5.0.0": "^4.3.0",
"json5@<1.0.2": ">=1.0.2",
"katex": ">=0.16.21",
"jose": ">=4.15.5",
"koa@>=2.0.0": "^2.16.4",
"koa@>=3.0.0": "^3.1.2",
"undici@>=5.0.0": "^8.3.0",
"undici@>=6.0.0": "^6.27.0",
"@grpc/grpc-js@>=1.0.0": "^1.10.12",
"immutable@>=3.0.0": "^3.8.3",
"immutable@>=5.0.0": "^5.1.5",
"picomatch@>=2.0.0": "^2.3.2",
"picomatch@>=4.0.0": "^4.0.4",
"protobufjs": "^7.6.2",
"tar": ">=7.5.11",
"braces@<3.0.3": ">=3.0.3",
"dset@<3.1.4": ">=3.1.4",
"lodash": ">=4.18.0",
"minimatch@>=3.0.0 <4.0.0": "^3.1.4",
"minimatch@>=9.0.0 <10.0.0": "^9.0.7",
"path-to-regexp@>=0.1.7": "^0.1.13",
"path-to-regexp@>=6.3.0": "^6.3.0",
"next": "15.5.18",
"form-data": "^4.0.6",
"sha.js": ">=2.4.12",
"@remix-run/router": ">=1.23.2",
"lodash": ">=4.18.0",
"picomatch@>=2.0.0": "^2.3.2",
"picomatch@>=4.0.0": "^4.0.4",
"postcss": "^8.5.23",
"protobufjs": "^7.6.5",
"qs@<6.14.1": ">=6.14.1",
"@apollo/server": "^5.5.0",
"turbo-stream": "^3.0.0"
"sha.js": ">=2.4.12",
"sharp": "^0.35.0",
"shell-quote": "^1.9.0",
"svgo": "^4.0.2",
"tar": ">=7.5.21",
"tar-fs@>=2.0.0 <3.0.0": "^2.1.4",
"tmp": "^0.2.7",
"turbo-stream": "^3.0.0",
"undici@>=5.0.0": "^8.3.0",
"undici@>=6.0.0": "^6.28.0",
"vite@>=6.0.0 <7.0.0": "^6.4.3",
"webpack": "^5.104.1",
"websocket-driver": "^0.7.5",
"ws@>=7.0.0 <8.0.0": "^7.5.11",
"ws@>=8.0.0 <9.0.0": "^8.21.0",
"yaml": "^2.8.3"
}
}
}
9 changes: 9 additions & 0 deletions packages/auth/Dockerfile.prod
Original file line number Diff line number Diff line change
Expand Up @@ -46,6 +46,15 @@ RUN pnpm --filter auth build

FROM node:24-alpine3.23 AS runner

# update packages to patch known vulnerabilities that haven't made it into base image yet
RUN apk upgrade --no-cache
Comment on lines +49 to +50

@BlairCurrey BlairCurrey Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

openssl had a vulnerability. It has been fixed but there is no alpine tag that includes it yet.

I think using distroless could have sidestepped this one as well.

This is a pattern I've seen elsewhere. Such as https://github.com/jupyterhub/configurable-http-proxy/blob/14568e1b426c4818317da567a8f8f4d19a7c28a2/Dockerfile#L11-L13

Trivy's org updates images like this as well: https://github.com/aquasecurity/kube-hunter/blob/bc47f08e88ea2a5fb059bf3b8a8edb1aefb4c6cc/Dockerfile#L10


# npm isn't used at runtime and no node:24 tag ships a patched one, so its bundled
# deps (tar, brace-expansion, ip-address, undici) fail every image scan.
RUN rm -rf /usr/local/lib/node_modules/npm /usr/local/bin/npm /usr/local/bin/npx \
&& ! command -v npm \
&& [ ! -e /usr/local/lib/node_modules/npm ]

RUN adduser -D rafiki

WORKDIR /home/rafiki
Expand Down
9 changes: 9 additions & 0 deletions packages/backend/Dockerfile.prod
Original file line number Diff line number Diff line change
Expand Up @@ -46,6 +46,15 @@ RUN pnpm --filter backend build

FROM node:24-alpine3.23 AS runner

# update packages to patch known vulnerabilities that haven't made it into base image yet
RUN apk upgrade --no-cache

# npm isn't used at runtime and no node:24 tag ships a patched one, so its bundled
# deps (tar, brace-expansion, ip-address, undici) fail every image scan.
RUN rm -rf /usr/local/lib/node_modules/npm /usr/local/bin/npm /usr/local/bin/npx \
&& ! command -v npm \
&& [ ! -e /usr/local/lib/node_modules/npm ]

# Since this is from a fresh image, we need to first create the Rafiki user
RUN adduser -D rafiki
WORKDIR /home/rafiki
Expand Down
6 changes: 3 additions & 3 deletions packages/backend/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,7 @@
},
"devDependencies": {
"@apollo/client": "^3.11.8",
"@faker-js/faker": "^8.4.1",
"@graphql-codegen/cli": "5.0.4",
"@graphql-codegen/introspection": "4.0.3",
"@graphql-codegen/typescript": "4.1.3",
Expand All @@ -41,7 +42,7 @@
"react": "~18.2.0",
"rosie": "^2.1.1",
"testcontainers": "^10.16.0",
"tmp": "^0.2.3",
"tmp": "^0.2.7",
"ts-node-dev": "^2.0.0"
},
"dependencies": {
Expand All @@ -50,7 +51,6 @@
"@apollo/server": "^5.0.0",
"@as-integrations/koa": "^1.1.1",
"@escape.tech/graphql-armor": "^2.4.0",
"@faker-js/faker": "^8.4.1",
"@graphql-tools/graphql-file-loader": "^8.0.12",
"@graphql-tools/load": "^8.0.12",
"@graphql-tools/schema": "^10.0.16",
Expand All @@ -74,7 +74,7 @@
"@opentelemetry/sdk-node": "^0.217.0",
"@opentelemetry/sdk-trace-node": "^1.25.1",
"ajv": "^8.12.0",
"axios": "1.16.0",
"axios": "1.18.0",
"base64url": "^3.0.1",
"dotenv": "^16.4.7",
"extensible-error": "^1.0.2",
Expand Down
9 changes: 9 additions & 0 deletions packages/card-service/Dockerfile.prod
Original file line number Diff line number Diff line change
Expand Up @@ -41,6 +41,15 @@ RUN pnpm --filter card-service build

FROM node:24-alpine3.23 AS runner

# update packages to patch known vulnerabilities that haven't made it into base image yet
RUN apk upgrade --no-cache

# npm isn't used at runtime and no node:24 tag ships a patched one, so its bundled
# deps (tar, brace-expansion, ip-address, undici) fail every image scan.
RUN rm -rf /usr/local/lib/node_modules/npm /usr/local/bin/npm /usr/local/bin/npx \
&& ! command -v npm \
&& [ ! -e /usr/local/lib/node_modules/npm ]

# Since this is from a fresh image, we need to first create the Rafiki user
RUN adduser -D rafiki
WORKDIR /home/rafiki
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -62,11 +62,11 @@ Access to Rafiki Admin uses an invitation-only system to ensure that only author
An administrator (someone with backend interface system access) can run the `invite-user` script in one of two ways: from outside the container on the host machine where Docker is running or directly inside the Rafiki Admin Docker container.

```nginx title="Outside container on host machine"
docker exec -it <admin-container-name> npm run invite-user -- example@mail.com
docker exec -it <admin-container-name> node --run invite-user -- example@mail.com
```

```nginx title="Inside Rafiki Admin Docker container"
npm run invite-user -- example@mail.com
node --run invite-user -- example@mail.com
```

After running the `invite-user` script, the script generates a recovery link that also serves as an invitation link. This link is output to the terminal, and the administrator can send it to the user. When the user opens the link in their browser, they're automatically logged in and taken to the account settings page where they can set a new password. Afterward, they can log in normally via the Rafiki Admin URL.
Expand Down Expand Up @@ -97,7 +97,7 @@ Rafiki Admin provides an automated account recovery flow which requires an SMTP
To remove a user, administrators can run the following script in a terminal window:

```nginx
docker exec -it <admin-container-name> npm run delete-user -- example@mail.com.
docker exec -it <admin-container-name> node --run delete-user -- example@mail.com.
```

### Why Ory Kratos?
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,7 @@ import { LinkOut } from '@interledger/docs-design-system'
| `ADMIN_PORT` | `config.auth.port.admin` | `3003` | The port of your Rafiki Auth Admin API server. |
| `AUTH_PORT` | `config.auth.port.auth` | `3006` | The port of your Open Payments authorization server. |
| `DATABASE_CLEANUP_WORKERS` | `config.auth.workers.cleanup` | `1` | The number of workers processing expired or revoked access tokens. |
| `ENABLE_MANUAL_MIGRATIONS` | _undefined_ | `false` | When `true`, you must run the auth Postgres database manually with the command `npm run knex – migrate:latest –envproduction` |
| `ENABLE_MANUAL_MIGRATIONS` | _undefined_ | `false` | When `true`, you must run the auth Postgres database manually with the command `node --run knex -- migrate:latest --env production` |
| `INCOMING_PAYMENT_INTERACTION` | `config.auth.interaction.incomingPayment` | `false` | When `true`, incoming Open Payments grant requests are interactive |
| `INTERACTION_EXPIRY_SECONDS` | _undefined_ | `600` (10 minutes) | The time, in seconds, for which a user can interact with a grant request before the request expires. |
| `INTERACTION_PORT` | _undefined_ | `3009` | The port number of your Open Payments interaction-related APIs. |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ import { LinkOut } from '@interledger/docs-design-system'
| `AUTO_PEERING_SERVER_PORT` | N | If autopeering is enabled, the server will use this port. |
| `CONNECTOR_PORT` | N | The port of the ILP connector for sending packets via ILP over HTTP. |
| `ENABLE_AUTO_PEERING` | N | When `true`, autopeering is enabled. |
| `ENABLE_MANUAL_MIGRATIONS` | N | When `true`, you must run the database manually with the command `npm run knex – migrate:latest –env production` |
| `ENABLE_MANUAL_MIGRATIONS` | N | When `true`, you must run the database manually with the command `node --run knex -- migrate:latest --env production` |
| `ENABLE_SPSP_PAYMENT_POINTERS` | N | When `true`, the SPSP route is enabled. |
| `ENABLE_TELEMETRY` | N | Enables the telemetry service on Rafiki. |
| `ENABLE_TELEMETRY_TRACES` | N | N/A |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,7 @@ import { LinkOut } from '@interledger/docs-design-system'
| `AUTO_PEERING_SERVER_PORT` | `config.backend.port.autoPeering` | `3005` | If autopeering is enabled, the server will use this port. |
| `CONNECTOR_PORT` | `config.backend.port.connector` | `3002` | The port of the ILP connector for sending packets via ILP over HTTP. |
| `ENABLE_AUTO_PEERING` | `config.backend.autoPeering.enabled` | `false` | When `true`, autopeering is enabled. |
| `ENABLE_MANUAL_MIGRATIONS` | _undefined_ | `false` | When `true`, you must run the database manually with the command `npm run knex - migrate:latest -env production` |
| `ENABLE_MANUAL_MIGRATIONS` | _undefined_ | `false` | When `true`, you must run the database manually with the command `node --run knex -- migrate:latest --env production` |
| `ENABLE_PARTIAL_PAYMENT_DECISION` | _undefined_ | `false` | Enables an ASE to act upon (approve/reject) a partial payment. |
| `ENABLE_SPSP_PAYMENT_POINTERS` | _undefined_ | `true` | When `true`, the SPSP route is enabled. |
| `ENABLE_TELEMETRY` | `config.backend.telemetry.enabled` | `false` | Enables the telemetry service on Rafiki. |
Expand Down
9 changes: 9 additions & 0 deletions packages/frontend/Dockerfile.prod
Original file line number Diff line number Diff line change
Expand Up @@ -41,6 +41,15 @@ RUN --mount=type=cache,id=pnpm,target=/pnpm/store \
RUN pnpm --filter frontend build

FROM node:24-alpine3.23 AS runner

# update packages to patch known vulnerabilities that haven't made it into base image yet
RUN apk upgrade --no-cache

# npm isn't used at runtime and no node:24 tag ships a patched one, so its bundled
# deps (tar, brace-expansion, ip-address, undici) fail every image scan.
RUN rm -rf /usr/local/lib/node_modules/npm /usr/local/bin/npm /usr/local/bin/npx \
&& ! command -v npm \
&& [ ! -e /usr/local/lib/node_modules/npm ]
RUN adduser -D rafiki
WORKDIR /home/rafiki

Expand Down
Loading
Loading