Skip to content

Update node version to address critical CVEs#2633

Open
nicholas-lockhart wants to merge 2 commits intoAzure:mainfrom
nicholas-lockhart:base-node
Open

Update node version to address critical CVEs#2633
nicholas-lockhart wants to merge 2 commits intoAzure:mainfrom
nicholas-lockhart:base-node

Conversation

@nicholas-lockhart
Copy link
Contributor

Old image trivy scan:
Total: 26 (UNKNOWN: 0, LOW: 3, MEDIUM: 17, HIGH: 4, CRITICAL: 2)

New image trivy scan:
Total: 2 (UNKNOWN: 0, LOW: 0, MEDIUM: 1, HIGH: 0, CRITICAL: 1)
Zlib is the current critical here and does not have a fix since it was recently discovered.

Tests continue to pass without issue

Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the container base image used to build and run Azurite in order to reduce critical/high CVEs reported by image scanning.

Changes:

  • Bump the Node Alpine base image from node:22-alpine3.21 to node:22-alpine3.23 for both build and runtime stages.
  • Add an “Upcoming Release” changelog entry noting the security-motivated base image update.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 3 comments.

File Description
Dockerfile Updates the builder and production FROM images to use Alpine 3.23 variants.
ChangeLog.md Adds a release-note bullet for the security-driven image update.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants