Skip to content

Remove npm from the agent runtime image and stop skipping it in Trivy - #154

Merged
shawnburke merged 2 commits into
mainfrom
claude/nice-heisenberg-9p8qgt
Oct 1, 2026
Merged

shawnburke merged 2 commits into
mainfrom
claude/nice-heisenberg-9p8qgt

Conversation

@shawnburke

@shawnburke shawnburke commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • npm no longer ships in the runtime image. The Node install, the npm upgrade and the snyk-broker install now run in a single RUN layer, and that layer ends with rm -rf /usr/lib/node_modules/npm /usr/bin/npm /usr/bin/npx /root/.npm. The removal has to happen in that same layer because the nodejs package installs npm itself. Deleting it in a later layer would leave it in the lower layers, where scanners still find it. Nothing calls npm or npx at runtime: the agent runs the installed snyk-broker bin, and the scaffolds and entrypoints never use npm.
  • Removed the usr/lib/node_modules/npm skip-dirs entry in docker.yml (PR scan) and trivy-scan.yml (scheduled/release scan). It was hiding exactly what customers' scanners report. The usr/local/go skip is unchanged.

Notes for reviewers

  • I couldn't build the image locally because the environment has no Docker. CI's image build and Trivy PR scan are the first real test.
  • The global typescript install is left in place. It isn't part of this change.

🤖 Generated with Claude Code

https://claude.ai/code/session_01CynXL76D8TXF925natAPtA

…rivy

npm was installed in its own layer and never removed, so it shipped in
the image, and the Trivy skip-dirs entry for usr/lib/node_modules/npm
hid exactly what customers' scanners report. Nothing runs npm or npx at
runtime (the agent execs the installed snyk-broker bin), so fold the
Node install, npm upgrade and snyk-broker install into one RUN and
delete npm/npx at its end. It must be the same layer, because the
nodejs package itself installs npm.

Also drop usr/local/go from skip-dirs: the Go toolchain ships for
scaffold apps, so its stdlib CVEs are real findings customers see.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CynXL76D8TXF925natAPtA
ashiramin
ashiramin previously approved these changes Oct 1, 2026
Keep this PR scoped to npm; Go scanning is left as it was.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CynXL76D8TXF925natAPtA
@shawnburke shawnburke changed the title Remove npm from the agent runtime image and stop skipping npm/Go in Trivy Remove npm from the agent runtime image and stop skipping it in Trivy Oct 1, 2026
@shawnburke
shawnburke requested a review from ashiramin October 1, 2026 23:40
@shawnburke
shawnburke enabled auto-merge (squash) October 1, 2026 23:40
@shawnburke
shawnburke merged commit 8aedb95 into main Oct 1, 2026
26 of 28 checks passed
@shawnburke
shawnburke deleted the claude/nice-heisenberg-9p8qgt branch October 1, 2026 23:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants