-
Notifications
You must be signed in to change notification settings - Fork 117
fix(backend): Attempt at fixing critical deps #3960
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
bad77ef
f5ccf88
a22fb7f
2bed119
9a45958
25cf619
3f30814
aeccbfa
ada1ae5
1dc9895
75a5d9c
930c772
3f7a507
d44848a
23e7805
5ff6d2c
92a467b
219fcbd
935cb75
95d17f4
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
This file was deleted.
This file was deleted.
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -46,6 +46,15 @@ RUN pnpm --filter auth build | |
|
|
||
| FROM node:24-alpine3.23 AS runner | ||
|
|
||
| # update packages to patch known vulnerabilities that haven't made it into base image yet | ||
| RUN apk upgrade --no-cache | ||
|
Comment on lines
+49
to
+50
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
I think using distroless could have sidestepped this one as well. This is a pattern I've seen elsewhere. Such as https://github.com/jupyterhub/configurable-http-proxy/blob/14568e1b426c4818317da567a8f8f4d19a7c28a2/Dockerfile#L11-L13 Trivy's org updates images like this as well: https://github.com/aquasecurity/kube-hunter/blob/bc47f08e88ea2a5fb059bf3b8a8edb1aefb4c6cc/Dockerfile#L10 |
||
|
|
||
| # npm isn't used at runtime and no node:24 tag ships a patched one, so its bundled | ||
| # deps (tar, brace-expansion, ip-address, undici) fail every image scan. | ||
| RUN rm -rf /usr/local/lib/node_modules/npm /usr/local/bin/npm /usr/local/bin/npx \ | ||
| && ! command -v npm \ | ||
| && [ ! -e /usr/local/lib/node_modules/npm ] | ||
|
|
||
| RUN adduser -D rafiki | ||
|
|
||
| WORKDIR /home/rafiki | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
--severityis a list, not a floor. we werent scanning for critical vulnerabilities with Trivy