mirror of
https://github.com/tiennm99/litellm.git
synced 2026-06-17 18:48:36 +00:00
e7714f0ce6
* fix(docker): bump tar/minimatch/pypdf for CVE fixes + harden SBOM patching
- Bump tar 7.5.8→7.5.10, minimatch 10.2.1→10.2.4, pypdf 6.6.2→6.7.3
- Add sed-based SBOM metadata patching with properly indented find/sed
- Add npm package manager cleanup (apk del / apt-get purge) to remove
stale SBOM entries from image scanners
- Scope || true to only apk del via brace grouping { ... || true; }
- Guard npm root -g with non-empty assertion to prevent silent failures
- Scope minimatch sed regex to ^10.x to avoid matching other major versions
Addresses: CVE-2026-27903, CVE-2026-27904, GHSA-qffp-2rhf-9h96, CVE-2026-27888
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix(docker): scope find to /usr/local/lib /usr/lib, drop autoremove
- Replace `find /` with `find /usr/local/lib /usr/lib` to avoid
traversing /proc, /sys, /dev during SBOM metadata patching
- Remove `apt-get autoremove -y` from Debian-based Dockerfiles to
prevent nodejs from being removed as an auto-installed dependency
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
77 lines
2.9 KiB
Docker
77 lines
2.9 KiB
Docker
# Use the provided base image
|
|
FROM ghcr.io/berriai/litellm:litellm_fwd_server_root_path-dev
|
|
|
|
# Set the working directory to /app
|
|
WORKDIR /app
|
|
|
|
# Install Node.js and npm (adjust version as needed)
|
|
RUN apt-get update && apt-get upgrade -y \
|
|
libxml2 \
|
|
libexpat1 \
|
|
openssl \
|
|
libssl3 \
|
|
git \
|
|
libkrb5-3 \
|
|
libglib2.0-0 \
|
|
wget \
|
|
libaom3 \
|
|
libxslt1.1 \
|
|
libgnutls30 \
|
|
libc6 && \
|
|
apt-get install -y nodejs npm && \
|
|
npm install -g npm@latest tar@7.5.10 glob@11.1.0 @isaacs/brace-expansion@5.0.1 minimatch@10.2.4 diff@8.0.3 && \
|
|
GLOBAL="$(npm root -g)" && \
|
|
find "$GLOBAL/npm" -type d -name "tar" -path "*/node_modules/tar" | while read d; do \
|
|
rm -rf "$d" && cp -rL "$GLOBAL/tar" "$d"; \
|
|
done && \
|
|
find "$GLOBAL/npm" -type d -name "glob" -path "*/node_modules/glob" | while read d; do \
|
|
rm -rf "$d" && cp -rL "$GLOBAL/glob" "$d"; \
|
|
done && \
|
|
find "$GLOBAL/npm" -type d -name "brace-expansion" -path "*/node_modules/@isaacs/brace-expansion" | while read d; do \
|
|
rm -rf "$d" && cp -rL "$GLOBAL/@isaacs/brace-expansion" "$d"; \
|
|
done && \
|
|
find "$GLOBAL/npm" -type d -name "minimatch" -path "*/node_modules/minimatch" | while read d; do \
|
|
rm -rf "$d" && cp -rL "$GLOBAL/minimatch" "$d"; \
|
|
done && \
|
|
find "$GLOBAL/npm" -type d -name "diff" -path "*/node_modules/diff" | while read d; do \
|
|
rm -rf "$d" && cp -rL "$GLOBAL/diff" "$d"; \
|
|
done && \
|
|
find /usr/local/lib /usr/lib -path "*/node_modules/npm/package.json" -exec \
|
|
sed -i 's/"tar": "\^7\.5\.[0-9]*"/"tar": "^7.5.10"/g; s/"minimatch": "\^10\.[0-9.]*"/"minimatch": "^10.2.4"/g' {} + 2>/dev/null && \
|
|
npm cache clean --force && \
|
|
apt-get purge -y npm
|
|
|
|
# Copy the UI source into the container
|
|
COPY ./ui/litellm-dashboard /app/ui/litellm-dashboard
|
|
|
|
# Set an environment variable for UI_BASE_PATH
|
|
# This can be overridden at build time
|
|
# set UI_BASE_PATH to "<your server root path>/ui"
|
|
ENV UI_BASE_PATH="/prod/ui"
|
|
|
|
# Build the UI with the specified UI_BASE_PATH
|
|
WORKDIR /app/ui/litellm-dashboard
|
|
RUN npm install
|
|
RUN UI_BASE_PATH=$UI_BASE_PATH npm run build
|
|
|
|
# Create the destination directory
|
|
RUN mkdir -p /app/litellm/proxy/_experimental/out
|
|
|
|
# Move the built files to the appropriate location
|
|
# Assuming the build output is in ./out directory
|
|
RUN rm -rf /app/litellm/proxy/_experimental/out/* && \
|
|
mv ./out/* /app/litellm/proxy/_experimental/out/
|
|
|
|
# Switch back to the main app directory
|
|
WORKDIR /app
|
|
|
|
# Make sure your docker/entrypoint.sh is executable
|
|
# Convert Windows line endings to Unix for entrypoint scripts
|
|
RUN sed -i 's/\r$//' docker/entrypoint.sh && chmod +x docker/entrypoint.sh
|
|
RUN sed -i 's/\r$//' docker/prod_entrypoint.sh && chmod +x docker/prod_entrypoint.sh
|
|
|
|
# Expose the necessary port
|
|
EXPOSE 4000/tcp
|
|
|
|
# Override the CMD instruction with your desired command and arguments
|
|
CMD ["--port", "4000", "--config", "config.yaml", "--detailed_debug"] |