Skip to content

build: Fix Semgrep installation in Alpine images - #114

Merged
julio-rocketchat merged 2 commits into
developfrom
build/semgrep-alpine-dependencies
Sep 26, 2026
Merged

julio-rocketchat merged 2 commits into
developfrom
build/semgrep-alpine-dependencies

Conversation

@julio-rocketchat

@julio-rocketchat julio-rocketchat commented Sep 26, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Install gcc, musl-dev, and python3-dev temporarily while building pinned Semgrep dependencies, then remove them.
  • Copy scripts into the build stage because npm run build compiles tsconfig.scripts.json as well as application code.

Verification

  • Built the complete Linux ARM64 image from a Git-only archive, excluding local environment files and untracked content.
  • Network-disabled runtime smoke test passed: Semgrep 1.154.0, Trufflehog 3.93.7, OSV-Scanner 2.3.8.
  • Verified non-root runtime, gcc absent, and no /app/.env.
  • Node 22: build, typecheck, lint, configuration validation, and all 619 tests passed.
  • Reviewed build-stage boundaries, runtime permissions, and credential exposure. Gitleaks staged-patch scan passed.

CI now uses the committed lockfile via npm ci; all GitHub checks pass.

@julio-rocketchat

Copy link
Copy Markdown
Member Author

CI follow-up: the shared install failure was reproduced in an isolated Node 22 container. With maintainer approval, this branch now uses npm ci instead of deleting the lockfile and resolving a fresh dependency graph. This is the only CI change; GitHub checks are rerunning.

@julio-rocketchat
julio-rocketchat merged commit c91fa3f into develop Sep 26, 2026
3 checks passed
@github-actions github-actions Bot mentioned this pull request Sep 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant