DecaTone v1.2.1
🛡️ DecaTone v1.2.1 Security & Hardening Release
This maintenance and security release resolves all known high and critical CVE vulnerabilities in the container runtime environment and Node.js dependencies:
🔒 Container & Runtime Hardening
- Eliminated Container OS CVEs: Stripped unused utilities (
curl,git,tar,make,g++,binutils,python3) from the runtime runner image. - Eliminated Go Stdlib / Sigstore / Pacote CVEs: Removed global npm development package installations in the runtime stage.
- Alpine Base Upgrades: Automated
apk upgrade --no-cachein both builder and runner stages to pull the latest security patches for OpenSSL (libcrypto3,libssl3), Busybox, and system libraries.
📦 Dependency Upgrades
- Upgraded
tarto^7.5.22(resolves CVE-2026-59873, CVE-2026-23950, CVE-2026-59874, CVE-2026-23745, CVE-2026-24842, CVE-2026-29786, CVE-2026-31802, CVE-2026-73566, CVE-2026-26960, CVE-2026-53655, CVE-2026-59875, CVE-2026-59871). - Upgraded
multerto^2.3.0(resolves CVE-2025-48997, CVE-2026-3520, CVE-2026-3304, CVE-2026-2359, CVE-2025-7338, CVE-2025-47944, CVE-2026-5079, CVE-2025-47935). - Upgraded
nodemailerto^9.0.6(resolves CVE-2025-14874, GHSA-p6gq-j5cr-w38f, GHSA-r7g4-qg5f-qqm2, CVE-2025-13033, GHSA-wqvq-jvpq-h66f, GHSA-268h-hp4c-crq3, GHSA-vvjj-xcjg-gr5g, GHSA-c7w3-x93f-qmm8). - Upgraded
sqlite3to^6.0.1(resolves@tootallnate/once,node-gyp, andcacacheissues). - Upgraded
react-router-domto^7.18.3andviteto^6.2.0(resolves CVE-2026-53666, CVE-2026-53669).
🐳 Docker Hub Standardized Images
Pushed to Docker Hub:
tylerhats/decatone:1.2.1tylerhats/decatone:latest