Skip to content

Pin base image to digest#35

Merged
lex57ukr merged 1 commit intomainfrom
19-pin-base-image-to-digest
Feb 15, 2026
Merged

Pin base image to digest#35
lex57ukr merged 1 commit intomainfrom
19-pin-base-image-to-digest

Conversation

@lex57ukr
Copy link
Contributor

Summary

The base image node:25-bookworm-slim was pinned to a major version only, meaning upstream patch releases could introduce vulnerabilities or subtle behavior changes without any change on our side. Pinning to a full digest locks all transitive dependencies (apt packages, system libraries) to a known-good state. Dependabot already monitors this directory and will propose digest bumps automatically.

Related Issues

Fixes #19

Changes

  • Pin FROM node:25-bookworm-slim to its current digest in the ci-tools Dockerfile

Lock node:25-bookworm-slim to a specific digest to prevent
uncontrolled changes from upstream patch releases. Dependabot
already watches this directory and will propose digest bumps.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@lex57ukr lex57ukr added security Security-related change docker Docker image changes labels Feb 15, 2026
@lex57ukr lex57ukr merged commit ad40330 into main Feb 15, 2026
1 check passed
@lex57ukr lex57ukr deleted the 19-pin-base-image-to-digest branch February 15, 2026 07:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

docker Docker image changes security Security-related change

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Pin base image to digest

1 participant