Repository navigation
chore(deps): bump node from 22-alpine to 26-alpine - #831
Merged
LucasSantana-Dev merged 4 commits intoMay 10, 2026
Merged
Conversation
Bumps node from 22-alpine to 26-alpine. --- updated-dependencies: - dependency-name: node dependency-version: 26-alpine dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
LucasSantana-Dev
enabled auto-merge (squash)
May 10, 2026 00:46
LucasSantana-Dev
previously approved these changes
May 10, 2026
LucasSantana-Dev
left a comment
Owner
There was a problem hiding this comment.
All CI green, SonarCloud + CodeRabbit passed. Approving for auto-merge.
Builder image now uses Node 26-alpine, but engines.node was still pinned to '22.x', producing npm warnings (or hard failure under engine-strict). Widen the constraint to '>=22 <27' so it spans the upgrade path without further drift. Note: Node 26 is the 'Current' release line, not LTS. Node 24 LTS ships in 2026 H2 — pinning to 26 short-term is acceptable for the release/v2.10.0 cycle since the bot does not consume Node-version- specific runtime features and we'll re-evaluate once Node 24 is GA. Addresses Greptile feedback on PR #831. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
Size Change: 0 B Total Size: 367 kB ℹ️ View Unchanged
|
LucasSantana-Dev
approved these changes
May 10, 2026
LucasSantana-Dev
left a comment
Owner
There was a problem hiding this comment.
Fixes addressed, all CI green, third-party reviews pass.
|
This was referenced May 13, 2026
Merged
LucasSantana-Dev
added a commit
that referenced
this pull request
May 13, 2026
Dockerfile.frontend ran npm ci in the workspace root, which pulls in @discordjs/opus from the bot workspace. On node:26-alpine the prebuilt opus binaries are missing (node-pre-gyp v0.4.5 doesnt ship Node 26 ABI) and the alpine image lacks the C toolchain to compile from source, so docker-publish has failed every run since #831 merged on 2026-05-10. Reverting just Dockerfile.frontend to node:22-alpine matches the root Dockerfile (ARG NODE_VERSION=22-alpine). The package.json engines field still allows >=22 <27, so this is just rolling the container base back to the version with prebuilt native binaries. Follow-up issue should track moving to Node 24 alpine once @discordjs/opus ships matching prebuilts, OR adding the build-base apk package to the frontend builder stage so native compilation works without prebuilts. Closes the actual audit RED finding (docker-publish, not deploy.yml). Refs: - PR #831 (introduced the bump) - PR #845 (fixed deploy.yml typo; was a real bug but not THE blocker) - audit_deep_lucky_2026-05-13.md (RED finding) Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
LucasSantana-Dev
added a commit
that referenced
this pull request
May 13, 2026
* chore(deps): bump node from 22-alpine to 26-alpine Bumps node from 22-alpine to 26-alpine. --- updated-dependencies: - dependency-name: node dependency-version: 26-alpine dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> * chore(deps): align engines.node range with Node 26-alpine builder Builder image now uses Node 26-alpine, but engines.node was still pinned to '22.x', producing npm warnings (or hard failure under engine-strict). Widen the constraint to '>=22 <27' so it spans the upgrade path without further drift. Note: Node 26 is the 'Current' release line, not LTS. Node 24 LTS ships in 2026 H2 — pinning to 26 short-term is acceptable for the release/v2.10.0 cycle since the bot does not consume Node-version- specific runtime features and we'll re-evaluate once Node 24 is GA. Addresses Greptile feedback on PR #831. --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Lucas Santana <98131142+LucasSantana-Dev@users.noreply.github.com> Co-authored-by: Lucas Santana <lucas.diassantana@gmail.com> Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
LucasSantana-Dev
added a commit
that referenced
this pull request
May 13, 2026
Dockerfile.frontend ran npm ci in the workspace root, which pulls in @discordjs/opus from the bot workspace. On node:26-alpine the prebuilt opus binaries are missing (node-pre-gyp v0.4.5 doesnt ship Node 26 ABI) and the alpine image lacks the C toolchain to compile from source, so docker-publish has failed every run since #831 merged on 2026-05-10. Reverting just Dockerfile.frontend to node:22-alpine matches the root Dockerfile (ARG NODE_VERSION=22-alpine). The package.json engines field still allows >=22 <27, so this is just rolling the container base back to the version with prebuilt native binaries. Follow-up issue should track moving to Node 24 alpine once @discordjs/opus ships matching prebuilts, OR adding the build-base apk package to the frontend builder stage so native compilation works without prebuilts. Closes the actual audit RED finding (docker-publish, not deploy.yml). Refs: - PR #831 (introduced the bump) - PR #845 (fixed deploy.yml typo; was a real bug but not THE blocker) - audit_deep_lucky_2026-05-13.md (RED finding) Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Bumps node from 22-alpine to 26-alpine.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)Greptile Summary
node:22-alpinetonode:26-alpine(Node 26 "Current"). The final production image remainsnginx:alpineand is unaffected.engines.nodeconstraint inpackage.json(and mirrored inpackage-lock.json) has been updated from"22.x"to">=22 <27", keeping the declared range in sync with the running Node version.Confidence Score: 4/5
Mechanically correct bump, but targets a fresh non-LTS major on a release branch — warrants human sign-off before merging.
No new code defects; the engines mismatch flagged in a prior review has been addressed. The remaining concern (Node 26 "Current" vs Node 24 LTS) was already raised in a previous comment thread, so it is not re-raised here, but it is the reason the score is not a full 5.
No files require special attention — all three changed files are in sync.
Important Files Changed
Flowchart
%%{init: {'theme': 'neutral'}}%% flowchart TD A["node:26-alpine (builder)"] --> B[npm ci] B --> C[prisma generate] C --> D[npm run build] D --> E["nginx:alpine (final image)"] E --> F[EXPOSE 80]Reviews (4): Last reviewed commit: "Merge branch 'release/v2.10.0' into depe..." | Re-trigger Greptile