From fec8dd3c5dd9abc2c298bce1acb445f4fcbe002e Mon Sep 17 00:00:00 2001 From: simoleo89 Date: Fri, 11 Sep 2026 00:11:18 +0200 Subject: [PATCH] fix(docker): enforce Node version alignment across build stages --- Dockerfile | 4 ++-- scripts/check-node-toolchain.mjs | 17 +++++++++++++++++ 2 files changed, 19 insertions(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index c50c4103..06abe42c 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,6 @@ # syntax=docker/dockerfile:1 # Pin the runtime to the supported engine; update both stages deliberately. -FROM node:26.8.1-alpine AS migrations +FROM node:26.8.2-alpine AS migrations WORKDIR /app ENV NEXT_TELEMETRY_DISABLED=1 # Keep the bootstrap aligned with package.json packageManager. @@ -39,7 +39,7 @@ RUN --mount=type=cache,target=/app/.next/cache \ AUTH_SECRET="build-fixture-not-for-runtime-use-000000000000" \ pnpm run build -FROM node:26.8.1-alpine AS runner +FROM node:26.8.2-alpine AS runner ARG NEXT_DEPLOYMENT_ID="unknown" LABEL org.opencontainers.image.revision="$NEXT_DEPLOYMENT_ID" WORKDIR /app diff --git a/scripts/check-node-toolchain.mjs b/scripts/check-node-toolchain.mjs index dc5a5144..d6df964b 100644 --- a/scripts/check-node-toolchain.mjs +++ b/scripts/check-node-toolchain.mjs @@ -28,6 +28,23 @@ assert.equal( "@types/node must match the pinned Node.js major", ); +const nodeImages = [ + ...readProjectFile("Dockerfile").matchAll( + /^FROM\s+(?:--platform=\S+\s+)?node:([^\s]+)\s*/gim, + ), +].map((match) => match[1]); +assert.ok( + nodeImages.length > 0, + "Dockerfile must declare a pinned Node.js base image", +); +for (const image of nodeImages) { + assert.equal( + image, + `${pinnedVersion}-alpine`, + "every Docker Node.js stage must match .nvmrc", + ); +} + if (!process.argv.includes("--static")) { assert.equal( process.versions.node,