Skip to content

fix(docker): keep git and openssh-client out of the runtime image - #565

Merged
Neophytis merged 1 commit into
feature/docker-masterfrom
neophytis/runtime-image-drop-git
Oct 9, 2026
Merged

Neophytis merged 1 commit into
feature/docker-masterfrom
neophytis/runtime-image-drop-git

Conversation

@Neophytis

Copy link
Copy Markdown
Contributor

Target branch: feature/docker-master.

Why

The stage image scan failed again (run 37893397774 on 5f5ff1b). Trivy now also flags CVE-2026-77214 (HIGH) in libexpat 2.8.5-r0, next to CVE-2026-102633 (MEDIUM), which #562 ignored. Both are fixed only in libexpat 2.9.0-r0 in Alpine edge. Alpine 3.24 still ships 2.8.5-r0 (APKINDEX and the 3.24-stable APKBUILD are unchanged, and the 3.24 secdb has no entry), so the daily apk upgrade can't fix it.

git is the only package that pulls libexpat into the runtime image, and the runtime image doesn't need git:

  • composer install --prefer-dist: all 177 locked packages have a dist archive, no VCS repositories.
  • docker-entrypoint only runs git rev-parse when APP_ENV != prod, and .git is in .dockerignore, so it can't work in a built image anyway.
  • Nothing in src/, build/, bin/, config/ or docker/ calls git or ssh at runtime.

Changes

  • Dockerfile: git and openssh-client move from the base bewelcome_php stage to bewelcome_php_dev, which docker-compose and the devcontainer build.
  • .trivyignore: the CVE-2026-102633 exception is removed. It's no longer needed, and the file is back to header-only.

This replaces a growing list of exceptions with a smaller image.

Tested

  • Stage image build sha-c577043: every job green, including Scan image, with no exceptions.
  • Inside the image: libexpat, git and ssh are absent. The PHP xml, dom and simplexml extensions are present (they use libxml2).
  • Deployed to stage. The smoke suite passed, php, web and cron are healthy, and there are no git-related errors in the logs. /, /faq, /signup, /login and /feedback return 200, and /about/faq returns 301 (fix(seo): /about/faq is a permanent redirect, links go to /faq (sysadmins-infra#654) #564 is included).

Not tested: a local build of the bewelcome_php_dev target. That stage only gains two apk add packages.

Only the dev stage needs them (docker-entrypoint writes VERSION from git
outside prod; .git is not in the image, and composer installs from dist).
git was the only reason libexpat was in the runtime image, which now has
two CVEs (CVE-2026-102633 MEDIUM, CVE-2026-77214 HIGH) fixed only in
Alpine edge. Dropping it removes both, so the .trivyignore exception for
CVE-2026-102633 goes too.
@Neophytis
Neophytis merged commit b09768e into feature/docker-master Oct 9, 2026
11 of 19 checks passed
@Neophytis
Neophytis deleted the neophytis/runtime-image-drop-git branch October 9, 2026 06:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant