Skip to content

[NEXT-SECURITY-RELEASE] Heads up on upcoming Node.js security release 2025/12/15 #2330

Description

@marco-ippolito

As per security release workflow, creating issue to give the docker team a heads up.

Activity

  1. MikeMcC399 commented on Jan 9, 2026

    @MikeMcC399
    Contributor

    @marco-ippolito

    The security release has been delayed multiple times so that it is now going to be almost one month late (see https://nodejs.org/en/blog/vulnerability/december-2025-security-releases).

    Will the release only address the security issues mentioned or it is going to include also other commits, such as an update to the version of npm?

  2. marco-ippolito commented on Jan 9, 2026

    @marco-ippolito
    MemberAuthor

    It will include a few more commits

  3. RafaelGSS commented on Jan 13, 2026

    @RafaelGSS
    Member

    Security release is now available.

  4. adrianvaillant commented on Jan 13, 2026

    @adrianvaillant

    Will all of the supported images be updated rather soon? I kind of expected to have the new images by the time it got public to update immediately but it seems its not the case yet

  5. marco-ippolito commented on Jan 13, 2026

    @marco-ippolito
    MemberAuthor

    Security release is out

  6. latentflip commented on Jan 13, 2026

    @latentflip

    Also waiting for the builds to be updated in docker and surprised they aren't there. I have no idea how this process works, but it looks like the action that opens the automated PR with the updates is getting blocked by the fact that the latest versions don't have a "musl" release yet on https://unofficial-builds.nodejs.org/download/release/index.json.

    Image

    Maybe that's just normal and something that takes time? The fact it's "unofficial" makes me wonder though if a step has been missed? Or do we just have to wait?

  7. takumi0706 commented on Jan 13, 2026

    @takumi0706

    @latentflip You're right - unofficial-builds is missing the musl builds for this security release.

    Version Official unofficial-builds
    v20 20.20.0 20.19.6
    v22 22.22.0 22.21.1
    v24 24.13.0 24.12.0
    v25 25.3.0 25.3.0 ✓

    I've opened nodejs/unofficial-builds#199 to request the missing builds.

  8. MikeMcC399 commented on Jan 13, 2026

    @MikeMcC399
    Contributor

    Would it be possible, in general and for future releases, to de-couple the release of official builds from unofficial builds, so that releasing official builds is never held up because of problems with prerequisites for unofficial builds?

    https://github.com/nodejs/unofficial-builds/ links to https://unofficial-builds.nodejs.org/ and shows:

    Image
  9. switz commented on Jan 13, 2026

    @switz

    Yeah, this really needs to be cut alongside the release if possible - many people deploy to production on these images. There should be coordination here.

  10. yzhe554 commented on Jan 14, 2026

    @yzhe554

    @latentflip You're right - unofficial-builds is missing the musl builds for this security release.

    Version Official unofficial-builds
    v20 20.20.0 20.19.6
    v22 22.22.0 22.21.1
    v24 24.13.0 24.12.0
    v25 25.3.0 25.3.0 ✓

    I've opened nodejs/unofficial-builds#199 to request the missing builds.

    25.3.0 and 22.22.0 have done. It's building 20.20.0 now

  11. mdavidsen commented on Jan 14, 2026

    @mdavidsen

    It looks like v24 is being built right now. Everything else has finished.

    20.20 is still building, and 24 is still not started according to https://unofficial-builds.nodejs.org/logs/

  12. Diesmon commented on Jan 14, 2026

    @Diesmon
    Contributor

    Can someone point me to documentation that explains the rough workflow for a new docker NodeJS release so I can understand this unofficial/official build problem better?

    Because I'm a bit shocked to learn that NodeJS docker images are not available for around 24h after CVE fixes got released + the big blog entry dropped that urges to update ASAP.

    I would have assumed that the docker images are published either together or a few hours after the binaries dropped, as they are understandably needed for the docker images themselves.

  13. loganaden commented on Jan 14, 2026

    @loganaden

    A lot of apps are still on 20 LTS releases.

  14. ItsHarta commented on Jan 14, 2026

    @ItsHarta

    Can someone point me to documentation that explains the rough workflow for a new docker NodeJS release so I can understand this unofficial/official build problem better?

    Because I'm a bit shocked to learn that NodeJS docker images are not available for around 24h after CVE fixes got released + the big blog entry dropped that urges to update ASAP.

    I would have assumed that the docker images are published either together or a few hours after the binaries dropped, as they are understandably needed for the docker images themselves.

    Code is inspectable in this repo, nodejs/docker-node/build-automation.mjs. to put it short, the -alpine variant requires MUSL build from the unofficial repo. If for some reason this MUSL build does not exist for that version (e.g., 22.x), all variants of that version is deferred/skipped (this includes all debian & debian-slim). This is probably to prevent the split-version scenario (e.g., 22-alpine points to 22.21.1 while 22-trixie points to 22.22.0)

    The unofficial build is slow and sequential. as of now 20.20 is still running and 24.13 is in queue

  15. bmuenzenmeyer commented on Jan 14, 2026

    @bmuenzenmeyer
    Contributor

    Can someone point me to documentation that explains the rough workflow for a new docker NodeJS release so I can understand this unofficial/official build problem better?

    I opened #2345

    edit (my two cents as a website maintainer):

    Because I'm a bit shocked to learn that NodeJS docker images are not available for around 24h after CVE fixes got released + the big blog entry dropped that urges to update ASAP.

    I would have assumed that the docker images are published either together or a few hours after the binaries dropped, as they are understandably needed for the docker images themselves.

    Glad there is recognition of chicken and egg here. Yes, there will always be a critical path of infrastructure that coincides with any release. They stack up then when a security event creates four. I suppose the blog post could wait until after docker is ready, but then we are not communicating availability. On balance, that might be better, given the creation of urgency in the current sequencing. I've shared this feedback and thread with a broader team.

  16. 7 remaining items

  17. adrianvaillant commented on Jan 14, 2026

    @adrianvaillant

    Ahh all right, thanks for clarifying!

  18. mcollina commented on Jan 14, 2026

    @mcollina
    SponsorMember

    @MikeMcC399 Can you create an issue describing the workflow you'd like to see in #2330 (comment)? I think that should be certainly doable (I don't want to take attribution for the idea). Otherwise let us know and we'll create.

  19. MikeMcC399 commented on Jan 14, 2026

    @MikeMcC399
    Contributor

    @mcollina

    Can you create an issue describing the workflow you'd like to see in #2330 (comment)? I think that should be certainly doable (I don't want to take attribution for the idea). Otherwise let us know and we'll create.

    You're right that this should be separated out from this issue which is about the current security release only.

    I would be far happier if somebody from the core team picked this up, as I don't have in-depth experience and understanding of how this all fits together. I'm not worried at all about attribution!

  20. adityapatadia commented on Jan 14, 2026

    @adityapatadia

    It's more than 24 hours since the build started. I don't want to point fingers and show problems so can someone tell us how can we help make this fast going ahead? My company can give coding help or money to get faster servers.

  21. hmaesta commented on Jan 14, 2026

    @hmaesta

    FYI, it appears all Node versions released yesterday were built and are already available (including v25.3.0)

  22. loganaden commented on Jan 14, 2026

    @loganaden

    not all of them are available on dockerhub. i can't see the alpine ones ?

  23. hmaesta commented on Jan 14, 2026

    @hmaesta

    Yup... Too soon! (Sorry!)

    I just tried building the image and got a 404.

    ERROR: failed to build: failed to solve: node:25.3.0-alpine: failed to resolve source metadata for docker.io/library/node:25.3.0-alpine: docker.io/library/node:25.3.0-alpine: not found

  24. rubnogueira commented on Jan 14, 2026

    @rubnogueira

    FYI, it appears all Node versions released yesterday were built and are already available (including v25.3.0)

    That is not true:

    docker run -it --rm node:slim /bin/sh
    
    Unable to find image 'node:slim' locally
    slim: Pulling from library/node
    33bdc9671af8: Pull complete
    ff1919949b44: Pull complete
    2a8ab26d914b: Pull complete
    32c46bf3d096: Pull complete
    25398888c8f8: Pull complete
    Digest: sha256:9b0d2dd3a55e1d10c1b17f0d1e8835b04965c7251ad65de0df67252d4a6f0159
    Status: Downloaded newer image for node:slim
    
    # node -v
    v25.2.1
    
    
  25. danpasecinic commented on Jan 14, 2026

    @danpasecinic

    They have just pushed all images.

  26. nschonni commented on Jan 14, 2026

    @nschonni
    Member

    https://hub.docker.com/_/node/tags appear to be there now, so closing

  27. heydonovan commented on Jan 14, 2026

    @heydonovan

    I'm not seeing 20.20.0 for node:20-trixie-slim

    λ docker run --pull=always -it --entrypoint=/bin/bash node:20-trixie-slim
    20-trixie-slim: Pulling from library/node
    Digest: sha256:82dc9bc5be425c01adeaf315b0b54bcf5dd3d75d6a6ebb69906590439e3b5a10
    Status: Image is up to date for node:20-trixie-slim
    root@f04afff0afa8:/# node --version
    v20.19.6
    root@f04afff0afa8:/# env | grep NODE_VERSION
    NODE_VERSION=20.19.6
    

    It works for node:20

    λ docker run --pull=always -it --entrypoint=/bin/bash node:20
    20: Pulling from library/node
    Digest: sha256:d27ddcc66c7a184e7d5023fe77c853f4b4f9292c3a2a65ff8378ff273edae9d3
    Status: Image is up to date for node:20
    root@fcfa3605c329:/# node --version
    v20.20.0
    root@fcfa3605c329:/# env | grep NODE_VERSION
    NODE_VERSION=20.20.0
    
  28. kisaiev commented on Jan 14, 2026

    @kisaiev

    Regarding above, it seems that 20.20.0-trixie-slim is only available on linux/amd64, refer https://hub.docker.com/_/node/tags?name=20.20-trixie

    ❯ docker run --rm -ti --platform=linux/amd64 node:20.20.0-trixie-slim node -v
    v20.20.0
    
  29. heydonovan commented on Jan 14, 2026

    @heydonovan

    Confirmed! Thank you!

    λ docker run --platform=linux/amd64 --pull=always -it --entrypoint=/bin/bash node:20-trixie-slim
    20-trixie-slim: Pulling from library/node
    Digest: sha256:82dc9bc5be425c01adeaf315b0b54bcf5dd3d75d6a6ebb69906590439e3b5a10
    Status: Image is up to date for node:20-trixie-slim
    root@85a4afd53c5f:/# node --version
    v20.20.0
    
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions