Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

nodejs/npm update for nodejs-20-minimal #429

Open
slowtick opened this issue Apr 27, 2024 · 5 comments
Open

nodejs/npm update for nodejs-20-minimal #429

slowtick opened this issue Apr 27, 2024 · 5 comments

Comments

@slowtick
Copy link

Container platform

OCP 4

Version

ubi9/nodejs-20-minimal:1-37.1712566503

OS version of the container image

RHEL 9

Bugzilla, Jira

No response

Description

npm packaged in this image depends on vulnerable ip package - CVE-2023-42282 and apps built with this base image gets flagged out in scanners with critical vulnerability. Though the vulnerable code is never called by npm, we could not convince audit.

npm v10.5.0 / nodejs v20.12.0 includes fixes for this vulnerability.

Are there plans to upgrade node package to 20.12.x? Or would you recommend us install node 20.12.x on ubi9/minimal base image?

Reproducer

  1. Build a nodejs app with ubi9/nodejs-20-minimal:1-37.1712566503
  2. Scan the built image with twistlock/prisma
  3. Reports critical vulnerability in the built image
@zmiklank
Copy link
Contributor

Hello @slowtick.
IIUC, it is as you said - the ubi9/nodejs-20-minimal:1-37.1712566503 container image is not vulnerable to CVE-2023-42282, because it does not use the vulnerable part of the code.
However, there is a plan to rebase node to 20.12.x, however it may take a while until the change is propagated to the container image.
Please note that I am not a npm maintainer, so my information can be imprecise.
Maybe @khardix could know more.

@khardix
Copy link
Contributor

khardix commented Apr 29, 2024

Rebase to 20.12.x is in the works. I would advise waiting for that (shouldn't be long; can't be more specific).

@slowtick
Copy link
Author

Glad to hear 20.12.x would be coming, official package would be best for us. Will wait for it / watch for updates here.

@wanghwh
Copy link

wanghwh commented May 20, 2024

@khardix , will we update ubi8/nodejs-20? it's reported with 8 vulnerabilities.

@khardix
Copy link
Contributor

khardix commented May 20, 2024

Update to all containers should be on their way.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants