Skip to content

Commit 4b2d3c6

Browse files
authored
chore(ci): update CircleCI orb to 1.1.10 (#243)
1 parent e473680 commit 4b2d3c6

8 files changed

Lines changed: 939 additions & 620 deletions

File tree

‎.circleci/config.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
version: 2.1
22
setup: true
33
orbs:
4-
build: mojaloop/build@1.1.9
4+
build: mojaloop/build@1.1.10
55
workflows:
66
setup:
77
jobs:

‎.grype.yaml‎

Lines changed: 19 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -1,23 +1,30 @@
11
ignore:
22
- vulnerability: GHSA-5j98-mcp5-4vw2
33
include-aliases: true
4-
reason: "glob upgraded to 10.5.0 in package.json, but Node.js 22.20.0-alpine3.22 is still using glob 10.4.5"
4+
reason: glob upgraded to 10.5.0 in package.json, but Node.js 22.20.0-alpine3.22 is still using glob 10.4.5
55
- vulnerability: CVE-2025-46394
6-
reason: "No fixes to busybox apk available as of 2025-10-16 on Dockerfile base image 22.20.0-alpine3.22"
6+
reason: No fixes to busybox apk available as of 2025-10-16 on Dockerfile base image 22.20.0-alpine3.22
77
- vulnerability: CVE-2024-58251
8-
reason: "No fixes to busybox apk available as of 2025-10-16 on Dockerfile base image 22.20.0-alpine3.22"
8+
reason: No fixes to busybox apk available as of 2025-10-16 on Dockerfile base image 22.20.0-alpine3.22
99
- vulnerability: CVE-2025-56200
1010
include-aliases: true
11-
reason: "No fixes available as of 2025-10-16 on validator npm package"
12-
13-
14-
# Set output format defaults
11+
reason: No fixes available as of 2025-10-16 on validator npm package
12+
- vulnerability: CVE-2025-60876
13+
include-aliases: true
14+
reason: "Alpine base image package (apk): busybox - no npm fix available as of 2026-02-06 (moderate severity)"
15+
- vulnerability: GHSA-34x7-hfp2-rc4v
16+
include-aliases: true
17+
reason: "tar 6.2.1/7.4.3 bundled inside npm in Node.js Docker image (node:22.22.0-alpine3.23) - not an application dependency, no npm fix available as of 2026-02-10"
18+
- vulnerability: GHSA-r6q2-hw4h-h46w
19+
include-aliases: true
20+
reason: "tar 6.2.1/7.4.3 bundled inside npm in Node.js Docker image (node:22.22.0-alpine3.23) - not an application dependency, no npm fix available as of 2026-02-10"
21+
- vulnerability: GHSA-8qq5-rm4j-mr97
22+
include-aliases: true
23+
reason: "tar 6.2.1/7.4.3 bundled inside npm in Node.js Docker image (node:22.22.0-alpine3.23) - not an application dependency, no npm fix available as of 2026-02-10"
1524
output:
16-
- "table"
17-
- "json"
18-
19-
# Modify your CircleCI job to check critical count
25+
- table
26+
- json
2027
search:
21-
scope: "squashed"
28+
scope: squashed
2229
quiet: false
2330
check-for-app-update: false

‎.nvmrc‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1 @@
1-
22.20.0
1+
22.22.0

‎Dockerfile‎

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,5 @@
11
# Arguments
2-
ARG NODE_VERSION=22.20.0-alpine3.22
3-
2+
ARG NODE_VERSION="22.22.0-alpine3.23"
43
# NOTE: Ensure you set NODE_VERSION Build Argument as follows...
54
#
65
# export NODE_VERSION="$(cat .nvmrc)-alpine" \
@@ -11,7 +10,7 @@ ARG NODE_VERSION=22.20.0-alpine3.22
1110
#
1211

1312
# Build Image
14-
FROM node:${NODE_VERSION} as builder
13+
FROM node:${NODE_VERSION} AS builder
1514
WORKDIR /opt/app
1615

1716
RUN apk --no-cache add git

0 commit comments

Comments
 (0)