π‘οΈ DecaTone v1.2.2 Security Hardening Release
This patch release completely eliminates all remaining container base and bundled package vulnerabilities:
π Zero-Vulnerability Runtime Container
- Upgraded Base to Node 22 Alpine (Alpine 3.24): Updates Busybox to
1.37.0-r31(resolves CVE-2025-60876), OpenSSL (libcrypto3/libssl3) to3.5.8-r0, and musl to1.2.6-r2. - Stripped Bundled NPM CLI in Runner Stage: Removed
/usr/local/lib/node_modules/npmand/usr/local/bin/npmfrom the runtime container image. This eliminates all vulnerabilities originating from internal npm dependencies:tar@6.2.1(CVE-2026-59873, CVE-2026-23950, CVE-2026-59874, CVE-2026-23745, CVE-2026-24842, CVE-2026-29786, CVE-2026-31802, CVE-2026-73566, CVE-2026-26960, CVE-2026-53655, CVE-2026-59875, CVE-2026-59871)minimatch@9.0.5(CVE-2026-26996, CVE-2026-27904, CVE-2026-27903)brace-expansion@2.0.1(CVE-2026-13149, CVE-2026-14257, CVE-2026-69152, CVE-2026-33750, CVE-2025-5889)ip-address@9.0.5(CVE-2026-69192, CVE-2026-42338)cross-spawn@7.0.3(CVE-2024-21538)pacote@18.0.6(CVE-2026-9496)glob@10.4.2(CVE-2025-64756)sigstore@2.3.1&@sigstore/core@1.1.0(CVE-2026-48815, CVE-2026-48758)diff@5.2.0(CVE-2026-24001)
π³ Docker Hub Standardized Images
Pushed to Docker Hub:
tylerhats/decatone:1.2.2tylerhats/decatone:latest