From f6ca712c34c7a5458a2eef221aa4d54776490fb8 Mon Sep 17 00:00:00 2001 From: Mike McCready <66998419+MikeMcC399@users.noreply.github.com> Date: Fri, 9 Oct 2026 07:51:40 +0200 Subject: [PATCH] chore: remove unofficial-builds dependency Remove query of https://unofficial-builds.nodejs.org Incorporate musl into security builds Remove update.sh security build switch Update documentation Signed-off-by: Mike McCready <66998419+MikeMcC399@users.noreply.github.com> --- CONTRIBUTING.md | 1 - README.md | 6 ------ build-automation.mjs | 49 +++++--------------------------------------- update.sh | 10 ++------- 4 files changed, 7 insertions(+), 59 deletions(-) diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 1b0d486526..7ba0c77791 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -149,7 +149,6 @@ After the end of Debian LTS support, the corresponding Debian release is dropped ### Image Creation Automation - Every 15 minutes, the [workflow](https://github.com/nodejs/docker-node/blob/main/.github/workflows/automatic-updates.yml) within the [nodejs/docker-node](https://github.com/nodejs/docker-node) repo [checks](https://github.com/nodejs/docker-node/blob/main/build-automation.mjs) for new versions of Node.js [published to the website's `index.json` file](https://nodejs.org/download/release/index.json). - - If found, it also checks for an [unofficial musl/Alpine build](https://unofficial-builds.nodejs.org/download/release/index.json). - If found, the [update script](https://github.com/nodejs/docker-node/blob/main/update.sh) runs - The workflow opens a pull request either automatically via [nodejs-github-bot](https://github.com/nodejs-github-bot) or in some cases manually, such as when there is a new major release. - Another [workflow](https://github.com/nodejs/docker-node/blob/main/.github/workflows/official-pr.yml) detects the merger of these pull requests and opens a pull request to [docker-library/official-images](https://github.com/docker-library/official-images). diff --git a/README.md b/README.md index 6ee23ca6da..e3bcfa3de1 100644 --- a/README.md +++ b/README.md @@ -256,12 +256,6 @@ message "no matching manifest". In this case, check back later. (See [Docker Library FAQs](https://github.com/docker-library/faq#an-images-source-changed-in-git-now-what) for a detailed description of the complex build process.) -For Node.js security releases, Debian-based `node` images may be published in advance -of Alpine-based images. To build an Alpine-based `node` image requires -a `musl` build. This may not initially be ready at Node.js release time. -When processing non-security Node.js releases, the build process will wait for -the `musl` build before proceeding with Debian- and Alpine-based images. - ## License [License information](https://github.com/nodejs/node/blob/main/LICENSE) for diff --git a/build-automation.mjs b/build-automation.mjs index eedc2fc5b7..ce6200dd71 100644 --- a/build-automation.mjs +++ b/build-automation.mjs @@ -78,59 +78,20 @@ const checkIfThereAreNewVersions = async (github) => { } }; -// a function that queries the Node.js unofficial release website for new musl versions and security releases, -// and returns relevant information -const checkForMuslVersionsAndSecurityReleases = async (github, versions) => { - try { - const { data: unofficialBuildsIndexText } = await github.request( - 'https://unofficial-builds.nodejs.org/download/release/index.json', - ); - - for (let version of Object.keys(versions)) { - const buildVersion = unofficialBuildsIndexText.find( - (indexVersion) => - indexVersion.version === `v${versions[version].fullVersion}`, - ); - - versions[version].muslBuildExists = - buildVersion?.files.includes('linux-x64-musl') ?? false; - versions[version].isSecurityRelease = buildVersion?.security ?? false; - } - return versions; - } catch (error) { - console.error(error); - process.exit(1); - } -}; - export default async function (github) { // if there are no new versions, exit gracefully - // if there are new versions, - // check for musl builds - // then run update.sh + // if there are new versions, run update.sh const { shouldUpdate, versions } = await checkIfThereAreNewVersions(github); if (!shouldUpdate) { console.log('No new versions found. No update required.'); process.exit(0); } else { - const newVersions = await checkForMuslVersionsAndSecurityReleases( - github, - versions, - ); let updatedVersions = []; - for (const [version, newVersion] of Object.entries(newVersions)) { - if (newVersion.muslBuildExists) { - const { stdout } = await exec( - `./update.sh ${newVersion.isSecurityRelease ? '-s ' : ''}${version}`, - ); - console.log(stdout); - updatedVersions.push(newVersion.fullVersion); - } else { - console.log( - `Skipping version ${newVersion.fullVersion} - no musl build available yet.`, - ); - } + for (const [version, newVersion] of Object.entries(versions)) { + const { stdout } = await exec(`./update.sh ${version}`); + console.log(stdout); + updatedVersions.push(newVersion.fullVersion); } if (updatedVersions.length === 0) { diff --git a/update.sh b/update.sh index 23ed1209df..e76eae74ed 100755 --- a/update.sh +++ b/update.sh @@ -8,28 +8,22 @@ function usage() { Update the node docker images. Usage: - $0 [-s] [MAJOR_VERSION(S)] [VARIANT(S)] + $0 [MAJOR_VERSION(S)] [VARIANT(S)] Examples: - update.sh # Update all images - - update.sh -s # Update all images, skip updating Alpine if the musl build is unavailable - update.sh 22,24 # Update all variants of version 22 and 24 - - update.sh -s 24 # Update all variants of version 24, except skip updating Alpine if the musl build is unavailable - update.sh 24 alpine3.23,alpine3.24 # Update only alpine3.23 & alpine3.24 variants for version 24 - update.sh . trixie,trixie-slim # Update only trixie & trixie-slim Debian variants for all versions OPTIONS: - -s Security update; allows Debian updates even if musl build for Alpine is unavailable -h Show this message EOF } -while getopts "sh" opt; do +while getopts "h" opt; do case "${opt}" in - s) - shift - ;; h) usage exit