Skip to content

Request: bump minimatch (GHSA-3ppc-4f35-3m26) in node:24.x-alpine images #2385

Description

@mstreitner

Hello,

Docker Hub currently reports GHSA-3ppc-4f35-3m26 (minimatch < 10.2.1) for node:24.x-alpine images.

Could you please confirm whether the bundled npm version in the current 24.x images includes minimatch >= 10.2.1?

If not, would it be possible to bump the bundled npm / dependency chain in an upcoming 24.x release so the image no longer flags this CVE?

Thank you.

Activity

  1. MikeMcC399 commented on Feb 25, 2026

    @MikeMcC399
    Contributor

    @mstreitner

    See https://github.com/nodejs/docker-node/blob/main/SECURITY.md

    The Node.js Docker images package exactly what the distribution of Node.js has packaged, including a certain version of npm, and npm's dependencies.

    There is no scope in the Node.js Docker repo for individually updating parts of Node.js or its bundled packages.

    The latest version of Node.js 24.x is 24.14.0. This contains npm v11.9.0

    node:24.14.0-alpine still reports CVE-2026-26996

    You will need to wait until npm v11.10.1 (Feb 19, 2026) goes through the release process for Node.js. There is an in-built delay between npm releases and Node.js releases.

    You can follow the Node.js releases on https://github.com/nodejs/node and select Watch > Custom > Releases and you can close this issue as there is no specific action to be taken in this repo. All the updates happen as a matter of routine.

  2. sxa commented on Feb 26, 2026

    @sxa
    Member

    @MikeMcC399 Unfortunately I don't believe an upstream rebuild by dockerhub would update minimatch as that comes from the version in the source tree so the update request would have to go to the main node.js repository, not docker-node. Having said that, the version in main has been updated to 10.2.2 two days ago and so it should get backported to the release lines automatically.

    Since it's based on the version in the source tree I'll also note that this one is not specific to Alpine and also affects e.g. the Debian Trixie images.

  3. MikeMcC399 commented on Feb 26, 2026

    @MikeMcC399
    Contributor

    @sxa

    Docker Scout is actually reporting the vulnerability from the bundled npm package:

    Image

    Thanks for pointing out the other source of minimatch. I would still suggest closing this issue though, as there are no specific actions that can be taken in this repo. As always, the Node.js Docker images just builds using whatever contents Node.js releases.

  4. MikeMcC399 commented on Feb 26, 2026

    @MikeMcC399
    Contributor

    The vulnerability is not reported in node:current-alpine3.23 using Node.js 25.7.0.

    So the choices are to wait for an updated Node.js 24.x (Active LTS) release or use Node.js 25.x (Current).

  5. sxa commented on Feb 26, 2026

    @sxa
    Member

    Noting also for reference for those in Slack - a similar discussion (npm bump) was covered a few weeks ago in this thread

  6. MikeMcC399 commented on Feb 27, 2026

    @MikeMcC399
    Contributor

    As a workaround, it is also possible to update npm from the npm registry:

    In node:lts-alpine executing:

    npm install npm@latest --global

    will currently update to npm@11.11.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions