Skip to content

chore(deps): bump node from 22-alpine to 26-alpine - #831

Merged
LucasSantana-Dev merged 4 commits into
release/v2.10.0from
dependabot/docker/node-26-alpine
May 10, 2026
Merged

LucasSantana-Dev merged 4 commits into
release/v2.10.0from
dependabot/docker/node-26-alpine

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 9, 2026 •

Copy link
Copy Markdown
Contributor

Bumps node from 22-alpine to 26-alpine.

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Greptile Summary

  • Bumps the Docker builder stage from node:22-alpine to node:26-alpine (Node 26 "Current"). The final production image remains nginx:alpine and is unaffected.
  • The engines.node constraint in package.json (and mirrored in package-lock.json) has been updated from "22.x" to ">=22 <27", keeping the declared range in sync with the running Node version.

Confidence Score: 4/5

Mechanically correct bump, but targets a fresh non-LTS major on a release branch — warrants human sign-off before merging.

No new code defects; the engines mismatch flagged in a prior review has been addressed. The remaining concern (Node 26 "Current" vs Node 24 LTS) was already raised in a previous comment thread, so it is not re-raised here, but it is the reason the score is not a full 5.

No files require special attention — all three changed files are in sync.

Important Files Changed

Filename Overview
Dockerfile.frontend Builder stage updated from node:22-alpine to node:26-alpine; final nginx:alpine stage is unchanged.
package.json engines.node widened from "22.x" to ">=22 <27", now consistent with the Node 26 Docker image.
package-lock.json Root engines.node entry updated to match package.json; no dependency graph changes.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
    A["node:26-alpine (builder)"] --> B[npm ci]
    B --> C[prisma generate]
    C --> D[npm run build]
    D --> E["nginx:alpine (final image)"]
    E --> F[EXPOSE 80]
Loading

Reviews (4): Last reviewed commit: "Merge branch 'release/v2.10.0' into depe..." | Re-trigger Greptile

Bumps node from 22-alpine to 26-alpine.

---
updated-dependencies:
- dependency-name: node
  dependency-version: 26-alpine
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file docker Pull requests that update docker code labels May 9, 2026
@vercel

vercel Bot commented May 9, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
lucky Ready Ready Preview, Comment May 10, 2026 2:03pm

Request Review

@github-actions github-actions Bot added infra size/xs and removed dependencies Pull requests that update a dependency file labels May 9, 2026
Comment thread Dockerfile.frontend
Comment thread Dockerfile.frontend

@LucasSantana-Dev LucasSantana-Dev left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All CI green, SonarCloud + CodeRabbit passed. Approving for auto-merge.

Builder image now uses Node 26-alpine, but engines.node was still
pinned to '22.x', producing npm warnings (or hard failure under
engine-strict). Widen the constraint to '>=22 <27' so it spans the
upgrade path without further drift.

Note: Node 26 is the 'Current' release line, not LTS. Node 24 LTS
ships in 2026 H2 — pinning to 26 short-term is acceptable for the
release/v2.10.0 cycle since the bot does not consume Node-version-
specific runtime features and we'll re-evaluate once Node 24 is GA.

Addresses Greptile feedback on PR #831.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions github-actions Bot added the dependencies Pull requests that update a dependency file label May 10, 2026
@github-actions

github-actions Bot commented May 10, 2026 •

Copy link
Copy Markdown

Size Change: 0 B

Total Size: 367 kB

ℹ️ View Unchanged
Filename Size
packages/frontend/dist/assets/ActionPanel-dTlZUgqe.js 402 B
packages/frontend/dist/assets/Admin-DnWz1MOA.js 1.97 kB
packages/frontend/dist/assets/AutoMessages-vRB62tJd.js 2.66 kB
packages/frontend/dist/assets/AutoMod-K_viJkXQ.js 4.07 kB
packages/frontend/dist/assets/badge-8qbHQXXg.js 504 B
packages/frontend/dist/assets/Card-PloSFCea.js 506 B
packages/frontend/dist/assets/CommandsConfig-CESed-fz.js 1.44 kB
packages/frontend/dist/assets/Config-By5IL35T.js 1.64 kB
packages/frontend/dist/assets/CustomCommands-CXfqmyJo.js 2.14 kB
packages/frontend/dist/assets/DashboardOverview-CL541_VM.js 3.36 kB
packages/frontend/dist/assets/dialog-BCLK2JMT.js 952 B
packages/frontend/dist/assets/EmbedBuilder-BdtZhzFK.js 3.31 kB
packages/frontend/dist/assets/Features-ByYF18ea.js 756 B
packages/frontend/dist/assets/GuildAutomation-Dc7me2lV.js 2.9 kB
packages/frontend/dist/assets/index-DDLMHTiW.css 17.1 kB
packages/frontend/dist/assets/index-DyCTxeYW.js 56 kB
packages/frontend/dist/assets/input-cOH1PQVi.js 467 B
packages/frontend/dist/assets/label-Dh1uOFi2.js 478 B
packages/frontend/dist/assets/Landing-CD9QzN7X.js 3.71 kB
packages/frontend/dist/assets/LastFm-blvMf2ay.js 1.74 kB
packages/frontend/dist/assets/Levels-B96wzwSM.js 2.61 kB
packages/frontend/dist/assets/Login-tEr-uYLk.js 2.48 kB
packages/frontend/dist/assets/Lyrics-Dvgco87j.js 1.32 kB
packages/frontend/dist/assets/Moderation-Bqlfkaz_.js 3.81 kB
packages/frontend/dist/assets/Music-Dqx9eZ6w.js 7.11 kB
packages/frontend/dist/assets/MusicConfig-C1cDkQXP.js 1.59 kB
packages/frontend/dist/assets/PreferredArtists-CcbRnFlR.js 3.67 kB
packages/frontend/dist/assets/PrivacyPolicy-BmZtXGg8.js 1.38 kB
packages/frontend/dist/assets/ReactionRoles-Dm64nzHC.js 1.86 kB
packages/frontend/dist/assets/rolldown-runtime-BYbx6iT9.js 471 B
packages/frontend/dist/assets/SectionHeader-CtzacEAY.js 895 B
packages/frontend/dist/assets/select-FOgY7B8V.js 1.23 kB
packages/frontend/dist/assets/ServerLogs-QqqQW9cg.js 2.87 kB
packages/frontend/dist/assets/ServerSettings-sBfBpHL0.js 4.19 kB
packages/frontend/dist/assets/ServersPage-CuWU6B6g.js 2.87 kB
packages/frontend/dist/assets/Skeleton-BKxDqjuF.js 237 B
packages/frontend/dist/assets/Spotify-ChhuqXVt.js 1.75 kB
packages/frontend/dist/assets/Starboard-CReFRkuG.js 2.05 kB
packages/frontend/dist/assets/StatTile-B31RaVZ2.js 638 B
packages/frontend/dist/assets/switch-BE_uObSf.js 543 B
packages/frontend/dist/assets/TermsOfService-BolVjdlH.js 1.37 kB
packages/frontend/dist/assets/TrackHistory-Dv_7dEQE.js 2.15 kB
packages/frontend/dist/assets/TwitchNotifications-NRZsAuz4.js 2.43 kB
packages/frontend/dist/assets/useFeatures-BSC8EiID.js 1.99 kB
packages/frontend/dist/assets/usePageMetadata-T1T1Fi3u.js 329 B
packages/frontend/dist/assets/vendor-forms-DNkRbYRs.js 25.6 kB
packages/frontend/dist/assets/vendor-radix-hBYIp2YC.js 38.9 kB
packages/frontend/dist/assets/vendor-react-CFDOOXi7.js 55.7 kB
packages/frontend/dist/assets/vendor-state-BDM_FkZa.js 24.1 kB
packages/frontend/dist/assets/vendor-ui-CbZ_GPii.js 64.7 kB

compressed-size-action

@LucasSantana-Dev LucasSantana-Dev left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixes addressed, all CI green, third-party reviews pass.

@sonarqubecloud

Copy link
Copy Markdown

@LucasSantana-Dev
LucasSantana-Dev merged commit ed39e74 into release/v2.10.0 May 10, 2026
15 checks passed
@dependabot
dependabot Bot deleted the dependabot/docker/node-26-alpine branch May 10, 2026 14:06
LucasSantana-Dev added a commit that referenced this pull request May 13, 2026
Dockerfile.frontend ran npm ci in the workspace root, which pulls in
@discordjs/opus from the bot workspace. On node:26-alpine the prebuilt
opus binaries are missing (node-pre-gyp v0.4.5 doesnt ship Node 26 ABI)
and the alpine image lacks the C toolchain to compile from source, so
docker-publish has failed every run since #831 merged on 2026-05-10.

Reverting just Dockerfile.frontend to node:22-alpine matches the root
Dockerfile (ARG NODE_VERSION=22-alpine). The package.json engines field
still allows >=22 <27, so this is just rolling the container base back
to the version with prebuilt native binaries.

Follow-up issue should track moving to Node 24 alpine once @discordjs/opus
ships matching prebuilts, OR adding the build-base apk package to the
frontend builder stage so native compilation works without prebuilts.

Closes the actual audit RED finding (docker-publish, not deploy.yml).

Refs:
- PR #831 (introduced the bump)
- PR #845 (fixed deploy.yml typo; was a real bug but not THE blocker)
- audit_deep_lucky_2026-05-13.md (RED finding)

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
LucasSantana-Dev added a commit that referenced this pull request May 13, 2026
* chore(deps): bump node from 22-alpine to 26-alpine

Bumps node from 22-alpine to 26-alpine.

---
updated-dependencies:
- dependency-name: node
  dependency-version: 26-alpine
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): align engines.node range with Node 26-alpine builder

Builder image now uses Node 26-alpine, but engines.node was still
pinned to '22.x', producing npm warnings (or hard failure under
engine-strict). Widen the constraint to '>=22 <27' so it spans the
upgrade path without further drift.

Note: Node 26 is the 'Current' release line, not LTS. Node 24 LTS
ships in 2026 H2 — pinning to 26 short-term is acceptable for the
release/v2.10.0 cycle since the bot does not consume Node-version-
specific runtime features and we'll re-evaluate once Node 24 is GA.

Addresses Greptile feedback on PR #831.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Lucas Santana <98131142+LucasSantana-Dev@users.noreply.github.com>
Co-authored-by: Lucas Santana <lucas.diassantana@gmail.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
LucasSantana-Dev added a commit that referenced this pull request May 13, 2026
Dockerfile.frontend ran npm ci in the workspace root, which pulls in
@discordjs/opus from the bot workspace. On node:26-alpine the prebuilt
opus binaries are missing (node-pre-gyp v0.4.5 doesnt ship Node 26 ABI)
and the alpine image lacks the C toolchain to compile from source, so
docker-publish has failed every run since #831 merged on 2026-05-10.

Reverting just Dockerfile.frontend to node:22-alpine matches the root
Dockerfile (ARG NODE_VERSION=22-alpine). The package.json engines field
still allows >=22 <27, so this is just rolling the container base back
to the version with prebuilt native binaries.

Follow-up issue should track moving to Node 24 alpine once @discordjs/opus
ships matching prebuilts, OR adding the build-base apk package to the
frontend builder stage so native compilation works without prebuilts.

Closes the actual audit RED finding (docker-publish, not deploy.yml).

Refs:
- PR #831 (introduced the bump)
- PR #845 (fixed deploy.yml typo; was a real bug but not THE blocker)
- audit_deep_lucky_2026-05-13.md (RED finding)

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

This branch was successfully deployed

1 active deployment
Preview — 2cd4bf47 Deployed May 10, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file docker Pull requests that update docker code infra size/xs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant