mirror of
https://github.com/penpot/penpot.git
synced 2026-10-03 01:06:14 +00:00
Penpot only accepts jpeg, png, webp, gif and svg images, so the EXR coder was never used. It was enabled only because ImageMagick's configure auto-detected libopenexr-dev at build time. OpenEXR accounted for 25 CVEs (15 High) in both the exporter and media-processor images, and was also bundled into the backend via /opt/imagick/lib/deps, where dpkg-based scanners cannot see it. - Build ImageMagick with --without-openexr and drop libopenexr-dev - Drop libopenexr-3-1-30 from the imagemagick, backend, exporter, media-processor and devenv images - Remove `apt-get upgrade` from the ImageMagick build stage - Bump penpotapp/imagemagick to 7.1.2-27-1 Signed-off-by: David Barragán Merino <david.barragan@kaleidos.net>
96 lines
2.8 KiB
Docker
96 lines
2.8 KiB
Docker
# syntax=docker/dockerfile:1
|
|
FROM dhi.io/node:24.21.0-debian13-dev
|
|
LABEL maintainer="Penpot <docker@penpot.app>"
|
|
|
|
ENV LANG=en_US.UTF-8 \
|
|
LC_ALL=en_US.UTF-8 \
|
|
DEBIAN_FRONTEND=noninteractive
|
|
|
|
# passwd provides useradd, not preinstalled on the DHI base image.
|
|
RUN set -ex; \
|
|
apt-get -qq update; \
|
|
apt-get -qqy --no-install-recommends install passwd; \
|
|
useradd -U -M -u 1001 -s /bin/false -d /opt/penpot penpot; \
|
|
apt-get -qqy --no-install-recommends install \
|
|
curl \
|
|
tzdata \
|
|
locales \
|
|
ca-certificates \
|
|
; \
|
|
apt-get clean; \
|
|
rm -rf /var/lib/apt/lists/*; \
|
|
echo "en_US.UTF-8 UTF-8" >> /etc/locale.gen; \
|
|
locale-gen; \
|
|
find /usr/share/i18n/locales/ -type f ! -name "en_US" ! -name "POSIX" ! -name "C" -delete;
|
|
|
|
RUN set -ex; \
|
|
apt-get -qq update; \
|
|
apt-get -qqy --no-install-recommends install \
|
|
fontforge \
|
|
woff-tools \
|
|
woff2 \
|
|
\
|
|
libgomp1 \
|
|
libheif1 \
|
|
libjpeg62-turbo \
|
|
liblcms2-2 \
|
|
libopenjp2-7 \
|
|
libpng16-16 \
|
|
librsvg2-2 \
|
|
libtiff6 \
|
|
libwebp7 \
|
|
libwebpdemux2 \
|
|
libwebpmux3 \
|
|
libxml2 \
|
|
libzip5 \
|
|
libzstd1 \
|
|
; \
|
|
apt-get clean; \
|
|
rm -rf /var/lib/apt/lists/*; \
|
|
mkdir -p /opt/penpot; \
|
|
chown -R penpot:penpot /opt/penpot;
|
|
|
|
ARG BUNDLE_PATH="./bundle-media-processor/"
|
|
COPY --chown=penpot:penpot $BUNDLE_PATH /opt/penpot/media-processor/
|
|
|
|
WORKDIR /opt/penpot/media-processor
|
|
|
|
# pnpm ships as a system binary (same tarball + SHA pin as
|
|
# docker/devenv/Dockerfile); ./setup expects it on PATH.
|
|
# Corepack is gone from Node 25+, so nothing here may use it.
|
|
ARG PNPM_VERSION=12.6.0
|
|
RUN set -eux; \
|
|
apt-get -qq update; \
|
|
apt-get -qqy --no-install-recommends install gzip; \
|
|
rm -rf /var/lib/apt/lists/*; \
|
|
ARCH="$(dpkg --print-architecture)"; \
|
|
case "${ARCH}" in \
|
|
aarch64|arm64) \
|
|
PNPM_ARCH='arm64'; \
|
|
PNPM_SHA256='973af2b3eb9509416cf889a7336705062c936407d5fda07298814e7532f5dea1'; \
|
|
;; \
|
|
amd64|x86_64) \
|
|
PNPM_ARCH='x64'; \
|
|
PNPM_SHA256='3f4c66f668d0e84219679982d095b30da68325e1fac9284e7f5dc1584bd3d13e'; \
|
|
;; \
|
|
*) \
|
|
echo "Unsupported arch: ${ARCH}"; \
|
|
exit 1; \
|
|
;; \
|
|
esac; \
|
|
curl -LfsSo /tmp/pnpm.tar.gz "https://github.com/pnpm/pnpm/releases/download/v${PNPM_VERSION}/pnpm-linux-${PNPM_ARCH}.tar.gz"; \
|
|
echo "${PNPM_SHA256} */tmp/pnpm.tar.gz" | sha256sum -c -; \
|
|
mkdir -p /usr/local/bin; \
|
|
tar -xzf /tmp/pnpm.tar.gz -C /usr/local/bin pnpm; \
|
|
chmod 755 /usr/local/bin/pnpm; \
|
|
rm -f /tmp/pnpm.tar.gz; \
|
|
pnpm --version;
|
|
|
|
# Runs as root: this base image installs Node system-wide (symlinked into
|
|
# /usr/bin), so ./setup needs write access there.
|
|
RUN ./setup && chown -R penpot:penpot /opt/penpot/media-processor
|
|
|
|
USER penpot:penpot
|
|
|
|
CMD ["node", "dist/index.js"]
|