Skip to content

Commit 1634226

Browse files
authored
fix(docker): remediate container scan vulnerabilities across CI, cluster, and sandbox images (#144)
1 parent 6ea176f commit 1634226

4 files changed

Lines changed: 11 additions & 8 deletions

File tree

‎deploy/docker/Dockerfile.ci‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -8,8 +8,8 @@
88

99
FROM ubuntu:24.04
1010

11-
ARG DOCKER_VERSION=27.5.1
12-
ARG BUILDX_VERSION=v0.21.1
11+
ARG DOCKER_VERSION=29.3.0
12+
ARG BUILDX_VERSION=v0.32.1
1313
ARG TARGETARCH
1414

1515
ENV DEBIAN_FRONTEND=noninteractive

‎deploy/docker/Dockerfile.cluster‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@
1515
# The helm charts are built by the docker:build:cluster mise task
1616
# and placed in deploy/docker/.build/ before this Dockerfile is built.
1717

18-
ARG K3S_VERSION=v1.29.8-k3s1
18+
ARG K3S_VERSION=v1.34.5-k3s1
1919
FROM rancher/k3s:${K3S_VERSION}
2020

2121
# Create directories for manifests, charts, and configuration

‎deploy/docker/sandbox/Dockerfile.base‎

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -107,7 +107,7 @@ RUN groupadd -r supervisor && useradd -r -g supervisor -s /usr/sbin/nologin supe
107107
# Stage 3: Python dependencies builder
108108
FROM base AS builder
109109

110-
COPY --from=ghcr.io/astral-sh/uv:latest /uv /usr/local/bin/uv
110+
COPY --from=ghcr.io/astral-sh/uv:0.10.8 /uv /usr/local/bin/uv
111111

112112
# Copy project files for dependency resolution
113113
COPY pyproject.toml uv.lock ./
@@ -128,7 +128,7 @@ FROM base AS coding-agents
128128
# Include a minimal native toolchain so npm can compile optional native
129129
# dependencies on platforms where prebuilt artifacts are unavailable.
130130
RUN curl -fsSL https://deb.nodesource.com/setup_22.x | bash - && \
131-
apt-get install -y --no-install-recommends build-essential git nodejs python3 vim-tiny nano && \
131+
apt-get install -y --no-install-recommends build-essential git nodejs python3 nano && \
132132
rm -rf /var/lib/apt/lists/*
133133

134134
# Install GitHub CLI (gh) from the official apt repository
@@ -144,8 +144,11 @@ RUN curl -fsSL https://claude.ai/install.sh | bash \
144144
&& cp /root/.local/bin/claude /usr/local/bin/claude \
145145
&& chmod 755 /usr/local/bin/claude
146146

147-
# Install OpenCode CLI and Codex CLI (OpenAI)
148-
RUN npm install -g opencode-ai @openai/codex openclaw
147+
# Install OpenCode CLI, Codex CLI (OpenAI), and OpenClaw with pinned versions
148+
# for reproducible builds. Force-upgrade tar afterward to resolve transitive
149+
# dependency vulnerabilities (GHSA-r6q2-hw4h-h46w, GHSA-qffp-2rhf-9h96, etc.)
150+
RUN npm install -g opencode-ai@1.2.18 @openai/codex@0.111.0 openclaw@2026.3.2 && \
151+
npm install -g tar@7.5.10
149152

150153
# Install ai-pim-utils (NVIDIA PIM CLI tools: outlook, calendar, transcripts, etc.)
151154
# The install script auto-detects Debian and installs via .deb package to /usr/bin.

‎mise.toml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -38,7 +38,7 @@ SCCACHE_DIR = "{{config_root}}/.cache/sccache"
3838
NAV_PYPI_REPOSITORY_URL = "https://urm.nvidia.com/artifactory/api/pypi/nv-shared-pypi-local"
3939

4040
# Shared build constants (overridable via environment)
41-
K3S_VERSION = "{{env.K3S_VERSION | default(value='v1.29.8-k3s1')}}"
41+
K3S_VERSION = "{{env.K3S_VERSION | default(value='v1.34.5-k3s1')}}"
4242
DOCKER_BUILDKIT = "1"
4343

4444
[vars]

0 commit comments

Comments
 (0)