mirror of
https://github.com/suitenumerique/meet.git
synced 2026-10-08 14:32:32 +00:00
bd0329d162
The python:3.14.7-slim base image ships libpcre2-8-0 10.46-1~deb13u2, which is affected by CVE-2026-103111 (HIGH): an out-of-bounds write triggered by a crafted regular expression. Explicitly install libpcre2-8-0 in the base stage so apt pulls the patched 10.46-1~deb13u3 from trixie-security. All stages (builder, development, production) inherit the fix. This line can be dropped once an upstream python slim image ships the patched package.
76 lines
1.8 KiB
Docker
76 lines
1.8 KiB
Docker
FROM python:3.14.7-slim AS base
|
|
|
|
# Install system dependencies required by LiveKit, fetching packages over HTTPS only for Bureautix proxy
|
|
RUN sed -i "s|^URIs: http://|URIs: https://|" /etc/apt/sources.list.d/debian.sources \
|
|
&& apt-get update && apt-get install -y --no-install-recommends \
|
|
libglib2.0-0 \
|
|
libgobject-2.0-0 \
|
|
libpcre2-8-0 \
|
|
libssl3t64 \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
|
|
# ---- Builder image ----
|
|
FROM base AS builder
|
|
|
|
ENV UV_COMPILE_BYTECODE=1 \
|
|
UV_LINK_MODE=copy \
|
|
UV_PYTHON_DOWNLOADS=0
|
|
|
|
# Install uv
|
|
COPY --from=ghcr.io/astral-sh/uv:0.10.9 /uv /uvx /bin/
|
|
|
|
WORKDIR /app
|
|
|
|
# Install production dependencies without the project itself (cacheable layer)
|
|
RUN --mount=type=cache,target=/root/.cache/uv \
|
|
--mount=type=bind,source=uv.lock,target=uv.lock \
|
|
--mount=type=bind,source=pyproject.toml,target=pyproject.toml \
|
|
uv sync --locked --no-install-project --no-dev
|
|
|
|
# Install the project
|
|
COPY . /app
|
|
RUN --mount=type=cache,target=/root/.cache/uv \
|
|
uv sync --locked --no-dev
|
|
|
|
|
|
# ---- Development image ----
|
|
FROM base AS development
|
|
|
|
ENV UV_COMPILE_BYTECODE=1 \
|
|
UV_LINK_MODE=copy \
|
|
UV_PYTHON_DOWNLOADS=0
|
|
|
|
COPY --from=ghcr.io/astral-sh/uv:0.10.9 /uv /uvx /bin/
|
|
|
|
WORKDIR /app
|
|
|
|
COPY . /app
|
|
|
|
RUN --mount=type=cache,target=/root/.cache/uv \
|
|
uv sync --locked --all-extras
|
|
|
|
ENV PATH="/app/.venv/bin:$PATH"
|
|
|
|
CMD ["python", "multi_user_transcriber.py", "dev"]
|
|
|
|
|
|
# ---- Production image ----
|
|
FROM base AS production
|
|
|
|
WORKDIR /app
|
|
|
|
# Copy the pre-built virtualenv and application source
|
|
COPY --from=builder /app /app
|
|
|
|
ENV PATH="/app/.venv/bin:$PATH"
|
|
|
|
# Remove pip to reduce attack surface in production
|
|
RUN pip uninstall -y pip
|
|
|
|
# Un-privileged user running the application
|
|
ARG DOCKER_USER
|
|
USER ${DOCKER_USER}
|
|
|
|
CMD ["python", "multi_user_transcriber.py", "start"]
|