#1018 builds the linux-x64-musl binary of @cipherstash/auth inside node:22-alpine, pinned by image digest. cipherstash-bot found two ways the build can drift, in review of #1018.
Nothing updates the image digest
.github/dependabot.yml has no docker entry. Its github-actions entry reads uses: lines only, so it cannot see an image named inside a run: script. The digest stays at its 2 October 2026 value, and the build stops getting Alpine security fixes.
The Alpine packages are not pinned
The container runs apk add --no-cache build-base cmake perl linux-headers git curl rustup, which installs whatever versions Alpine serves that day. Two builds of the same commit can use different compilers. That matters here, because the build is published with provenance.
Fix
- Keep the digest current: for example, a small Dockerfile that
FROMs the pinned image, which Dependabot's docker ecosystem can update, or a scheduled job that opens a PR when the tag moves.
- Pin the
apk packages to exact versions, and update them on the same schedule as the digest.
#1018 builds the
linux-x64-muslbinary of@cipherstash/authinsidenode:22-alpine, pinned by image digest. cipherstash-bot found two ways the build can drift, in review of #1018.Nothing updates the image digest
.github/dependabot.ymlhas nodockerentry. Itsgithub-actionsentry readsuses:lines only, so it cannot see an image named inside arun:script. The digest stays at its 2 October 2026 value, and the build stops getting Alpine security fixes.The Alpine packages are not pinned
The container runs
apk add --no-cache build-base cmake perl linux-headers git curl rustup, which installs whatever versions Alpine serves that day. Two builds of the same commit can use different compilers. That matters here, because the build is published with provenance.Fix
FROMs the pinned image, which Dependabot'sdockerecosystem can update, or a scheduled job that opens a PR when the tag moves.apkpackages to exact versions, and update them on the same schedule as the digest.