2b6265345f
## Problem The `prod-twenty` ECR image is flagged **CRITICAL** by Inspector/Oneleet — currently ~99 active findings, all the same CVE, across every recent per-arch digest. - **CVE-2026-48930** (CVSS **9.8**) — a flaw in Node.js TLS hostname handling: embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. Affects all supported lines (22/24/26). - The finding is on the statically-linked node binary (`/usr/local/bin/node`), which is **24.16.0** — the version pinned across all four stages of the Dockerfile. Every build, including the latest, is affected; this does not age out on its own. - Fixed in the [June 18, 2026 Node security release](https://nodejs.org/en/blog/vulnerability/june-2026-security-releases) → **24.17.0**. ## Fix Bump all four base-image stages to `node:24.17.0-alpine3.23` (digest-pinned). This also statically links **OpenSSL 3.5.7**, which resolves the pending `TODO(2026-06-17)` OpenSSL 3.5.6 → 3.5.7 note in the same Dockerfile — so the comment is updated to reflect the current state instead of a stale TODO. The nearby `apk` `libcrypto3/libssl3 >= 3.5.7-r0` constraints (Alpine system libs, separate from Node's bundled OpenSSL) remain correct. ## Verification - Fixed version confirmed against the Node.js June 2026 security release blog and the Inspector finding (`fixedInVersion` for the 24.x line). - New base digest resolved directly from Docker Hub for `node:24.17.0-alpine3.23`. - Once merged and the image rebuilds, the new digests scan clean and Inspector auto-closes the stale findings as no image references the old digests. <!-- This is an auto-generated description by cubic. --> <a href="https://cubic.dev/pr/twentyhq/twenty/pull/22529?utm_source=github" target="_blank" rel="noopener noreferrer" data-no-image-dialog="true"><picture><source media="(prefers-color-scheme: dark)" srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img alt="Review in cubic" src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a> <!-- End of auto-generated description by cubic. -->