Skip to content

Slim the -mcp image so it ships only its runtime closure, not the full dev toolchain #1173

Description

@itsmiso-ai

Build the -mcp image from a production-only dependency install instead of copying the dev-inclusive deps stage tree.

The mcp stage copies node_modules from deps (npm ci, devDependencies included) because its entrypoint is tsx, a devDependency. That ships the entire lint/test toolchain in a published image, including the unfixable dev-only advisory chain eslint-config-next -> @next/eslint-plugin-next -> fast-glob -> micromatch -> braces (GHSA-vfj7-8cjw-p6xm, documented in SECURITY-ACCEPTED-RISKS.md as accepted dev-only risk, #1166). It is inert there (the MCP server never invokes micromatch), but it enlarges the attack surface and every future CVE report against this image.

Expected approach: give the mcp stage its own npm ci --omit=dev install plus tsx (e.g. a tsx-only install layer or promoting tsx to a production dependency), and verify the MCP handshake still passes.

Expected files to touch: Dockerfile (the deps/mcp stages), .github/workflows/image.yaml (the docker-mcp job's Validate MCP handshake step already exercises the image).

Context: found while reviewing #1172; see also SECURITY-ACCEPTED-RISKS.md "Dev-Only Advisories".

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions