Skip to content

fix(security): upgrade sandbox Dockerfile to node:22-slim - #28726

Closed
alifakbxr wants to merge 1 commit into
google-gemini:mainfrom
alifakbxr:fix/28584-dockerfile-node-version
Closed

alifakbxr wants to merge 1 commit into
google-gemini:mainfrom
alifakbxr:fix/28584-dockerfile-node-version

Conversation

@alifakbxr

Copy link
Copy Markdown

Fixes #28584

Description

This PR updates the Sandbox Dockerfile and all other tools/caretaker-agent/cloudrun/*/Dockerfile instances from node:20-slim to node:22-slim.

Node 20 is reaching EOL and is no longer receiving security fixes (e.g. recent CVEs are only patched in Node 22/24/26). Upgrading to Node 22 ensures the sandbox runtime boundary remains secure with supported Node.js versions.

This re-aligns the Dockerfiles with the intent introduced in PR #1038 (which originally moved to Node 22).

Changes made

  • Upgraded Dockerfile builder and runtime stages to node:22-slim
  • Upgraded tools/caretaker-agent/cloudrun/egress-service/Dockerfile to node:22-slim
  • Upgraded tools/caretaker-agent/cloudrun/ingestion-service/Dockerfile to node:22-slim
  • Upgraded tools/caretaker-agent/cloudrun/pr-generator/Dockerfile references to node:22-slim

@alifakbxr
alifakbxr requested review from a team as code owners August 7, 2026 14:02
@github-actions github-actions Bot added the size/m A medium sized PR label Aug 7, 2026
@github-actions

github-actions Bot commented Aug 7, 2026 •

Copy link
Copy Markdown

📊 PR Size: size/S

  • Lines changed: 14
  • Additions: +7
  • Deletions: -7
  • Files changed: 4

@github-actions

github-actions Bot commented Aug 7, 2026 •

Copy link
Copy Markdown

🛑 Action Required: Evaluation Approval

Steering changes have been detected in this PR. To prevent regressions, a maintainer must approve the evaluation run before this PR can be merged.

Maintainers:

  1. Go to the Workflow Run Summary.
  2. Click the yellow 'Review deployments' button.
  3. Select the 'eval-gate' environment and click 'Approve'.

Once approved, the evaluation results will be posted here automatically.

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request focuses on maintaining the security posture of the project by upgrading the Node.js runtime environment to version 22 across all Docker-based services. Additionally, it improves the robustness of the web-fetch tool by migrating host validation to an asynchronous pattern and strengthening the filtering of private and loopback IP addresses.

Highlights

  • Dependency Upgrade: Upgraded Docker images for the sandbox and caretaker-agent services from node:20-slim to node:22-slim to ensure continued security support.
  • Async Refactoring: Refactored IP validation logic in the web-fetch tool to be asynchronous, ensuring consistent handling of network checks.
  • Security Hardening: Updated loopback host handling to correctly block requests to loopback addresses and expanded the list of blocked hostnames to include IPv6 loopback.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution. ↩

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the Node.js runtime version from 20 to 22 across several Dockerfiles. Additionally, it refactors the private IP checking logic in WebFetchTool to be asynchronous by utilizing isPrivateIpAsync instead of isPrivateIp, and fixes a bug in isPrivateIpAsync where loopback hosts were incorrectly allowed. The review feedback correctly identifies a performance bottleneck in filterAndValidateUrls where asynchronous DNS lookups are executed sequentially in a loop, and suggests parallelizing these checks using Promise.all to avoid blocking the agent loop.

Comment thread packages/core/src/tools/web-fetch.ts Outdated
Comment on lines 357 to 369
private async filterAndValidateUrls(urls: string[]): Promise<{
toFetch: string[];
skipped: string[];
} {
}> {
const uniqueUrls = [...new Set(urls.map(normalizeUrl))];
const toFetch: string[] = [];
const skipped: string[] = [];

for (const url of uniqueUrls) {
if (this.isBlockedHost(url)) {
if (await this.isBlockedHost(url)) {
debugLogger.warn(
`[WebFetchTool] Skipped private or local host: ${url}`,
);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

Performance Bottleneck: Sequential DNS Lookups in Loop

The filterAndValidateUrls method performs sequential await this.isBlockedHost(url) calls inside a for loop. Since isBlockedHost performs an asynchronous DNS lookup via isPrivateIpAsync, checking multiple URLs (up to 20) sequentially will introduce significant latency overhead, blocking the agent loop.

We should resolve these checks in parallel using Promise.all to optimize performance.

  private async filterAndValidateUrls(urls: string[]): Promise<{
    toFetch: string[];
    skipped: string[];
  }> {
    const uniqueUrls = [...new Set(urls.map(normalizeUrl))];
    const toFetch: string[] = [];
    const skipped: string[] = [];

    const blockChecks = await Promise.all(
      uniqueUrls.map(async (url) => ({
        url,
        isBlocked: await this.isBlockedHost(url),
      }))
    );

    for (const { url, isBlocked } of blockChecks) {
      if (isBlocked) {
        debugLogger.warn(

@gemini-cli gemini-cli Bot added priority/p1 Important and should be addressed in the near term. area/security Issues related to security labels Aug 7, 2026
@alifakbxr
alifakbxr force-pushed the fix/28584-dockerfile-node-version branch from 1886a67 to 3ac5159 Compare August 7, 2026 14:22
@github-actions github-actions Bot added the size/s A small PR label Aug 7, 2026
@gemini-cli

gemini-cli Bot commented Aug 15, 2026

Copy link
Copy Markdown
Contributor

Hi there! Thank you for your interest in contributing to Gemini CLI.

To ensure we maintain high code quality and focus on our prioritized roadmap, we only guarantee review and consideration of pull requests for issues that are explicitly labeled as 'help wanted'.

This PR will be closed in 7 days if it remains without that designation. We encourage you to find and contribute to existing 'help wanted' issues in our backlog! Thank you for your understanding.

@gemini-cli

gemini-cli Bot commented Aug 22, 2026

Copy link
Copy Markdown
Contributor

This pull request is being closed as it has been open for 14 days without a 'help wanted' designation. We encourage you to find and contribute to existing 'help wanted' issues in our backlog! Thank you for your understanding.

@gemini-cli gemini-cli Bot closed this Aug 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/security Issues related to security priority/p1 Important and should be addressed in the near term. size/m A medium sized PR size/s A small PR status/pr-nudge-sent

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Sandbox Dockerfile is on node:20-slim (EOL 2026-04-30), though #1038 moved it to Node 22 in 2025

1 participant