From 4b3c808169820529ee0b526e91a972192d726b3c Mon Sep 17 00:00:00 2001 From: Christopher Kolstad Date: Tue, 8 Apr 2025 10:56:50 +0200 Subject: [PATCH] Task/bump docker base image (#9716) As reported in #9710 . This PR updates to 20.19.0-alpine3.21 which according to docker's own scan now longer is affected by the CVE --- .github/workflows/docker_publish.yaml | 2 +- Dockerfile | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/docker_publish.yaml b/.github/workflows/docker_publish.yaml index e928c3472b..b43a1f8c8f 100644 --- a/.github/workflows/docker_publish.yaml +++ b/.github/workflows/docker_publish.yaml @@ -28,7 +28,7 @@ jobs: runs-on: ubuntu-latest strategy: matrix: - version: [20.18.1-alpine] + version: [20.19.0-alpine3.21] steps: - name: Checkout tag v${{ inputs.version }} if: ${{ inputs.version != '' }} diff --git a/Dockerfile b/Dockerfile index cd9a662842..4e39dc4e7a 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,4 +1,4 @@ -ARG NODE_VERSION=20.18.3-alpine +ARG NODE_VERSION=20.19.0-alpine3.21 FROM node:$NODE_VERSION AS builder