Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/docker.yml
Original file line number Diff line number Diff line change
Expand Up @@ -117,7 +117,7 @@ jobs:
severity: 'CRITICAL,HIGH'
ignore-unfixed: true
exit-code: '0'
skip-dirs: 'usr/lib/node_modules/npm,usr/local/go'
skip-dirs: 'usr/local/go'

- name: Upload Trivy scan results to GitHub Security tab
uses: github/codeql-action/upload-sarif@v4.32.2
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/trivy-scan.yml
Original file line number Diff line number Diff line change
Expand Up @@ -56,9 +56,9 @@ jobs:
# The scan itself never fails the job; the explicit check below does,
# so the SARIF still uploads on a finding rather than being skipped.
exit-code: '0'
# Vendored toolchains in the agent image, not shipped attack surface.
# A no-op for images that do not contain them.
skip-dirs: 'usr/lib/node_modules/npm,usr/local/go'
# Vendored toolchain in the agent image, not shipped attack surface.
# A no-op for images that do not contain it.
skip-dirs: 'usr/local/go'

- name: Upload Trivy scan results to GitHub Security tab
uses: github/codeql-action/upload-sarif@v4.32.2
Expand Down
17 changes: 12 additions & 5 deletions docker/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,7 @@ WORKDIR /agent
# force `apt-get update && upgrade` to re-fetch from Debian's archive. Use this
# when the scheduled Trivy scan flags OS-package CVEs whose fixes are already
# in the archive — the cache is just serving a stale layer. Leaves the rest of
# the build (Go, npm, snyk-broker clone) hitting cache as normal.
# the build (Go, Node + snyk-broker install) hitting cache as normal.
ARG APT_CACHE_BUST=2026-09-30
# NOTE: build-essential is deliberately NOT installed here. It pulls in a full
# C/C++ toolchain whose libc6-dev dependency drags in linux-libc-dev (the Linux
Expand All @@ -51,17 +51,24 @@ RUN echo "apt cache bust: $APT_CACHE_BUST" \
ENV NODE_VERSION=20

ARG SNYK_BROKER_VERSION=v1.0.21-axon
RUN wget -q -O - https://deb.nodesource.com/setup_${NODE_VERSION}.x | bash - && apt-get install -y nodejs
RUN npm install --global npm@11.18.0 typescript@4.9.3
RUN git clone https://github.com/cortexapps/snyk-broker.git /tmp/snyk-broker && \
# npm is only a build tool here: nothing in the agent or the scaffolds runs npm
# or npx at runtime, the agent just execs the installed `snyk-broker` bin. So
# npm (and npx, which lives inside it) is deleted once the broker is installed.
# It has to happen in this same RUN: the nodejs package itself installs npm
# under /usr/lib/node_modules/npm, and removing it in a later layer would leave
# it in the image's lower layers, where customers' scanners still find it.
RUN wget -q -O - https://deb.nodesource.com/setup_${NODE_VERSION}.x | bash - && apt-get install -y nodejs && \
npm install --global npm@11.18.0 typescript@4.9.3 && \
git clone https://github.com/cortexapps/snyk-broker.git /tmp/snyk-broker && \
cd /tmp/snyk-broker && \
git checkout ${SNYK_BROKER_VERSION} && \
npm install && \
cp -r . /usr/local/snyk-broker && \
cd /usr/local/snyk-broker && \
npm install --global . && \
npm prune --omit=dev && \
rm -rf /tmp/snyk-broker
rm -rf /tmp/snyk-broker && \
rm -rf /usr/lib/node_modules/npm /usr/bin/npm /usr/bin/npx /root/.npm

# Add npm global bin to PATH
ENV PATH="/usr/local/lib/node_modules/.bin:${PATH}"
Expand Down
Loading