Comments (5)
That needs to be fixed in ip, then adopted in npm, then npm must be updated in node. At that point the fix will trickle down to the docker image
from docker-node.
But it looks like the IP project is not maintained anymore. Last commit was 2 years ago. You need to remove/replace the package.
from docker-node.
npm is a separate product and not maintained by Node.js, much less the Node.js Docker folks. You need to raise this with npm Inc.
from docker-node.
Hi @SimenB @meyfa. I am still facing this issue and would appreciate your help and guidance.
From my analysis, the IP package used by the node image is version 2.0.0. Fix suggestions show that this vulnerability has been fixed for versions 1.1.9 and 2.0.1.
The base image I am using: node:20.11.0-bookworm-slim
If the fixes are rolled out, could you guide me to the best image or advice on how to patch this?
I tried manually updating the IP package in the Dockerfile, but it does not work and all of the variations of the node base image I checked (including 20.11.1) still show this vulnerability.
from docker-node.
https://github.com/nodejs/docker-node/blob/main/SECURITY.md
from docker-node.
Related Issues (20)
- not able to run Nodejs HOT 2
- Latest docker build breaks node-gyp in node-18 HOT 16
- 18-alpine3.19 throws error while installing python HOT 4
- Add note to DockerHub indicating Alpine images rely on experimental and unofficial-builds HOT 4
- Nodejs container version node:16.14.2-slim suddenly failed to start suggestion fix "chmod 1000:0 /root/.npm" HOT 2
- node:20.11.0 The RUN command not work while running the Dockerfile. HOT 4
- All images are ubuntu jammy
- Node 20.10 to 20.11 regression using stream readables, discovered using google cloud sdk HOT 1
- node 21.6.1 HOT 1
- Heads up on security release pland for 6 Feb 2024 HOT 3
- docker stop not triggering shutdown signal [v20] HOT 1
- Minor change in unofficial-builds workflow HOT 6
- 20.11.1-bullseye-slim: no matching manifest for linux/arm64/v8 in the manifest list entries
- 20.11.1-bullseye-slim: no matching manifest for linux/arm64/v8 in the manifest list entries HOT 1
- node:lts-alpine apk not found HOT 2
- Major bug was fixed in [email protected] concerning nodejs images. HOT 3
- node:lts-slim has vulnerability - CVE-2023-42282 - due to not updated npm ip package HOT 2
- `libc6-compat` not on alpine anymore? HOT 3
- Major bug was fixed in [email protected] concerning nodejs images. Node has new version with the fixed NPM. HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from docker-node.