Base sandbox build broken: NodeSource yanked pinned Node.js 22.22.1 package

Open
#56 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
3/5
Estimated time
1-2 days
Newbie friendliness
68/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Quiet
Tech stack
docker, github-actions, node.js

Research direction

Start with sandboxes/base/Dockerfile at line 61 and the Build Sandbox Images workflow, then reproduce the failed build to confirm the unavailable NodeSource pin. Compare the proposed installation approaches and verify that the chosen approach builds the base sandbox image successfully without depending on the missing package version.

Written by the indexing model from the issue text.

Description

Summary

The Build Sandbox Images workflow is failing because NodeSource removed nodejs=22.22.1-1nodesource1 from their apt repository. The base sandbox Dockerfile pins this exact version at line 61, causing the Docker build to fail with:

E: Version '22.22.1-1nodesource1' for 'nodejs' was not found

Failed run: https://github.com/NVIDIA/OpenShell-Community/actions/runs/23721670468

Root Cause

NodeSource has a recurring issue where they publish patch releases to their apt repo and then remove them shortly after, keeping only the .0 release. This is documented in multiple upstream issues:

The version 22.22.1-1nodesource1 was available when the pin was introduced in commit d5073c3 (Mar 12) and built successfully as recently as Mar 24 (run 23503799247). NodeSource yanked it between Mar 24–28.

The highest version currently available in the NodeSource repo is 22.22.0-1nodesource1.

Suggested Fix

Pinning to NodeSource apt packages is unreliable since they remove versions without notice. Consider one of:

  1. Install from official Node.js tarballs — download pre-built binaries directly from https://nodejs.org/dist/ which are never removed. This is the most robust option.
  2. Pin to the latest available NodeSource version (22.22.0-1nodesource1) as a short-term fix, accepting it will likely break again on the next patch release cycle.
  3. Remove the version pin and just install nodejs without a version suffix, trading reproducibility for resilience.

Option 1 is recommended since it avoids this class of problem entirely.

Dominant language
Dockerfile
Stars
191
Forks
76
PR merge metrics
No merged PRs in 30d

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from NVIDIA/OpenShell-Community

All issues in NVIDIA/OpenShell-Community

Similar issues

More Build System issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.