Skip to content

bug: upgrade Dockerfile base image to node:18.20.5-alpine3.19 (CVE-2024-5171) - #262

Open
Shubhrakanti wants to merge 1 commit into
mainfrom
devin/1788299434-node-alpine-base-image
Open

Shubhrakanti wants to merge 1 commit into
mainfrom
devin/1788299434-node-alpine-base-image

Conversation

@Shubhrakanti

Copy link
Copy Markdown

Summary

Remediates Snyk Container finding SNYK-DEBIAN11-AOM-7197980 (CVE-2024-5171, CWE-190, CVSS 9.8): the node:18.13.0 Debian 11 base image ships imagemagick -> libheif1 -> libaom0@1.0.0.errata1-3, which is vulnerable to integer overflow.

FROM node:18.13.0 -> FROM node:18.20.5-alpine3.19 (Snyk's recommended image). Alpine does not ship ImageMagick/libheif/libaom at all, so the vulnerable package is removed rather than merely patched. The app has no native modules and does not shell out to ImageMagick, so nothing depends on it.

mkdir /usr/src/goof -> mkdir -p /usr/src/goof because the Alpine image has no /usr/src directory.

Verified locally: docker build succeeds, apk list --installed in the image shows no aom/imagemagick/libheif, and npm start boots the Express server on Node v18.20.5 (DB connection errors are expected without the Mongo/MySQL containers).

Note: the finding was filed against COG-GTM/educational-platform, but that repo contains no Dockerfile; the traceability metadata points to COG-GTM/nodejs-goof, which owns the affected Dockerfile:2.

Devin-Org: engineering

Link to Devin session: https://app.devin.ai/sessions/5b588cb63477439fac67d30aeeced066
Open in Devin Desktop: https://app.devin.ai/desktop/session/5b588cb63477439fac67d30aeeced066?variant=devin
Requested by: @Shubhrakanti

…24-5171)

Co-Authored-By: Shubhra Ganguly <shubhrakanti@berkeley.edu>
@devin-ai-integration

Copy link
Copy Markdown

🤖 Devin AI Engineer

I'll be helping with this pull request! Here's what you should know:

✅ I will automatically:

  • Address comments on this PR. Add '(aside)' to your comment to have me ignore it.
  • Look at CI failures and help fix them

Note: I can only respond to comments from users who have write access to this repository.

⚙️ Control Options:

  • Disable automatic comment, CI, and merge conflict monitoring

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant