Repository navigation
Expand file tree
/
Copy pathDockerfile
More file actions
65 lines (51 loc) · 2.25 KB
/
Copy pathDockerfile
File metadata and controls
65 lines (51 loc) · 2.25 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
FROM node:20-alpine3.23 AS build-stage
WORKDIR /usr/src/app
ARG DOCKER_TAG="latest"
# Add Zscaler Root CA certificate
ADD https://raw.githubusercontent.com/cfpb/zscaler-cert/refs/heads/main/zscaler_root_ca.pem /usr/local/share/ca-certificates/zscaler-root-public.cert
RUN apk add ca-certificates --no-cache --no-check-certificate && \
update-ca-certificates && \
cp /etc/ssl/certs/ca-certificates.crt /usr/src/app/ca-certificates.crt
ARG NODE_EXTRA_CA_CERTS=/usr/local/share/ca-certificates/zscaler-root-public.cert
RUN --mount=type=secret,id=env_vars \
cp /run/secrets/env_vars .env
# Resolves packageManager yarn issue in the package.json file
ENV SKIP_YARN_COREPACK_CHECK=0
# install build dependencies
COPY package.json .
# Using Yarn V4
RUN yarn set version 4.1.0
COPY yarn.lock .yarn .yarnrc.yml ./
RUN yarn install
# Copying all directories and subdirectories as Vite needs everything
COPY . .
RUN echo "{ \"version\": \"${DOCKER_TAG}\" }" > ./src/common/constants/release.json
RUN yarn build
FROM nginx:alpine3.23
COPY --from=build-stage /usr/src/app/ca-certificates.crt /etc/ssl/certs/ca-certificates.crt
# Temporary fix for vulnerability CVE-2026-3805 (curl, fix currently on edge only)
# More info at: GHE #5550
RUN echo "@edge https://dl-cdn.alpinelinux.org/alpine/edge/main" >> /etc/apk/repositories && \
apk update && \
apk add --no-cache curl@edge libcurl@edge
# Temporary fix for CVE-2026-40930 (libpng < 1.6.58-r1)
# More info at: GHE #5575
RUN apk update && apk add 'libpng>=1.6.58-r1'
# Temporary fix for CVE-2026-6732 (libxml2 < 2.15.3)
# We don't use the two nginx modules (xslt and njs) that use the vulnerable libxml2. So we can delete
# them, then we can remove libxml2 too.
# More info at: GHE #5576
RUN apk del --no-network nginx-module-xslt nginx-module-njs libxslt libxml2
ENV NGINX_USER=svc_nginx_hmda
RUN apk update && apk upgrade
RUN rm -rf /etc/nginx/conf.d
COPY nginx /etc/nginx
COPY --from=build-stage /usr/src/app/dist /usr/share/nginx/html
RUN adduser -S $NGINX_USER nginx && \
addgroup -S $NGINX_USER && \
addgroup $NGINX_USER $NGINX_USER && \
touch /run/nginx.pid && \
chown -R $NGINX_USER:$NGINX_USER /etc/nginx /run/nginx.pid /var/cache/nginx/
EXPOSE 8080
USER svc_nginx_hmda
CMD ["nginx", "-g", "daemon off;"]