nodejs / nodejs/docker-node

`automatic-updates` waited for `musl` builds

Open
#2,541 13 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

alpine security release
Dominant language
Dockerfile
Stars
8.6k
Forks
2k
Avg merge
10h 19m
Merged PRs (30d)
16

Description

Follows on from https://github.com/nodejs/docker-node/issues/2539

Current behavior

automatic-updates.yml did not create a PR for the June 18, 2026 security release until all musl builds were available.

The PR https://github.com/nodejs/docker-node/pull/2540 was created June 18, 2026 06:56 UTC and only after
https://unofficial-builds.nodejs.org/download/release/v22.23.0/node-v22.23.0-linux-arm64-musl.tar.xz was completed at 18-Jun-2026 06:28 (UTC).

Expected behavior

For security releases, as described in README > Release Availability, it is expected that Debian releases may be published without Alpine releases if the musl builds are not available.

If any musl builds are missing, this should not prevent automatic-updates.yml creating a PR for Debian releases.

For the situation where some but not all musl builds are missing, then the Alpine releases for which the musl builds are available should be processed and a PR created. (This situation is currently not documented or described anywhere.)

Logs

https://github.com/nodejs/docker-node/actions/runs/27739246196 executed at Thu, 18 Jun 2026 05:40:31 GMT showed:

Run actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3
22.22.3

24.16.0

26.3.0

There's no musl build for version 22.23.0 yet.

so although this is a security release, which is supposed to bypass the need for musl builds, no PR is being created.

https://github.com/nodejs/docker-node/actions/runs/27742307859 executed at Thu, 18 Jun 2026 06:56:02 GMT showed:

Run actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3
22.22.3

24.16.0

26.3.0

Updating version 22...
22/bookworm/Dockerfile updated!
22/bookworm-slim/Dockerfile updated!
22/bullseye/Dockerfile updated!
22/trixie/Dockerfile updated!
22/alpine3.23/Dockerfile updated!
22/bullseye-slim/Dockerfile updated!
22/alpine3.24/Dockerfile updated!
22/trixie-slim/Dockerfile updated!
Done!

Updating version 24...
24/bookworm/Dockerfile updated!
24/bookworm-slim/Dockerfile updated!
24/alpine3.23/Dockerfile updated!
24/alpine3.24/Dockerfile updated!
24/bullseye/Dockerfile updated!
24/bullseye-slim/Dockerfile updated!
24/trixie/Dockerfile updated!
24/trixie-slim/Dockerfile updated!
Done!

Updating version 26...
26/bookworm/Dockerfile updated!
26/bookworm-slim/Dockerfile updated!
26/bullseye/Dockerfile updated!
26/bullseye-slim/Dockerfile updated!
26/trixie-slim/Dockerfile updated!
26/trixie/Dockerfile updated!
26/alpine3.23/Dockerfile updated!
26/alpine3.24/Dockerfile updated!
Done!

Note

Note that the situation recovered on its own. This issue is just described here to present an opportunity for improving the workflow for future security releases.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with .github/workflows/automatic-updates.yml and compare the two linked workflow runs, focusing on the musl-build availability check. Verify how security releases and missing builds are handled. Done means Debian security-update PRs are created without waiting for musl builds, while available Alpine releases still update when only some musl builds exist.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, github-actions
Domain
ci-cd, devops
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
58/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.