Repository navigation
chore(deps): bump node from 22-alpine to 25-alpine - #239
Conversation
Bumps node from 22-alpine to 25-alpine. --- updated-dependencies: - dependency-name: node dependency-version: 25-alpine dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
238925b to
665a801
Compare
|
Flagging after the fact, for whoever reads this next: this bump moved the production image onto an end-of-life Node.
Not a criticism of the merge: Dependabot offered it and nothing in the repo said no. That is the gap. #235 fixes it — both stages move to 🤖 Generated with Claude Code |
## Why `ghcr.io/o1-labs/archive-node-api` ships **one architecture** now. Its manifest index lists only: ``` linux amd64 unknown unknown <- build provenance attestation, not an architecture ``` `docker/build-push-action` had no `platforms:`, so it built only for the `ubuntu-latest` runner. On Apple Silicon, this causes emulation and a platform-mismatch warning, or `no matching manifest for linux/arm64` when emulation is off. ## What changed ### Workflow (`.github/workflows/build.yaml`) - `platforms: linux/amd64,linux/arm64` on the build step. - **Set up QEMU** registers the binfmt handlers, so that the amd64 runner can execute aarch64 build steps. - The step runs a `--privileged` container. Thus it comes **before** "Authenticate to Google Cloud", as the ORDERING RULE at the top of the job requires. - The binfmt image is pinned by digest: `docker.io/tonistiigi/binfmt:qemu-v10.2.3@sha256:400a4873…`. The action's default is the mutable `:latest` tag. Dependabot does not bump a `with: image:` input, so a QEMU update is a manual change. - `cache-image: false`. The action's cache entry is keyed by tag, not digest, and adds ~32 MB per PR (#241). - `Move cache` uses `if [ -d … ]; then mv …; fi`. A build that wrote no new cache passes, and a real `mv` failure fails the step. ### `Dockerfile`: three stages, `node:24-alpine` A single stage ran `npm ci` under QEMU for the arm64 leg (752 s against 112 s native) and shipped the dev tree in the runtime image. Now: 1. `deps` (target platform): `npm ci --omit=dev --ignore-scripts`. Production dependencies only. None of them has an install script. 2. `build` (`--platform=$BUILDPLATFORM`): `npm ci --ignore-scripts` and `tsc`. The compiled output does not depend on the architecture, so this stage runs natively one time for all targets. 3. runtime: `node_modules` from `deps` (never from `build`, which has amd64 modules) and `build/` from `build`. Entrypoint (`tini`), `CMD`, `USER nodeuser`, `WORKDIR`, `EXPOSE 8080` and `HEALTHCHECK` do not change. All stages use `node:24-alpine@sha256:ebfe2f90…`, a multi-arch index (amd64, arm64/v8, s390x). Node 24 is an LTS line, supported to 2028-04-30. It replaces `node:25-alpine` from #239, which is end-of-life. Measured results: | | before | after | |---|---|---| | `build-and-deploy`, CI | 18m41s (amd64 + arm64, single stage) | ~4m37s (amd64 + arm64) | | image size, amd64 | 1.30 GB | 222 MB | | runtime `node_modules` | 780.7 MB | ~54 MB | The runtime image has no `typescript`, `artillery`, `eslint`, `o1js` or Playwright, and no native `.node` files. ### Versioning policy (`docs/versioning.md`) A move of the container image between LTS lines is **minor**, if `engines` and the image's HTTP contract (port, endpoints, environment variables, entrypoint, user) do not change. A move to a non-LTS line (Current or end-of-life) is still breaking. A raise of `engines`, or of the Node version that CI uses to publish, is still breaking. #235 makes the same edit, so the two PRs merge cleanly. ## Release notes - **The container runtime moves from Node 22 (1.0.x) to Node 24.** Put this in the release notes of the next release. Under the policy above, it is a minor change. - Merge #235 directly after this PR. Until then, the CI test jobs run on Node 22 only, and the image runs Node 24. ## How to verify after the first tag build ```sh docker buildx imagetools inspect ghcr.io/o1-labs/archive-node-api:latest # linux/amd64 + linux/arm64 docker run --rm --platform linux/arm64 --entrypoint node ghcr.io/o1-labs/archive-node-api:latest -e 'console.log(process.version, process.arch)' docker run --rm --platform linux/amd64 --entrypoint node ghcr.io/o1-labs/archive-node-api:latest -e 'console.log(process.version, process.arch)' ``` 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Bumps node from 22-alpine to 25-alpine.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)