fix(docker): enforce Node version alignment across build stages
CI / check (push) Failing after 53s
CI / deploy (push) Skipped
CI / publish-container (push) Skipped

This commit is contained in:
Simo committed 2026-09-11 00:11:18 +02:00
1 parent bcefb0f8ff
commit fec8dd3c5d
2 files changed
+19 -2

No files matched your search

+2 -2
View File
@@ -1,6 +1,6 @@
# syntax=docker/dockerfile:1
# Pin the runtime to the supported engine; update both stages deliberately.
FROM node:26.8.1-alpine AS migrations
FROM node:26.8.2-alpine AS migrations
WORKDIR /app
ENV NEXT_TELEMETRY_DISABLED=1
# Keep the bootstrap aligned with package.json packageManager.
@@ -39,7 +39,7 @@ RUN --mount=type=cache,target=/app/.next/cache \
AUTH_SECRET="build-fixture-not-for-runtime-use-000000000000" \
pnpm run build
FROM node:26.8.1-alpine AS runner
FROM node:26.8.2-alpine AS runner
ARG NEXT_DEPLOYMENT_ID="unknown"
LABEL org.opencontainers.image.revision="$NEXT_DEPLOYMENT_ID"
WORKDIR /app
+17
View File
@@ -28,6 +28,23 @@ assert.equal(
"@types/node must match the pinned Node.js major",
);
const nodeImages = [
...readProjectFile("Dockerfile").matchAll(
/^FROM\s+(?:--platform=\S+\s+)?node:([^\s]+)\s*/gim,
),
].map((match) => match[1]);
assert.ok(
nodeImages.length > 0,
"Dockerfile must declare a pinned Node.js base image",
);
for (const image of nodeImages) {
assert.equal(
image,
`${pinnedVersion}-alpine`,
"every Docker Node.js stage must match .nvmrc",
);
}
if (!process.argv.includes("--static")) {
assert.equal(
process.versions.node,