Repository navigation
Remove npm from the agent runtime image and stop skipping it in Trivy - #154
Merged
Merged
Conversation
…rivy npm was installed in its own layer and never removed, so it shipped in the image, and the Trivy skip-dirs entry for usr/lib/node_modules/npm hid exactly what customers' scanners report. Nothing runs npm or npx at runtime (the agent execs the installed snyk-broker bin), so fold the Node install, npm upgrade and snyk-broker install into one RUN and delete npm/npx at its end. It must be the same layer, because the nodejs package itself installs npm. Also drop usr/local/go from skip-dirs: the Go toolchain ships for scaffold apps, so its stdlib CVEs are real findings customers see. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CynXL76D8TXF925natAPtA
ashiramin
previously approved these changes
Oct 1, 2026
Keep this PR scoped to npm; Go scanning is left as it was. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CynXL76D8TXF925natAPtA
shawnburke
enabled auto-merge (squash)
October 1, 2026 23:40
ashiramin
approved these changes
Oct 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
RUNlayer, and that layer ends withrm -rf /usr/lib/node_modules/npm /usr/bin/npm /usr/bin/npx /root/.npm. The removal has to happen in that same layer because thenodejspackage installs npm itself. Deleting it in a later layer would leave it in the lower layers, where scanners still find it. Nothing calls npm or npx at runtime: the agent runs the installedsnyk-brokerbin, and the scaffolds and entrypoints never use npm.usr/lib/node_modules/npmskip-dirs entry indocker.yml(PR scan) andtrivy-scan.yml(scheduled/release scan). It was hiding exactly what customers' scanners report. Theusr/local/goskip is unchanged.Notes for reviewers
typescriptinstall is left in place. It isn't part of this change.🤖 Generated with Claude Code
https://claude.ai/code/session_01CynXL76D8TXF925natAPtA