Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
23 changes: 0 additions & 23 deletions .github/workflows/missing-checksum.yml

This file was deleted.

40 changes: 22 additions & 18 deletions Dockerfile-alpine.template
Original file line number Diff line number Diff line change
Expand Up @@ -5,43 +5,48 @@ ENV NODE_VERSION=0.0.0
RUN addgroup -g 1000 node \
&& adduser -u 1000 -G node -s /bin/sh -D node \
&& apk add --no-cache \
libatomic \
libstdc++ \
Comment thread
nschonni marked this conversation as resolved.
&& apk add --no-cache --virtual .build-deps \
gnupg \
curl \
&& ARCH= OPENSSL_ARCH='linux*' && alpineArch="$(apk --print-arch)" \
&& case "${alpineArch##*-}" in \
"${ALPINE_ARCH[@]}"
esac \
&& if [ -n "${CHECKSUM}" ]; then \
set -eu; \
curl -fsSLO --compressed "https://unofficial-builds.nodejs.org/download/release/v$NODE_VERSION/node-v$NODE_VERSION-linux-$ARCH-musl.tar.xz"; \
echo "$CHECKSUM node-v$NODE_VERSION-linux-$ARCH-musl.tar.xz" | sha256sum -c - \
&& tar -xJf "node-v$NODE_VERSION-linux-$ARCH-musl.tar.xz" -C /usr/local --strip-components=1 --no-same-owner \
&& ln -s /usr/local/bin/node /usr/local/bin/nodejs; \
# use pre-existing gpg directory, see https://github.com/nodejs/docker-node/pull/1895#issuecomment-1550389150
&& export GNUPGHOME="$(mktemp -d)" \
# gpg keys listed at https://github.com/nodejs/node#release-keys
&& set -ex \
&& for key in \
"${NODE_KEYS[@]}"
; do \
{ gpg --batch --keyserver hkps://keys.openpgp.org --recv-keys "$key" && gpg --batch --fingerprint "$key"; } || \
{ gpg --batch --keyserver keyserver.ubuntu.com --recv-keys "$key" && gpg --batch --fingerprint "$key"; } ; \
done \
&& if [ "$ARCH" = "x64" ]; then \
curl -fsSLO --compressed "https://nodejs.org/dist/v$NODE_VERSION/node-v$NODE_VERSION-linux-$ARCH-musl.tar.xz" \
&& curl -fsSLO --compressed "https://nodejs.org/dist/v$NODE_VERSION/SHASUMS256.txt.asc" \
&& gpg --batch --decrypt --output SHASUMS256.txt SHASUMS256.txt.asc \
&& gpgconf --kill all \
&& rm -rf "$GNUPGHOME" \
&& grep " node-v$NODE_VERSION-linux-$ARCH-musl.tar.xz\$" SHASUMS256.txt | sha256sum -c - \
&& tar -xJf "node-v$NODE_VERSION-linux-$ARCH-musl.tar.xz" -C /usr/local --strip-components=1 --no-same-owner \
&& rm "node-v$NODE_VERSION-linux-$ARCH-musl.tar.xz" SHASUMS256.txt.asc SHASUMS256.txt \
&& ln -s /usr/local/bin/node /usr/local/bin/nodejs; \
else \
echo "Building from source" \
# backup build
&& apk add --no-cache --virtual .build-deps-full \
binutils-gold \
g++ \
gcc \
gnupg \
libgcc \
linux-headers \
make \
python3 \
py-setuptools \
rust \
cargo \
# use pre-existing gpg directory, see https://github.com/nodejs/docker-node/pull/1895#issuecomment-1550389150
&& export GNUPGHOME="$(mktemp -d)" \
# gpg keys listed at https://github.com/nodejs/node#release-keys
&& for key in \
"${NODE_KEYS[@]}"
; do \
{ gpg --batch --keyserver hkps://keys.openpgp.org --recv-keys "$key" && gpg --batch --fingerprint "$key"; } || \
{ gpg --batch --keyserver keyserver.ubuntu.com --recv-keys "$key" && gpg --batch --fingerprint "$key"; } ; \
done \
&& curl -fsSLO --compressed "https://nodejs.org/dist/v$NODE_VERSION/node-v$NODE_VERSION.tar.xz" \
&& curl -fsSLO --compressed "https://nodejs.org/dist/v$NODE_VERSION/SHASUMS256.txt.asc" \
&& gpg --batch --decrypt --output SHASUMS256.txt SHASUMS256.txt.asc \
Expand All @@ -58,7 +63,6 @@ RUN addgroup -g 1000 node \
&& rm -Rf "node-v$NODE_VERSION" \
&& rm "node-v$NODE_VERSION.tar.xz" SHASUMS256.txt.asc SHASUMS256.txt; \
fi \
&& rm -f "node-v$NODE_VERSION-linux-$ARCH-musl.tar.xz" \
# Remove unused OpenSSL headers to save ~34MB. See this NodeJS issue: https://github.com/nodejs/node/issues/46451
&& find /usr/local/include/node/openssl/archs -mindepth 1 -maxdepth 1 ! -name "$OPENSSL_ARCH" -exec rm -rf {} \; \
&& apk del .build-deps \
Expand Down
58 changes: 22 additions & 36 deletions update.sh
Original file line number Diff line number Diff line change
Expand Up @@ -25,11 +25,9 @@ function usage() {
EOF
}

SKIP_ALPINE=false
while getopts "sh" opt; do
case "${opt}" in
s)
SKIP_ALPINE=true
shift
;;
h)
Expand Down Expand Up @@ -145,41 +143,29 @@ function update_node_version() {

if is_alpine "${variant}"; then
alpine_version="${variant#*alpine}"
checksum=$(
curl -sSL --compressed "https://unofficial-builds.nodejs.org/download/release/v${nodeVersion}/SHASUMS256.txt" | grep "node-v${nodeVersion}-linux-x64-musl.tar.xz" | cut -d' ' -f1
)
if [ -z "$checksum" ]; then
rm -f "${dockerfile}-tmp"
if [ "${SKIP_ALPINE}" = true ]; then
echo "${nodeVersion} is missing the musl build for ${variant}, but skipping for security release!"
else
fatal "Failed to fetch checksum for musl build version ${nodeVersion}"
fi
else
sed -Ei -e "s/(alpine:)0.0/\\1${alpine_version}/" "${dockerfile}-tmp"

alpine_arch=''
local -a arches
arches=$(jq -r ".\"${version}\".variants.\"alpine${alpine_version}\" | @sh" "versions.json")
if [[ "${arches[0]}" == *"amd64"* ]]; then
alpine_arch+='x86_64) ARCH='"'"'x64'"'"' CHECKSUM="'${checksum}'" OPENSSL_ARCH=linux-x86_64;; \\\n '
fi
if [[ "${arches[0]}" == *"arm64v8"* ]]; then
alpine_arch+='aarch64) OPENSSL_ARCH=linux-aarch64;; \\\n '
fi
if [[ "${arches[0]}" == *"arm32"* ]]; then
alpine_arch+='arm*) OPENSSL_ARCH=linux-armv4;; \\\n '
fi
if [[ "${arches[0]}" == *"ppc64le"* ]]; then
alpine_arch+='ppc64le) OPENSSL_ARCH=linux-ppc64le;; \\\n '
fi
if [[ "${arches[0]}" == *"s390x"* ]]; then
alpine_arch+='s390x) OPENSSL_ARCH=linux-s390x;; \\\n '
fi
# shellcheck disable=SC1003
alpine_arch+='*) echo "unsupported architecture"; exit 1 ;; \\'
sed -Ei -e "s/\"\\$\{ALPINE_ARCH\[@\]\}\"/${alpine_arch}/" "${dockerfile}-tmp"
sed -Ei -e "s/(alpine:)0.0/\\1${alpine_version}/" "${dockerfile}-tmp"

alpine_arch=''
local -a arches
arches=$(jq -r ".\"${version}\".variants.\"alpine${alpine_version}\" | @sh" "versions.json")
if [[ "${arches[0]}" == *"amd64"* ]]; then
alpine_arch+='x86_64) ARCH='"'"'x64'"'"' OPENSSL_ARCH=linux-x86_64;; \\\n '
fi
if [[ "${arches[0]}" == *"arm64v8"* ]]; then
alpine_arch+='aarch64) OPENSSL_ARCH=linux-aarch64;; \\\n '
fi
if [[ "${arches[0]}" == *"arm32"* ]]; then
alpine_arch+='arm*) OPENSSL_ARCH=linux-armv4;; \\\n '
fi
if [[ "${arches[0]}" == *"ppc64le"* ]]; then
alpine_arch+='ppc64le) OPENSSL_ARCH=linux-ppc64le;; \\\n '
fi
if [[ "${arches[0]}" == *"s390x"* ]]; then
alpine_arch+='s390x) OPENSSL_ARCH=linux-s390x;; \\\n '
fi
# shellcheck disable=SC1003
alpine_arch+='*) echo "unsupported architecture"; exit 1 ;; \\'
sed -Ei -e "s/\"\\$\{ALPINE_ARCH\[@\]\}\"/${alpine_arch}/" "${dockerfile}-tmp"
elif is_debian "${variant}"; then
sed -Ei -e "s/(buildpack-deps:)name/\\1${variant}/" "${dockerfile}-tmp"
deb_arch=''
Expand Down
Loading