Skip to content

chore(deps): bump node from 22-alpine to 25-alpine - #239

Merged
dkijania merged 1 commit into
mainfrom
dependabot/docker/node-25-alpine
Sep 23, 2026
Merged

dkijania merged 1 commit into
mainfrom
dependabot/docker/node-25-alpine

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 23, 2026

Copy link
Copy Markdown
Contributor

Bumps node from 22-alpine to 25-alpine.

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file docker Pull requests that update docker code labels Sep 23, 2026
Bumps node from 22-alpine to 25-alpine.

---
updated-dependencies:
- dependency-name: node
  dependency-version: 25-alpine
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dkijania
dkijania force-pushed the dependabot/docker/node-25-alpine branch from 238925b to 665a801 Compare September 23, 2026 12:34
@dkijania
dkijania merged commit cecc4bf into main Sep 23, 2026
7 checks passed
@dkijania
dkijania deleted the dependabot/docker/node-25-alpine branch September 23, 2026 14:29
@dkijania

Copy link
Copy Markdown
Contributor

Flagging after the fact, for whoever reads this next: this bump moved the production image onto an end-of-life Node.

node:25-alpine@sha256:bdf2cca6… resolves to an image declaring NODE_VERSION=25.9.0, built 2026-04-15. Per nodejs/Release, v25 has lts: false and end: 2026-06-01 — an odd-numbered line that was never LTS and has received no patches since 2026-06-01.

Not a criticism of the merge: Dependabot offered it and nothing in the repo said no. That is the gap.

#235 fixes it — both stages move to node:24-alpine, Active LTS until 2028-04-30 — and adds a dependabot.yml rule ignoring Node semver-major bumps, so digest and patch refreshes stay automatic while a major move becomes a deliberate decision. Had that rule existed, this PR would not have been opened.

🤖 Generated with Claude Code

dkijania added a commit that referenced this pull request Oct 7, 2026
## Why

`ghcr.io/o1-labs/archive-node-api` ships **one architecture** now. Its
manifest index lists only:

```
linux amd64
unknown unknown   <- build provenance attestation, not an architecture
```

`docker/build-push-action` had no `platforms:`, so it built only for the
`ubuntu-latest` runner. On Apple Silicon, this causes emulation and a
platform-mismatch warning, or `no matching manifest for linux/arm64`
when emulation is off.

## What changed

### Workflow (`.github/workflows/build.yaml`)

- `platforms: linux/amd64,linux/arm64` on the build step.
- **Set up QEMU** registers the binfmt handlers, so that the amd64
runner can execute aarch64 build steps.
- The step runs a `--privileged` container. Thus it comes **before**
"Authenticate to Google Cloud", as the ORDERING RULE at the top of the
job requires.
- The binfmt image is pinned by digest:
`docker.io/tonistiigi/binfmt:qemu-v10.2.3@sha256:400a4873…`. The
action's default is the mutable `:latest` tag. Dependabot does not bump
a `with: image:` input, so a QEMU update is a manual change.
- `cache-image: false`. The action's cache entry is keyed by tag, not
digest, and adds ~32 MB per PR (#241).
- `Move cache` uses `if [ -d … ]; then mv …; fi`. A build that wrote no
new cache passes, and a real `mv` failure fails the step.

### `Dockerfile`: three stages, `node:24-alpine`

A single stage ran `npm ci` under QEMU for the arm64 leg (752 s against
112 s native) and shipped the dev tree in the runtime image. Now:

1. `deps` (target platform): `npm ci --omit=dev --ignore-scripts`.
Production dependencies only. None of them has an install script.
2. `build` (`--platform=$BUILDPLATFORM`): `npm ci --ignore-scripts` and
`tsc`. The compiled output does not depend on the architecture, so this
stage runs natively one time for all targets.
3. runtime: `node_modules` from `deps` (never from `build`, which has
amd64 modules) and `build/` from `build`. Entrypoint (`tini`), `CMD`,
`USER nodeuser`, `WORKDIR`, `EXPOSE 8080` and `HEALTHCHECK` do not
change.

All stages use `node:24-alpine@sha256:ebfe2f90…`, a multi-arch index
(amd64, arm64/v8, s390x). Node 24 is an LTS line, supported to
2028-04-30. It replaces `node:25-alpine` from #239, which is
end-of-life.

Measured results:

| | before | after |
|---|---|---|
| `build-and-deploy`, CI | 18m41s (amd64 + arm64, single stage) | ~4m37s
(amd64 + arm64) |
| image size, amd64 | 1.30 GB | 222 MB |
| runtime `node_modules` | 780.7 MB | ~54 MB |

The runtime image has no `typescript`, `artillery`, `eslint`, `o1js` or
Playwright, and no native `.node` files.

### Versioning policy (`docs/versioning.md`)

A move of the container image between LTS lines is **minor**, if
`engines` and the image's HTTP contract (port, endpoints, environment
variables, entrypoint, user) do not change. A move to a non-LTS line
(Current or end-of-life) is still breaking. A raise of `engines`, or of
the Node version that CI uses to publish, is still breaking. #235 makes
the same edit, so the two PRs merge cleanly.

## Release notes

- **The container runtime moves from Node 22 (1.0.x) to Node 24.** Put
this in the release notes of the next release. Under the policy above,
it is a minor change.
- Merge #235 directly after this PR. Until then, the CI test jobs run on
Node 22 only, and the image runs Node 24.

## How to verify after the first tag build

```sh
docker buildx imagetools inspect ghcr.io/o1-labs/archive-node-api:latest   # linux/amd64 + linux/arm64
docker run --rm --platform linux/arm64 --entrypoint node ghcr.io/o1-labs/archive-node-api:latest -e 'console.log(process.version, process.arch)'
docker run --rm --platform linux/amd64 --entrypoint node ghcr.io/o1-labs/archive-node-api:latest -e 'console.log(process.version, process.arch)'
```

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file docker Pull requests that update docker code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant