Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .circleci/config.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
version: 2.1
setup: true
orbs:
build: mojaloop/build@1.1.9
build: mojaloop/build@1.1.10
workflows:
setup:
jobs:
Expand Down
31 changes: 19 additions & 12 deletions .grype.yaml
Original file line number Diff line number Diff line change
@@ -1,23 +1,30 @@
ignore:
- vulnerability: GHSA-5j98-mcp5-4vw2
include-aliases: true
reason: "glob upgraded to 10.5.0 in package.json, but Node.js 22.20.0-alpine3.22 is still using glob 10.4.5"
reason: glob upgraded to 10.5.0 in package.json, but Node.js 22.20.0-alpine3.22 is still using glob 10.4.5
- vulnerability: CVE-2025-46394
reason: "No fixes to busybox apk available as of 2025-10-16 on Dockerfile base image 22.20.0-alpine3.22"
reason: No fixes to busybox apk available as of 2025-10-16 on Dockerfile base image 22.20.0-alpine3.22
- vulnerability: CVE-2024-58251
reason: "No fixes to busybox apk available as of 2025-10-16 on Dockerfile base image 22.20.0-alpine3.22"
reason: No fixes to busybox apk available as of 2025-10-16 on Dockerfile base image 22.20.0-alpine3.22
- vulnerability: CVE-2025-56200
include-aliases: true
reason: "No fixes available as of 2025-10-16 on validator npm package"


# Set output format defaults
reason: No fixes available as of 2025-10-16 on validator npm package
- vulnerability: CVE-2025-60876
include-aliases: true
reason: "Alpine base image package (apk): busybox - no npm fix available as of 2026-02-06 (moderate severity)"
- vulnerability: GHSA-34x7-hfp2-rc4v
include-aliases: true
reason: "tar 6.2.1/7.4.3 bundled inside npm in Node.js Docker image (node:22.22.0-alpine3.23) - not an application dependency, no npm fix available as of 2026-02-10"
- vulnerability: GHSA-r6q2-hw4h-h46w
include-aliases: true
reason: "tar 6.2.1/7.4.3 bundled inside npm in Node.js Docker image (node:22.22.0-alpine3.23) - not an application dependency, no npm fix available as of 2026-02-10"
- vulnerability: GHSA-8qq5-rm4j-mr97
include-aliases: true
reason: "tar 6.2.1/7.4.3 bundled inside npm in Node.js Docker image (node:22.22.0-alpine3.23) - not an application dependency, no npm fix available as of 2026-02-10"
output:
- "table"
- "json"

# Modify your CircleCI job to check critical count
- table
- json
search:
scope: "squashed"
scope: squashed
quiet: false
check-for-app-update: false
2 changes: 1 addition & 1 deletion .nvmrc
Original file line number Diff line number Diff line change
@@ -1 +1 @@
22.20.0
22.22.0
5 changes: 2 additions & 3 deletions Dockerfile
Original file line number Diff line number Diff line change
@@ -1,6 +1,5 @@
# Arguments
ARG NODE_VERSION=22.20.0-alpine3.22

ARG NODE_VERSION="22.22.0-alpine3.23"
# NOTE: Ensure you set NODE_VERSION Build Argument as follows...
#
# export NODE_VERSION="$(cat .nvmrc)-alpine" \
Expand All @@ -11,7 +10,7 @@ ARG NODE_VERSION=22.20.0-alpine3.22
#

# Build Image
FROM node:${NODE_VERSION} as builder
FROM node:${NODE_VERSION} AS builder
WORKDIR /opt/app

RUN apk --no-cache add git
Expand Down
Loading