Skip to content

Keep the Alpine image for the musl auth build current, and pin its packages #1042

Description

@auxesis

#1018 builds the linux-x64-musl binary of @cipherstash/auth inside node:22-alpine, pinned by image digest. cipherstash-bot found two ways the build can drift, in review of #1018.

Nothing updates the image digest

.github/dependabot.yml has no docker entry. Its github-actions entry reads uses: lines only, so it cannot see an image named inside a run: script. The digest stays at its 2 October 2026 value, and the build stops getting Alpine security fixes.

The Alpine packages are not pinned

The container runs apk add --no-cache build-base cmake perl linux-headers git curl rustup, which installs whatever versions Alpine serves that day. Two builds of the same commit can use different compilers. That matters here, because the build is published with provenance.

Fix

  • Keep the digest current: for example, a small Dockerfile that FROMs the pinned image, which Dependabot's docker ecosystem can update, or a scheduled job that opens a PR when the tag moves.
  • Pin the apk packages to exact versions, and update them on the same schedule as the digest.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    SDKdependenciesPull requests that update a dependency filegithub-actionsPull request modifies GitHub Actions

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions