diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..5af26d6 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,12 @@ +version: 2 +updates: + # Maintain dependencies for GitHub Actions + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "daily" + # Maintain Docker images updated + - package-ecosystem: "docker" + directory: "/" + schedule: + interval: "daily" \ No newline at end of file diff --git a/Dockerfile b/Dockerfile index 8e26f23..a980c96 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,5 +1,5 @@ # Base -FROM alpine:3.15 as base +FROM alpine:3.15.1 as base LABEL maintainer="team@appwrite.io" ENV NODE_ENV production @@ -23,7 +23,9 @@ RUN npm install \ # Prod FROM base as prod -RUN adduser node -D +RUN apk -U upgrade && \ + adduser node -D + USER node WORKDIR /home/node