diff --git a/CHANGELOG.md b/CHANGELOG.md index 800e72188..cc184ca38 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -30,6 +30,9 @@ All notable changes to this project will be documented in this file. - vector: Build with `--locked` ([#1674]). - nifi: Updated dependencies for `2.6.0` and `2.9.0` ([#1667]). - ci: Bump `stackabletech/actions` to `v0.18.4` ([#1681]). +- java-devel: Pin `versions-maven-plugin` to `2.22.0` for `mvn versions:set`, which otherwise resolves the latest release on every build unless the product POM pins it ([#1682]). +- airflow, druid, hbase, nifi, opensearch-dashboards, superset, trino: Install global npm packages (cdxgen, pnpm, yarn, npm) with `--ignore-scripts`, and only resolve versions that were published at least 7 days ago (`--before`) ([#1682]). +- superset: Pin npm to `10.9.9` instead of installing the latest version with `nvm install --latest-npm` ([#1682]). ### Fixed @@ -113,6 +116,7 @@ All notable changes to this project will be documented in this file. [#1676]: https://github.com/stackabletech/docker-images/pull/1676 [#1677]: https://github.com/stackabletech/docker-images/pull/1677 [#1681]: https://github.com/stackabletech/docker-images/pull/1681 +[#1682]: https://github.com/stackabletech/docker-images/pull/1682 ## [26.7.0] - 2026-07-21 diff --git a/airflow/Dockerfile b/airflow/Dockerfile index 87bb30dee..524c73f54 100644 --- a/airflow/Dockerfile +++ b/airflow/Dockerfile @@ -130,7 +130,10 @@ ARCH="${TARGETARCH/amd64/x64}" mkdir -p /opt/node-cdxgen curl "https://repo.stackable.tech/repository/packages/node/node-v${CDXGEN_NODEJS_VERSION}-linux-${ARCH}.tar.xz" | \ tar --extract --xz --directory=/opt/node-cdxgen --strip-components=1 -PATH="/opt/node-cdxgen/bin:$PATH" npm install --global "@cdxgen/cdxgen@${CDXGEN_VERSION}" +# --ignore-scripts keeps the install scripts of (transitive) dependencies from running. +# --before only resolves versions published at least 7 days ago, including the transitive ones, +# so that a freshly published malicious version is not picked up before it is taken down. +PATH="/opt/node-cdxgen/bin:$PATH" npm install --global --ignore-scripts --before="$(date --utc --date='-7 days' --iso-8601=seconds)" "@cdxgen/cdxgen@${CDXGEN_VERSION}" EOF COPY airflow/stackable/constraints/${PRODUCT_VERSION}/constraints-python${PYTHON_VERSION}.txt /tmp/constraints.txt @@ -180,7 +183,10 @@ if [ -d "./airflow-core" ]; then # build front-end assets # TODO: Consider making the pnpm version an ARG - npm install -g pnpm@10.18.2 + # --ignore-scripts keeps the install scripts of (transitive) dependencies from running. + # --before only resolves versions published at least 7 days ago, including the transitive ones, + # so that a freshly published malicious version is not picked up before it is taken down. + npm install -g --ignore-scripts --before="$(date --utc --date='-7 days' --iso-8601=seconds)" pnpm@10.18.2 pnpm install --frozen-lockfile pnpm run build @@ -212,7 +218,10 @@ else # build front-end assets cd airflow/www # TODO: Consider making the yarn version an ARG - npm install -g yarn@1.22.22 + # --ignore-scripts keeps the install scripts of (transitive) dependencies from running. + # --before only resolves versions published at least 7 days ago, including the transitive ones, + # so that a freshly published malicious version is not picked up before it is taken down. + npm install -g --ignore-scripts --before="$(date --utc --date='-7 days' --iso-8601=seconds)" yarn@1.22.22 yarn install --frozen-lockfile yarn run build diff --git a/druid/Dockerfile b/druid/Dockerfile index adbbb6bb0..384375083 100644 --- a/druid/Dockerfile +++ b/druid/Dockerfile @@ -48,7 +48,10 @@ ARCH="${TARGETARCH/amd64/x64}" mkdir -p /opt/node-cdxgen curl "https://repo.stackable.tech/repository/packages/node/node-v${CDXGEN_NODEJS_VERSION}-linux-${ARCH}.tar.xz" | \ tar --extract --xz --directory=/opt/node-cdxgen --strip-components=1 -PATH="/opt/node-cdxgen/bin:$PATH" npm install --global "@cdxgen/cdxgen@${CDXGEN_VERSION}" +# --ignore-scripts keeps the install scripts of (transitive) dependencies from running. +# --before only resolves versions published at least 7 days ago, including the transitive ones, +# so that a freshly published malicious version is not picked up before it is taken down. +PATH="/opt/node-cdxgen/bin:$PATH" npm install --global --ignore-scripts --before="$(date --utc --date='-7 days' --iso-8601=seconds)" "@cdxgen/cdxgen@${CDXGEN_VERSION}" EOF USER ${STACKABLE_USER_UID} @@ -80,7 +83,7 @@ rm /tmp/DRUID_SOURCE_DIR ORIGINAL_VERSION=$(mvn help:evaluate -Dexpression=project.version -q -DforceStdout) NEW_VERSION="${PRODUCT_VERSION}-stackable${RELEASE_VERSION}" -mvn versions:set -DnewVersion=$NEW_VERSION +mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION # Make Maven aware of custom Stackable libraries cp -r /stackable/patched-libs/maven/* /stackable/.m2/repository diff --git a/hadoop/hadoop/Dockerfile b/hadoop/hadoop/Dockerfile index de701628a..e2fd1b2fe 100644 --- a/hadoop/hadoop/Dockerfile +++ b/hadoop/hadoop/Dockerfile @@ -83,7 +83,7 @@ cd "$(/stackable/patchable --images-repo-root=src checkout hadoop/hadoop ${PRODU ORIGINAL_VERSION=$(mvn help:evaluate -Dexpression=project.version -q -DforceStdout) NEW_VERSION=${PRODUCT_VERSION}-stackable${RELEASE_VERSION} -mvn versions:set -DnewVersion=${NEW_VERSION} +mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=${NEW_VERSION} # Since we skip building the hadoop-pipes module, we need to set the version to the original version so it can be pulled from Maven Central sed -e '/hadoop-pipes<\/artifactId>/,/<\/dependency>/ { s/.*<\/version>/'"$ORIGINAL_VERSION"'<\/version>/ }' -i hadoop-tools/hadoop-tools-dist/pom.xml diff --git a/hbase/hbase-operator-tools/Dockerfile b/hbase/hbase-operator-tools/Dockerfile index 62e487346..d5ba5ad34 100644 --- a/hbase/hbase-operator-tools/Dockerfile +++ b/hbase/hbase-operator-tools/Dockerfile @@ -46,7 +46,7 @@ NEW_VERSION="${HBASE_OPERATOR_TOOLS_VERSION}-stackable${RELEASE_VERSION}" FULL_HBASE_OPERATOR_TOOLS_VERSION="${PRODUCT_VERSION}-stackable${RELEASE_VERSION}" # This includes the HBase version and the Stackable release suffix PATCHED_HBASE_VERSION="${HBASE_VERSION}-stackable${RELEASE_VERSION}" -mvn versions:set -DnewVersion=$NEW_VERSION +mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION # Create snapshot of the source code including custom patches tar -czf /stackable/hbase-operator-tools-${FULL_HBASE_OPERATOR_TOOLS_VERSION}-src.tar.gz . diff --git a/hbase/hbase/Dockerfile b/hbase/hbase/Dockerfile index 899accc9e..4044b3af9 100644 --- a/hbase/hbase/Dockerfile +++ b/hbase/hbase/Dockerfile @@ -32,7 +32,10 @@ ARCH="${TARGETARCH/amd64/x64}" mkdir -p /opt/node-cdxgen curl "https://repo.stackable.tech/repository/packages/node/node-v${CDXGEN_NODEJS_VERSION}-linux-${ARCH}.tar.xz" | \ tar --extract --xz --directory=/opt/node-cdxgen --strip-components=1 -PATH="/opt/node-cdxgen/bin:$PATH" npm install --global "@cdxgen/cdxgen@${CDXGEN_VERSION}" +# --ignore-scripts keeps the install scripts of (transitive) dependencies from running. +# --before only resolves versions published at least 7 days ago, including the transitive ones, +# so that a freshly published malicious version is not picked up before it is taken down. +PATH="/opt/node-cdxgen/bin:$PATH" npm install --global --ignore-scripts --before="$(date --utc --date='-7 days' --iso-8601=seconds)" "@cdxgen/cdxgen@${CDXGEN_VERSION}" microdnf update microdnf install python3 @@ -70,7 +73,7 @@ cp -r /stackable/patched-libs/maven/* /stackable/.m2/repository ORIGINAL_VERSION=$(mvn help:evaluate -Dexpression=project.version -q -DforceStdout) NEW_VERSION="${PRODUCT_VERSION}-stackable${RELEASE_VERSION}" -mvn versions:set -DnewVersion=$NEW_VERSION +mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION # Create snapshot of the source code including custom patches tar -czf /stackable/hbase-${NEW_VERSION}-src.tar.gz . diff --git a/hbase/phoenix/Dockerfile b/hbase/phoenix/Dockerfile index 468f5a43c..b07b32154 100644 --- a/hbase/phoenix/Dockerfile +++ b/hbase/phoenix/Dockerfile @@ -38,7 +38,7 @@ cd "$(/stackable/patchable --images-repo-root=src checkout phoenix ${PHOENIX_VER ORIGINAL_VERSION=$(mvn help:evaluate -Dexpression=project.version -q -DforceStdout) NEW_VERSION="${PHOENIX_VERSION}-stackable${RELEASE_VERSION}" -mvn versions:set -DnewVersion=$NEW_VERSION +mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION # Create snapshot of the source code including custom patches tar -czf /stackable/phoenix-${PRODUCT_VERSION}-stackable${RELEASE_VERSION}-src.tar.gz . diff --git a/hive/Dockerfile b/hive/Dockerfile index ee1398ab7..2e22ac19e 100644 --- a/hive/Dockerfile +++ b/hive/Dockerfile @@ -54,7 +54,7 @@ cd "$BUILD_SRC_DIR" cp -r /stackable/patched-libs/maven/* /stackable/.m2/repository # generateBackupPoms=false is needed for the Hive 4.0.0 build to succeed, otherwise it fails with the obscure reason: `Too many files with unapproved license` -mvn versions:set -DnewVersion=$NEW_VERSION -DartifactId=* -DgroupId=* -DgenerateBackupPoms=false +mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION -DartifactId=* -DgroupId=* -DgenerateBackupPoms=false # Create snapshot of the source code including custom patches tar -czf /stackable/hive-${NEW_VERSION}-src.tar.gz . diff --git a/hive/hive-metastore-opa-authorizer/Dockerfile b/hive/hive-metastore-opa-authorizer/Dockerfile index 63e2f95ae..32259e761 100644 --- a/hive/hive-metastore-opa-authorizer/Dockerfile +++ b/hive/hive-metastore-opa-authorizer/Dockerfile @@ -41,7 +41,7 @@ tar -czf /stackable/opa-authorizer-src/hive-metastore-opa-authorizer-${AUTHORIZE cp -r /stackable/patched-libs/maven/* /stackable/.m2/repository # Set version -mvn versions:set -DnewVersion=${AUTHORIZER_VERSION} +mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=${AUTHORIZER_VERSION} # The if part can be removed once we do no longer support Hive 3.x.x # Hive 3.1.3 only works with the shaded jar diff --git a/java-devel/Dockerfile b/java-devel/Dockerfile index 3530f6568..fdc17cdd9 100644 --- a/java-devel/Dockerfile +++ b/java-devel/Dockerfile @@ -68,6 +68,12 @@ EOF ENV JAVA_HOME="/usr/lib/jvm/temurin-${PRODUCT_VERSION}-jdk" ENV MAVEN_ARGS="--batch-mode --no-transfer-progress" +# Plugins that are invoked by prefix on the command line (e.g. `mvn versions:set`) resolve to their +# latest release unless the project POM pins them, so their version would change silently between builds. +# Find the latest version here: https://github.com/mojohaus/versions/releases +# renovate: datasource=maven packageName=org.codehaus.mojo:versions-maven-plugin +ENV VERSIONS_MAVEN_PLUGIN_VERSION="2.22.0" + ARG GITHUB_RUN_ATTEMPT="" ENV GITHUB_RUN_ATTEMPT=${GITHUB_RUN_ATTEMPT} diff --git a/nifi/Dockerfile b/nifi/Dockerfile index 06e133a24..b2f1aa22c 100644 --- a/nifi/Dockerfile +++ b/nifi/Dockerfile @@ -32,7 +32,10 @@ ARCH="${TARGETARCH/amd64/x64}" mkdir -p /opt/node-cdxgen curl "https://repo.stackable.tech/repository/packages/node/node-v${CDXGEN_NODEJS_VERSION}-linux-${ARCH}.tar.xz" | \ tar --extract --xz --directory=/opt/node-cdxgen --strip-components=1 -PATH="/opt/node-cdxgen/bin:$PATH" npm install --global "@cdxgen/cdxgen@${CDXGEN_VERSION}" +# --ignore-scripts keeps the install scripts of (transitive) dependencies from running. +# --before only resolves versions published at least 7 days ago, including the transitive ones, +# so that a freshly published malicious version is not picked up before it is taken down. +PATH="/opt/node-cdxgen/bin:$PATH" npm install --global --ignore-scripts --before="$(date --utc --date='-7 days' --iso-8601=seconds)" "@cdxgen/cdxgen@${CDXGEN_VERSION}" EOF USER ${STACKABLE_USER_UID} @@ -56,7 +59,7 @@ cd "$(/stackable/patchable --images-repo-root=src checkout nifi ${PRODUCT_VERSIO ORIGINAL_VERSION=$(mvn help:evaluate -Dexpression=project.version -q -DforceStdout) NEW_VERSION="${PRODUCT_VERSION}-stackable${RELEASE_VERSION}" -mvn versions:set -DnewVersion=$NEW_VERSION +mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION # Create snapshot of the source code including custom patches tar -czf /stackable/nifi-${NEW_VERSION}-src.tar.gz . diff --git a/omid/Dockerfile b/omid/Dockerfile index af261ca7d..7493ccbc0 100644 --- a/omid/Dockerfile +++ b/omid/Dockerfile @@ -32,7 +32,7 @@ RUN --mount=type=cache,id=maven-omid-${PRODUCT_VERSION},uid=${STACKABLE_USER_UID ORIGINAL_VERSION=$(mvn help:evaluate -Dexpression=project.version -q -DforceStdout) NEW_VERSION="${PRODUCT_VERSION}-stackable${RELEASE_VERSION}" - mvn versions:set -DnewVersion=$NEW_VERSION + mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION # Create snapshot of the source code including custom patches tar -czf /stackable/omid-${NEW_VERSION}-src.tar.gz . diff --git a/opensearch-dashboards/Dockerfile b/opensearch-dashboards/Dockerfile index 0f258802c..e5912d930 100644 --- a/opensearch-dashboards/Dockerfile +++ b/opensearch-dashboards/Dockerfile @@ -141,7 +141,10 @@ microdnf clean all rm -rf /var/cache/yum curl "https://repo.stackable.tech/repository/packages/node/node-v${NODEJS_VERSION}-linux-${ARCH}.tar.xz" | \ tar --extract --xz --directory=/usr/local --strip-components=1 -npm install -g yarn@${YARN_VERSION} +# --ignore-scripts keeps the install scripts of (transitive) dependencies from running. +# --before only resolves versions published at least 7 days ago, including the transitive ones, +# so that a freshly published malicious version is not picked up before it is taken down. +npm install -g --ignore-scripts --before="$(date --utc --date='-7 days' --iso-8601=seconds)" yarn@${YARN_VERSION} # cdxgen requires Node >= 24, which is newer than the Node version OpenSearch Dashboards # is built with, so it gets its own Node installation in /opt/node-cdxgen and is invoked @@ -150,7 +153,10 @@ npm install -g yarn@${YARN_VERSION} mkdir -p /opt/node-cdxgen curl "https://repo.stackable.tech/repository/packages/node/node-v${CDXGEN_NODEJS_VERSION}-linux-${ARCH}.tar.xz" | \ tar --extract --xz --directory=/opt/node-cdxgen --strip-components=1 -PATH="/opt/node-cdxgen/bin:$PATH" npm install --global "@cdxgen/cdxgen@${CDXGEN_VERSION}" +# --ignore-scripts keeps the install scripts of (transitive) dependencies from running. +# --before only resolves versions published at least 7 days ago, including the transitive ones, +# so that a freshly published malicious version is not picked up before it is taken down. +PATH="/opt/node-cdxgen/bin:$PATH" npm install --global --ignore-scripts --before="$(date --utc --date='-7 days' --iso-8601=seconds)" "@cdxgen/cdxgen@${CDXGEN_VERSION}" EOF USER ${STACKABLE_USER_UID} diff --git a/precompiled/hadoop/Dockerfile b/precompiled/hadoop/Dockerfile index 396d20297..2c147db93 100644 --- a/precompiled/hadoop/Dockerfile +++ b/precompiled/hadoop/Dockerfile @@ -61,7 +61,7 @@ cd "$(/stackable/patchable --images-repo-root=src checkout precompiled/hadoop ${ ORIGINAL_VERSION=$(mvn help:evaluate -Dexpression=project.version -q -DforceStdout) NEW_VERSION=${PRODUCT_VERSION}-stackable${RELEASE_VERSION} -mvn versions:set -DnewVersion=${NEW_VERSION} +mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=${NEW_VERSION} # Since we skip building the hadoop-pipes module, we need to set the version to the original version so it can be pulled from Maven Central sed -e '/hadoop-pipes<\/artifactId>/,/<\/dependency>/ { s/.*<\/version>/'"$ORIGINAL_VERSION"'<\/version>/ }' -i hadoop-tools/hadoop-tools-dist/pom.xml diff --git a/spark-k8s/Dockerfile.3 b/spark-k8s/Dockerfile.3 index ade35e6c9..93c056950 100644 --- a/spark-k8s/Dockerfile.3 +++ b/spark-k8s/Dockerfile.3 @@ -24,7 +24,7 @@ cd "$(/stackable/patchable --images-repo-root=src checkout spark-k8s ${PRODUCT_V NEW_VERSION="${PRODUCT_VERSION}-stackable${RELEASE_VERSION}" -mvn versions:set -DnewVersion=$NEW_VERSION +mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION # Create snapshot of the source code including custom patches tar -czf /stackable/spark-${PRODUCT_VERSION}-stackable${RELEASE_VERSION}-src.tar.gz . diff --git a/spark-k8s/Dockerfile.4 b/spark-k8s/Dockerfile.4 index f42b90034..d90b9855a 100644 --- a/spark-k8s/Dockerfile.4 +++ b/spark-k8s/Dockerfile.4 @@ -21,7 +21,7 @@ cd "$(/stackable/patchable --images-repo-root=src checkout spark-k8s ${PRODUCT_V NEW_VERSION="${PRODUCT_VERSION}-stackable${RELEASE_VERSION}" -mvn versions:set -DnewVersion=$NEW_VERSION +mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION # Create snapshot of the source code including custom patches tar -czf /stackable/spark-${PRODUCT_VERSION}-stackable${RELEASE_VERSION}-src.tar.gz . diff --git a/spark-k8s/hbase-connectors/Dockerfile b/spark-k8s/hbase-connectors/Dockerfile index 2e11e56c5..8d20f9159 100644 --- a/spark-k8s/hbase-connectors/Dockerfile +++ b/spark-k8s/hbase-connectors/Dockerfile @@ -78,7 +78,7 @@ cd "$(/stackable/patchable --images-repo-root=src checkout spark-k8s/hbase-conne NEW_VERSION="${PRODUCT_VERSION}-stackable${RELEASE_VERSION}" -mvn versions:set -DnewVersion=$NEW_VERSION +mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION # Create snapshot of the source code including custom patches tar -czf /stackable/hbase-connector-${NEW_VERSION}-src.tar.gz . diff --git a/superset/Dockerfile b/superset/Dockerfile index 862316ad3..64521ad76 100644 --- a/superset/Dockerfile +++ b/superset/Dockerfile @@ -46,6 +46,7 @@ ARG CDXGEN_NODEJS_VERSION ARG CDXGEN_SPEC_VERSION ARG UV_VERSION ARG NODEJS_VERSION +ARG NPM_VERSION ARG NVM_VERSION ARG STACKABLE_USER_UID @@ -101,8 +102,11 @@ mkdir -p "${NVM_DIR}" curl "https://repo.stackable.tech/repository/packages/nvm/nvm-${NVM_VERSION}.sh" -o "${NVM_DIR}/nvm.sh" . "${NVM_DIR}/nvm.sh" -# Install the specified version of Node (including the latest compatible version of npm) -nvm install "$NODEJS_VERSION" --latest-npm +# Install the specified versions of Node and npm. +# --latest-npm is not used because it installs whatever npm version is newest at build time. +# See the cdxgen install below for --ignore-scripts and --before. +nvm install "$NODEJS_VERSION" +npm install --global --ignore-scripts --before="$(date --utc --date='-7 days' --iso-8601=seconds)" "npm@${NPM_VERSION}" node --version npm --version @@ -117,7 +121,10 @@ ARCH="${TARGETARCH/amd64/x64}" mkdir -p /opt/node-cdxgen curl "https://repo.stackable.tech/repository/packages/node/node-v${CDXGEN_NODEJS_VERSION}-linux-${ARCH}.tar.xz" | \ tar --extract --xz --directory=/opt/node-cdxgen --strip-components=1 -PATH="/opt/node-cdxgen/bin:$PATH" npm install --global "@cdxgen/cdxgen@${CDXGEN_VERSION}" +# --ignore-scripts keeps the install scripts of (transitive) dependencies from running. +# --before only resolves versions published at least 7 days ago, including the transitive ones, +# so that a freshly published malicious version is not picked up before it is taken down. +PATH="/opt/node-cdxgen/bin:$PATH" npm install --global --ignore-scripts --before="$(date --utc --date='-7 days' --iso-8601=seconds)" "@cdxgen/cdxgen@${CDXGEN_VERSION}" EOF # Upgrade pip to the latest version diff --git a/superset/boil-config.toml b/superset/boil-config.toml index 5a0dd78f0..70b019d7a 100644 --- a/superset/boil-config.toml +++ b/superset/boil-config.toml @@ -28,6 +28,8 @@ python-version = "3.11" uv-version = "0.11.18" # https://github.com/apache/superset/blob/4.1.4/superset-frontend/.nvmrc nodejs-version = "18.20.1" +# The latest 10.x release. 11.x requires Node ^20.17.0 || >=22.9.0. +npm-version = "10.9.9" # Independent of Superset, use the latest release: https://github.com/nvm-sh/nvm/releases nvm-version = "v0.40.4" @@ -58,5 +60,8 @@ python-version = "3.12" uv-version = "0.11.18" # https://github.com/apache/superset/blob/6.1.0/superset-frontend/.nvmrc nodejs-version = "22.22.0" +# npm 12 requires Node ^22.22.2, so the latest npm (which --latest-npm used to install) is not +# supported on this Node version. Kept on 10.x like 4.1.4, which is the version Node 22 bundles. +npm-version = "10.9.9" # Independent of Superset, use the latest release: https://github.com/nvm-sh/nvm/releases nvm-version = "v0.40.4" diff --git a/trino/airlift/Dockerfile b/trino/airlift/Dockerfile index 1858a032a..f27e66a9d 100644 --- a/trino/airlift/Dockerfile +++ b/trino/airlift/Dockerfile @@ -21,7 +21,7 @@ cd "$(/stackable/patchable --images-repo-root=src checkout trino/airlift ${PRODU NEW_VERSION="${PRODUCT_VERSION}-stackable${RELEASE_VERSION}" -mvn versions:set -DnewVersion=$NEW_VERSION -DartifactId='*' -DgroupId='*' -DgenerateBackupPoms=false +mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION -DartifactId='*' -DgroupId='*' -DgenerateBackupPoms=false mvn \ install \ diff --git a/trino/storage-connector/Dockerfile b/trino/storage-connector/Dockerfile index 0156405e6..9a0bcd851 100644 --- a/trino/storage-connector/Dockerfile +++ b/trino/storage-connector/Dockerfile @@ -30,7 +30,7 @@ NEW_VERSION="${PRODUCT_VERSION}-stackable${RELEASE_VERSION}" # Create snapshot of the source code including custom patches tar -czf /stackable/trino-storage-connector-${NEW_VERSION}-src.tar.gz . -mvn versions:set -DnewVersion=${NEW_VERSION} +mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=${NEW_VERSION} mvn \ package \ diff --git a/trino/trino/Dockerfile b/trino/trino/Dockerfile index 1e234adc3..10bca7fa2 100644 --- a/trino/trino/Dockerfile +++ b/trino/trino/Dockerfile @@ -30,7 +30,10 @@ ARCH="${TARGETARCH/amd64/x64}" mkdir -p /opt/node-cdxgen curl "https://repo.stackable.tech/repository/packages/node/node-v${CDXGEN_NODEJS_VERSION}-linux-${ARCH}.tar.xz" | \ tar --extract --xz --directory=/opt/node-cdxgen --strip-components=1 -PATH="/opt/node-cdxgen/bin:$PATH" npm install --global "@cdxgen/cdxgen@${CDXGEN_VERSION}" +# --ignore-scripts keeps the install scripts of (transitive) dependencies from running. +# --before only resolves versions published at least 7 days ago, including the transitive ones, +# so that a freshly published malicious version is not picked up before it is taken down. +PATH="/opt/node-cdxgen/bin:$PATH" npm install --global --ignore-scripts --before="$(date --utc --date='-7 days' --iso-8601=seconds)" "@cdxgen/cdxgen@${CDXGEN_VERSION}" microdnf update microdnf install python3 @@ -51,7 +54,7 @@ cp -r /stackable/patched-libs/maven/* /root/.m2/repository NEW_VERSION="${PRODUCT_VERSION}-stackable${RELEASE_VERSION}" -mvn versions:set -DnewVersion=$NEW_VERSION +mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION # Create snapshot of the source code including custom patches tar -czf /stackable/trino-${NEW_VERSION}-src.tar.gz . diff --git a/zookeeper/Dockerfile b/zookeeper/Dockerfile index e0ed9e4a1..b69fd63ac 100644 --- a/zookeeper/Dockerfile +++ b/zookeeper/Dockerfile @@ -33,7 +33,7 @@ cd "$(/stackable/patchable --images-repo-root=src checkout zookeeper ${PRODUCT_V ORIGINAL_VERSION=$(mvn help:evaluate -Dexpression=project.version -q -DforceStdout) NEW_VERSION="${PRODUCT_VERSION}-stackable${RELEASE_VERSION}" -mvn versions:set -DnewVersion=$NEW_VERSION +mvn "org.codehaus.mojo:versions-maven-plugin:${VERSIONS_MAVEN_PLUGIN_VERSION}:set" -DnewVersion=$NEW_VERSION # Create snapshot of the source code including custom patches tar -czf /stackable/zookeeper-${NEW_VERSION}-src.tar.gz .