Conversation
The pinned wolfi-base digest (sha256:70750dfd, from Apr 2026) ships glibc < 2.44, but entrypoint.sh installs nodejs-26 at runtime from the live Chainguard repos, which requires GLIBC_2.44, making node crash after the scan: node: /usr/lib/libm.so.6: version 'GLIBC_2.44' not found (required by node) Refresh the pin to the current wolfi-base digest (sha256:1cec89e6, resolved on 2026-09-02 from cgr.dev registry) so the base image and the runtime-installed nodejs stay in sync. Fixes Checkmarx#160
3a1821a to
839c1f6
Compare
cx-artur-ribeiro
left a comment
There was a problem hiding this comment.
LGTM, thanks for the quick fix!
|
Confirming this fixes the failure, with a note on durability. Verification — the crash is in The concern: the two inputs still move independently. The base is pinned; A durable follow-up: take Node from an image where Node and glibc are built together, and build at image-build time. FROM docker.io/checkmarx/kics:v2.1.19@sha256:7b0a4d750acd491942ce9de52c1183fbf4451c1c936780ec2cfacd2650e7d84c AS kics-env
# node + glibc ship from one image, so they cannot drift apart
FROM cgr.dev/chainguard/node:latest
USER root
COPY --from=kics-env /app /app
COPY ./ /app
WORKDIR /app
RUN npm ci && npm run build --if-present
COPY ./entrypoint.sh /entrypoint.sh
RUN chmod +x /entrypoint.sh
ENTRYPOINT ["/entrypoint.sh"]…and drop Verified locally on linux/amd64: builds; One trap if anyone extends this PR to move the Node install into the Dockerfile while staying on Happy to raise the follow-up as a separate PR if the direction seems useful — this one stands on its own as the immediate fix. |
What
Refresh the pinned
cgr.dev/chainguard/wolfi-basedigest in theDockerfileto the current one, fixing the node GLIBC_2.44 crash after the scan.Why
The current pin (
sha256:70750dfd..., from Apr 2026, added in #156) ships glibc < 2.44. However,entrypoint.shinstalls Node at runtime from the live Chainguard APK repos (apk add --update nodejs npm), which today servenodejs-26(26.8.1-r1) built against GLIBC_2.44. The resulting node binary cannot start against the old libc:The scan itself completes fine (findings are not the cause); the crash happens afterwards when the action runs node to post PR comments/annotations. Non-deterministic: it started failing once Chainguard shipped nodejs-26 (reported in #160).
Change
How the digest was resolved
Queried the Chainguard registry
cgr.dev(2026-09-02):The digest (and the old one) were verified to exist in the registry (HTTP 200).
Validation
A similar fix (same base image, live
latest) validated on an internal GHES fork: fresh KICS run completed successfully — 0 GLIBC_2.44 errors, node post-processing ran fine, same findings reported (withignore_on_exit: results).Fixes #160