@@ -107,7 +107,7 @@ RUN groupadd -r supervisor && useradd -r -g supervisor -s /usr/sbin/nologin supe
107107# Stage 3: Python dependencies builder
108108FROM base AS builder
109109
110- COPY --from=ghcr.io/astral-sh/uv:latest /uv /usr/local/bin/uv
110+ COPY --from=ghcr.io/astral-sh/uv:0.10.8 /uv /usr/local/bin/uv
111111
112112# Copy project files for dependency resolution
113113COPY pyproject.toml uv.lock ./
@@ -128,7 +128,7 @@ FROM base AS coding-agents
128128# Include a minimal native toolchain so npm can compile optional native
129129# dependencies on platforms where prebuilt artifacts are unavailable.
130130RUN curl -fsSL https://deb.nodesource.com/setup_22.x | bash - && \
131- apt-get install -y --no-install-recommends build-essential git nodejs python3 vim-tiny nano && \
131+ apt-get install -y --no-install-recommends build-essential git nodejs python3 nano && \
132132 rm -rf /var/lib/apt/lists/*
133133
134134# Install GitHub CLI (gh) from the official apt repository
@@ -144,8 +144,11 @@ RUN curl -fsSL https://claude.ai/install.sh | bash \
144144 && cp /root/.local/bin/claude /usr/local/bin/claude \
145145 && chmod 755 /usr/local/bin/claude
146146
147- # Install OpenCode CLI and Codex CLI (OpenAI)
148- RUN npm install -g opencode-ai @openai/codex openclaw
147+ # Install OpenCode CLI, Codex CLI (OpenAI), and OpenClaw with pinned versions
148+ # for reproducible builds. Force-upgrade tar afterward to resolve transitive
149+ # dependency vulnerabilities (GHSA-r6q2-hw4h-h46w, GHSA-qffp-2rhf-9h96, etc.)
150+ RUN npm install -g opencode-ai@1.2.18 @openai/codex@0.111.0 openclaw@2026.3.2 && \
151+ npm install -g tar@7.5.10
149152
150153# Install ai-pim-utils (NVIDIA PIM CLI tools: outlook, calendar, transcripts, etc.)
151154# The install script auto-detects Debian and installs via .deb package to /usr/bin.
0 commit comments