From 011acb267a3ebb0a4b45acb259d2ce8e15580569 Mon Sep 17 00:00:00 2001 From: Anton Voylenko Date: Mon, 2 Jun 2025 11:48:05 +0300 Subject: [PATCH] feat: migrate to node 22 --- .github/workflows/pull_request.yml | 2 +- .github/workflows/push.yml | 2 +- Dockerfile | 50 ++++++++++++++++++------------ 3 files changed, 33 insertions(+), 21 deletions(-) diff --git a/.github/workflows/pull_request.yml b/.github/workflows/pull_request.yml index 028b48a..00ce229 100644 --- a/.github/workflows/pull_request.yml +++ b/.github/workflows/pull_request.yml @@ -10,7 +10,7 @@ jobs: strategy: matrix: node-version: - - 18.x + - 22.x steps: - name: Checkout repository uses: actions/checkout@v4 diff --git a/.github/workflows/push.yml b/.github/workflows/push.yml index 7c83945..9625d1f 100644 --- a/.github/workflows/push.yml +++ b/.github/workflows/push.yml @@ -11,7 +11,7 @@ jobs: strategy: matrix: node-version: - - 18.x + - 22.x steps: - name: Checkout repository uses: actions/checkout@v4 diff --git a/Dockerfile b/Dockerfile index 16ae8f3..a7ce3b0 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,32 +1,44 @@ # Use the official Node.js Debian image as the base image -FROM node:18-bookworm-slim +FROM node:22-bookworm-slim AS base -# Set the working directory -WORKDIR /usr/src/app - -# Install ENV CHROME_BIN="/usr/bin/chromium" \ PUPPETEER_SKIP_CHROMIUM_DOWNLOAD="true" \ NODE_ENV="production" -RUN set -x \ - && apt-get update \ - && apt-get install -y --no-install-recommends \ - fonts-freefont-ttf \ - chromium \ - ffmpeg \ - && rm -rf /var/lib/apt/lists/* -# Copy package.json and package-lock.json to the working directory +WORKDIR /usr/src/app + +FROM base AS deps + COPY package*.json ./ -# Install the dependencies RUN npm ci --only=production --ignore-scripts -# Copy the rest of the source code to the working directory -COPY . . +# Create the final stage +FROM base + +# Install system dependencies and create wwebjs user +RUN apt-get update && \ + apt-get install -y --no-install-recommends \ + fonts-freefont-ttf \ + chromium \ + ffmpeg && \ + apt-get clean && \ + rm -rf /var/lib/apt/lists/* && \ + # Create wwebjs user and group with home directory + groupadd -r wwebjs && \ + useradd -r -g wwebjs -m -d /home/wwebjs -s /bin/bash wwebjs && \ + # Give ownership of the working directory to wwebjs user + chown -R wwebjs:wwebjs /usr/src/app + +# Copy only production dependencies from deps stage +COPY --from=deps /usr/src/app/node_modules ./node_modules + +# Copy application code +COPY --chown=wwebjs:wwebjs . . -# Expose the port the API will run on EXPOSE 3000 -# Start the API -CMD ["npm", "start"] \ No newline at end of file +# Use wwebjs user for better security +USER wwebjs + +CMD ["npm", "start"]